<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LSVPN Satellite Reconnection Time in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-reconnection-time/m-p/245527#M69950</link>
    <description>&lt;P&gt;Hi Sam,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have big problems with LSVPN as well.&lt;/P&gt;&lt;P&gt;After replacing the Root CA, some gateways fail to connect to gateways, because the gateway or satellite has an old certificate cached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the first tunnel goes down, only tries to "reconnect" to the primary gateway happens, no failover to the secondary gateway.&lt;/P&gt;&lt;P&gt;AFter manually clicking on reconnect to gateway (secondary) the gateway is displayed as "user disconnected".&lt;/P&gt;&lt;P&gt;Yesterday somehow there was a connection to the secondary gateway when testing failover, but no routes were distributed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my opinion LSVPN is bananaware when these fundamental things aren't working properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Chacko&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jan 2019 13:23:38 GMT</pubDate>
    <dc:creator>Chacko42</dc:creator>
    <dc:date>2019-01-10T13:23:38Z</dc:date>
    <item>
      <title>LSVPN Satellite Reconnection Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-reconnection-time/m-p/228794#M65769</link>
      <description>&lt;P&gt;Does anyone know how to decrease the time between LSVPN Satellite connection attempts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If one of our satellites drops off (e.g. reboot/power outage/etc), after it comes back up it will take up to an hour to connect to it's nominated&amp;nbsp;Gateway. Also, if the Gateway is rebooted (e.g. after hours mainteance) it takes up to an hour before all of the satellites&amp;nbsp;re-connect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently the 'Configuration&amp;nbsp;refresh' internal is set to 2 hours for the Gateway.&lt;/P&gt;&lt;P&gt;I'm unclear if this configuration option affects the actual reconnection times - I imagine it would act as a 'worst case' scenario where the Satellite would be forced to reconnect to attempt to refresh config?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm hoping there's a method of setting the LSVPN Satellite "re-connect timer" down to about 5 minutes or so, as currently it's very painful when there's a reboot.&amp;nbsp;Remoting in to manually click 'Reconnect to Gateway' is not&amp;nbsp;a feasuible option, as the Satellite's are installed in branch offices with non-technically-literate people and the Management interfaces are not available via WAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IPSec tunnels seem to reconnect much quicker. I was considering having an IPSec tunnel from each of the ~50 Satellites back to a central point to maintain a management interface, so I can manually click "Reconnect to Gateway" - but&amp;nbsp;then why even both using LSVPN, if we have IPSec tunnels to all devices?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit - been through 2 TAC cases so far with no solid&amp;nbsp;answers to any of the above&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 05:15:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-reconnection-time/m-p/228794#M65769</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-08-30T05:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN Satellite Reconnection Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-reconnection-time/m-p/228857#M65772</link>
      <description>&lt;P&gt;are your endpoints actively generating traffic to your central site ?&lt;/P&gt;
&lt;P&gt;have you set up a tunnel monitoring profile with wait recover or failover?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 12:03:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-reconnection-time/m-p/228857#M65772</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-08-30T12:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN Satellite Reconnection Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-reconnection-time/m-p/228917#M65800</link>
      <description>&lt;P&gt;Hi reaper&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, there are automated systems on-site sending data back to a central hub (cameras, etc).&lt;/P&gt;&lt;P&gt;So I would expect LAN devices to be generating traffic destined for the LSVPN Gateway as soon as the firewall was online&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additionally, when I reboot the hub firewall I have MultiPing running to establish when the branches come back online. This application is generating ping traffic across all know links, but it still takes roughty an hour for them all to come back online. It's always different firewalls in different orders, and&amp;nbsp;they seem to come back in a roughly linear pattern over the hour - but it's always roughly an hour for them all to come back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I was under the impression that&amp;nbsp;LSVPN was not established when 'interesting traffic' was encountered (ala Cisco) but rather as a function of the 'satd' daemon? I'm hoping to find out if we can manipulate this daemon to attempt re-establishment&amp;nbsp;more quickly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought of a tunnel monitor, but TAC advised that was only useful in the event we had redundant paths. The tunnel monitor could be used as a trigger to activate a redundanct/secondary path - but&amp;nbsp;it would not prompt a Satellite to attempt reconnection of a failed tunnel. If you have experience that suggests the opposite then I'd be happy to try&amp;nbsp;this method&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 16:12:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-reconnection-time/m-p/228917#M65800</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-08-30T16:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN Satellite Reconnection Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-reconnection-time/m-p/245527#M69950</link>
      <description>&lt;P&gt;Hi Sam,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have big problems with LSVPN as well.&lt;/P&gt;&lt;P&gt;After replacing the Root CA, some gateways fail to connect to gateways, because the gateway or satellite has an old certificate cached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the first tunnel goes down, only tries to "reconnect" to the primary gateway happens, no failover to the secondary gateway.&lt;/P&gt;&lt;P&gt;AFter manually clicking on reconnect to gateway (secondary) the gateway is displayed as "user disconnected".&lt;/P&gt;&lt;P&gt;Yesterday somehow there was a connection to the secondary gateway when testing failover, but no routes were distributed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my opinion LSVPN is bananaware when these fundamental things aren't working properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Chacko&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 13:23:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-reconnection-time/m-p/245527#M69950</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-01-10T13:23:38Z</dc:date>
    </item>
  </channel>
</rss>

