<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dual ISP IPSEC vpn tunnel monitor drops the connection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-ipsec-vpn-tunnel-monitor-drops-the-connection/m-p/226525#M65213</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I added second ISP to firewall and created ECMP for dual ISP followed those guides:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Implement-ECMP-Load-Balancing-on-the-Firewall/ta-p/110339#" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Implement-ECMP-Load-Balancing-on-the-Firewall/ta-p/110339#&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when I'm trying to configure tunnel monitoring on the IPSEC tunnels (after I configure tunnel interface IPv4 from local network subnet) the connection drops and cann't connect again.&lt;/P&gt;&lt;P&gt;Only after I disable the tunnel monitoring settings the vpn connection comes up&amp;nbsp;again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;anyone has suggestions what to do or what to check for it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Aug 2018 22:08:15 GMT</pubDate>
    <dc:creator>SShnap</dc:creator>
    <dc:date>2018-08-08T22:08:15Z</dc:date>
    <item>
      <title>Dual ISP IPSEC vpn tunnel monitor drops the connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-ipsec-vpn-tunnel-monitor-drops-the-connection/m-p/226525#M65213</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I added second ISP to firewall and created ECMP for dual ISP followed those guides:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Implement-ECMP-Load-Balancing-on-the-Firewall/ta-p/110339#" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Implement-ECMP-Load-Balancing-on-the-Firewall/ta-p/110339#&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when I'm trying to configure tunnel monitoring on the IPSEC tunnels (after I configure tunnel interface IPv4 from local network subnet) the connection drops and cann't connect again.&lt;/P&gt;&lt;P&gt;Only after I disable the tunnel monitoring settings the vpn connection comes up&amp;nbsp;again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;anyone has suggestions what to do or what to check for it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 22:08:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-ipsec-vpn-tunnel-monitor-drops-the-connection/m-p/226525#M65213</guid>
      <dc:creator>SShnap</dc:creator>
      <dc:date>2018-08-08T22:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP IPSEC vpn tunnel monitor drops the connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-ipsec-vpn-tunnel-monitor-drops-the-connection/m-p/226655#M65241</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/40971"&gt;@SShnap&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What version of PAN-OS are you running?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 19:55:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-ipsec-vpn-tunnel-monitor-drops-the-connection/m-p/226655#M65241</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-09T19:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP IPSEC vpn tunnel monitor drops the connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-ipsec-vpn-tunnel-monitor-drops-the-connection/m-p/229048#M65836</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm running PAVM200 with PANOS 8.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 17:54:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-ipsec-vpn-tunnel-monitor-drops-the-connection/m-p/229048#M65836</guid>
      <dc:creator>SShnap</dc:creator>
      <dc:date>2018-08-31T17:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP IPSEC vpn tunnel monitor drops the connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-ipsec-vpn-tunnel-monitor-drops-the-connection/m-p/229050#M65838</link>
      <description>&lt;P&gt;- You shouldn't be using 8.0.0 anymore by far; update PAN-OS to something like 8.0.10 so you get the security fixes and all of the associated fixes, base images are&amp;nbsp;&lt;STRONG&gt;not&lt;/STRONG&gt; production ready.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Depending on what you have specified in the tunnel monitoring profile this would be an expected action. When used in conjunction with DPD the montioring profile only has two options&amp;nbsp;&lt;EM&gt;wait recover&lt;/EM&gt; or&amp;nbsp;&lt;EM&gt;fail over&lt;/EM&gt;. In either case the firewall will attempt to recover by negotiating new IPSec keys. When certain peer devices see this action they will sometimes close the connection on their end depending on the configuration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would start by simply upgrading the PAN-OS version, because you shouldn't be running 8.0.0 anymore. That likely won't fix it, but it's better for your device as a whole. Since you are only running into an issue with the tunnel montioring profile active verify what the monitoring profile actually has set for the action. It could easily be that the peer device simply is dropping the connection when the PA attempts to re-key.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 18:28:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp-ipsec-vpn-tunnel-monitor-drops-the-connection/m-p/229050#M65838</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-31T18:28:15Z</dc:date>
    </item>
  </channel>
</rss>

