<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Behaviour of VPN tunnels in HA pair during the failover in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/behaviour-of-vpn-tunnels-in-ha-pair-during-the-failover/m-p/245139#M69889</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91304"&gt;@R_Sharma&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IPSec SAs are synced but not the IKE SAs. So normally everything works fine during failover with - as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;mentionned - with a few pings lost (in most cases I had only one or two pings lost).&amp;nbsp;&lt;/P&gt;&lt;P&gt;But because of the not synced IKE SAs you need to be careful. In the past I hat connections that were no longer established when IPSec timout was reached and IKE SA wasn't renewed so far. (Probably depends on the IKE/IPSec implelementation on the other side). Since then after a failover I manually (/with a script) renew all IKE SAs and the problem is solved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
    <pubDate>Mon, 07 Jan 2019 18:58:51 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2019-01-07T18:58:51Z</dc:date>
    <item>
      <title>Behaviour of VPN tunnels in HA pair during the failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/behaviour-of-vpn-tunnels-in-ha-pair-during-the-failover/m-p/245054#M69881</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Can anyone please explain the behaviour of VPN tunnels during the failover on PAN.&lt;/P&gt;&lt;P&gt;Does the ISAKMP and IPSEC SA table gets passed on to the standby unit ?&lt;/P&gt;&lt;P&gt;Does the VPN tunnels will re-estalish the session again&amp;nbsp; on the new active unit after the failover? what would be the downtime that the users will experience for vpn tunnels?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 04:51:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/behaviour-of-vpn-tunnels-in-ha-pair-during-the-failover/m-p/245054#M69881</guid>
      <dc:creator>R_Sharma</dc:creator>
      <dc:date>2019-01-07T04:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: Behaviour of VPN tunnels in HA pair during the failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/behaviour-of-vpn-tunnels-in-ha-pair-during-the-failover/m-p/245116#M69887</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;While it has been a while since I had to fail over firewalls. In the past I have upgraded a active/passive PAN's that I was VPN'ed into and duiring a failover, my connection was not dropped. The sessions should be handed over to the passive unit and everything should continue to function. At most in testing I have seen a few ping drops. So a video conference or phone call might get dropped.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 15:49:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/behaviour-of-vpn-tunnels-in-ha-pair-during-the-failover/m-p/245116#M69887</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-01-07T15:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Behaviour of VPN tunnels in HA pair during the failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/behaviour-of-vpn-tunnels-in-ha-pair-during-the-failover/m-p/245139#M69889</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91304"&gt;@R_Sharma&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IPSec SAs are synced but not the IKE SAs. So normally everything works fine during failover with - as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;mentionned - with a few pings lost (in most cases I had only one or two pings lost).&amp;nbsp;&lt;/P&gt;&lt;P&gt;But because of the not synced IKE SAs you need to be careful. In the past I hat connections that were no longer established when IPSec timout was reached and IKE SA wasn't renewed so far. (Probably depends on the IKE/IPSec implelementation on the other side). Since then after a failover I manually (/with a script) renew all IKE SAs and the problem is solved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 18:58:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/behaviour-of-vpn-tunnels-in-ha-pair-during-the-failover/m-p/245139#M69889</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-01-07T18:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Behaviour of VPN tunnels in HA pair during the failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/behaviour-of-vpn-tunnels-in-ha-pair-during-the-failover/m-p/245321#M69925</link>
      <description>&lt;P&gt;It is worth mentioning what cluster are you running! Because the smallest boxes are using so called HA-lite, which doesn't support IPsec SA sync.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-web-interface-help/device/device-high-availability/ha-lite" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-web-interface-help/device/device-high-availability/ha-lite&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 12:46:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/behaviour-of-vpn-tunnels-in-ha-pair-during-the-failover/m-p/245321#M69925</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2019-01-09T12:46:19Z</dc:date>
    </item>
  </channel>
</rss>

