<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec packet drop , once the ecmp is enabled in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221460#M63775</link>
    <description>&lt;P&gt;Thank you for the clarification ...i will try the same and let you know if this helps ...&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jul 2018 13:46:26 GMT</pubDate>
    <dc:creator>Rameshwar</dc:creator>
    <dc:date>2018-07-10T13:46:26Z</dc:date>
    <item>
      <title>IPsec packet drop , once the ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221385#M63761</link>
      <description>&lt;P&gt;Hi Team&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are facing packet drop issue on ipsec traffic once the ecmp is enabled .&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have two ISP and wish to balance the traffic and using balanced round robbin for the same , once this is enabled ipsec packet drop occurs and if we disable ecmp everything is fine .&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first internet line is lease line on which the ipsec is terminated and the other line is ADSL i.e. dynamic IP .&amp;nbsp;&lt;/P&gt;&lt;P&gt;i am suspecting , since the ecmp is enabled the traffic is going from adsl line and the return traffic is coming on lease line and getting dropped by FW .&amp;nbsp;&lt;/P&gt;&lt;P&gt;please advise if there is any solution for this senario... if i ebale IP modulo or IP hash for ECMP will this resolve the issue or PBF for symetric return ??&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 09:20:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221385#M63761</guid>
      <dc:creator>Rameshwar</dc:creator>
      <dc:date>2018-07-10T09:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec packet drop , once the ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221437#M63762</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/67619"&gt;@Rameshwar&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how did you configure the vpn exactly? is it bound to a loopback or the physical interfaces&lt;/P&gt;
&lt;P&gt;IP modulo/hash should help the connection be 'sticky' to a single link and only switch when the link goes down&lt;/P&gt;
&lt;P&gt;PBF will not be an option as you can't control system sourced connections through pbf&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 12:47:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221437#M63762</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-07-10T12:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec packet drop , once the ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221439#M63763</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the ipsec is configured to use the tunnel interface and terminated on the physical interface of 1st IP i.e. the lease line.&amp;nbsp;&lt;/P&gt;&lt;P&gt;i guess ip modulo\hash should help is resolving this issue ...any more suggestions on this senario&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 12:51:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221439#M63763</guid>
      <dc:creator>Rameshwar</dc:creator>
      <dc:date>2018-07-10T12:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec packet drop , once the ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221442#M63766</link>
      <description>&lt;P&gt;if the VPN is bound to the physical interface of the leased line, you should also be able to add a static route for the remote peer pointed to the next hop on the leased line (metric 1)&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 13:05:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221442#M63766</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-07-10T13:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec packet drop , once the ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221443#M63767</link>
      <description>&lt;P&gt;If VPN is bound to IP of first ISP then it should never go over 2nd interface. As you will always receive return packets on first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However if you choose something else of phase 1 identification (or seperate IP for ID and transport IP for phase 1) you can setup tunnel with dynamic IPs.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 13:06:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221443#M63767</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-07-10T13:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec packet drop , once the ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221444#M63768</link>
      <description>Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;Sorry for th typo ... it is first isp ... the change in the ipsec config will not be the option as this is production fw .</description>
      <pubDate>Tue, 10 Jul 2018 13:12:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221444#M63768</guid>
      <dc:creator>Rameshwar</dc:creator>
      <dc:date>2018-07-10T13:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec packet drop , once the ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221446#M63769</link>
      <description>&lt;P&gt;Then this IPSEC traffic must stick to first ISP cause reply will always come over that one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 13:18:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221446#M63769</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-07-10T13:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec packet drop , once the ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221447#M63770</link>
      <description>Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;So what I understand is to add the static route for ipsec traffic as a next hop i.e the router ip of first isp with metric 1......but we already added proxy id that shuld add the route but may be not with metric 1 ... but if i add the route as next hop router ip then the traffic will go to the internet n not through the tunnel or shuld i select tunnel interface while adding the route?</description>
      <pubDate>Tue, 10 Jul 2018 13:18:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221447#M63770</guid>
      <dc:creator>Rameshwar</dc:creator>
      <dc:date>2018-07-10T13:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec packet drop , once the ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221448#M63771</link>
      <description>Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;I agree but we are using the ecmp balanced round robbin in this i guess fw is sending to adsl line n the return is coming to lease line .. since lease line doesnt know abut it it is dropping .</description>
      <pubDate>Tue, 10 Jul 2018 13:22:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221448#M63771</guid>
      <dc:creator>Rameshwar</dc:creator>
      <dc:date>2018-07-10T13:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec packet drop , once the ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221449#M63772</link>
      <description>&lt;P&gt;proxy IDs are routing _inside_ the tunnel, this has no impact whatsoever in regards to the physical route the tunnel takes&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 13:33:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221449#M63772</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-07-10T13:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec packet drop , once the ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221450#M63773</link>
      <description>&lt;P&gt;thank you ..but m kind of confuse here.. when you say...&lt;SPAN&gt;if the VPN is bound to the physical interface of the leased line, you should also be able to add a static route for the remote peer pointed to the next hop on the leased line (metric 1)...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;the destination is private IP or public ip of remote peer ? ...the next hope will be the ISP router IP of lease line ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 13:38:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221450#M63773</guid>
      <dc:creator>Rameshwar</dc:creator>
      <dc:date>2018-07-10T13:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec packet drop , once the ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221455#M63774</link>
      <description>&lt;P&gt;The public IP of the remote vpn peer , pointed to the router of the leased line&lt;/P&gt;
&lt;P&gt;This will ensure outgoing vpn connections always go out the ISP1 interface&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 13:43:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221455#M63774</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-07-10T13:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec packet drop , once the ecmp is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221460#M63775</link>
      <description>&lt;P&gt;Thank you for the clarification ...i will try the same and let you know if this helps ...&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 13:46:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-packet-drop-once-the-ecmp-is-enabled/m-p/221460#M63775</guid>
      <dc:creator>Rameshwar</dc:creator>
      <dc:date>2018-07-10T13:46:26Z</dc:date>
    </item>
  </channel>
</rss>

