<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: tunnel monitor with VPN tunnel in passive mode in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-with-vpn-tunnel-in-passive-mode/m-p/313002#M80863</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The passive member disabled it routing engine. That way the firewall is not able to initiate or response to any packet send to its dataplane interfaces. Think for the tunnel monitor the same way as the HA path-monitor.&lt;/P&gt;&lt;P&gt;- Both (tunnel monitor and path-monitor) as simple icmp ping packets generated by the FW waiting for response&lt;/P&gt;&lt;P&gt;- When the member is in passive mode it is not able to generate those ping packets so both monitors are inactive&lt;/P&gt;</description>
    <pubDate>Wed, 26 Feb 2020 08:46:57 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2020-02-26T08:46:57Z</dc:date>
    <item>
      <title>tunnel monitor with VPN tunnel in passive mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-with-vpn-tunnel-in-passive-mode/m-p/312845#M80848</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you think if having tunnel monitor for an IPSec tunnel in passive mode makes any benefit?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When tunnel monitor detects tunnel down, the firewall would attempt to accelerate the recovery by negotiating new IPSec keys. If firewall in passive node it wouldn´t be able to initiate the negotiations from its side in order to reestablish the tunnel, am I right?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you in advance!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2020 17:56:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-with-vpn-tunnel-in-passive-mode/m-p/312845#M80848</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2020-02-25T17:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: tunnel monitor with VPN tunnel in passive mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-with-vpn-tunnel-in-passive-mode/m-p/312958#M80853</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;SPAN&gt;If firewall in passive node it wouldn´t be able to initiate the negotiations from its side in order to reestablish the tunnel, am I right?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;If the firewall is passive it doesn't even bring up it's tunnel interfaces, all of that is going to be handled by your active node.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 03:13:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-with-vpn-tunnel-in-passive-mode/m-p/312958#M80853</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-02-26T03:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: tunnel monitor with VPN tunnel in passive mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-with-vpn-tunnel-in-passive-mode/m-p/313002#M80863</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The passive member disabled it routing engine. That way the firewall is not able to initiate or response to any packet send to its dataplane interfaces. Think for the tunnel monitor the same way as the HA path-monitor.&lt;/P&gt;&lt;P&gt;- Both (tunnel monitor and path-monitor) as simple icmp ping packets generated by the FW waiting for response&lt;/P&gt;&lt;P&gt;- When the member is in passive mode it is not able to generate those ping packets so both monitors are inactive&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 08:46:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-with-vpn-tunnel-in-passive-mode/m-p/313002#M80863</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2020-02-26T08:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: tunnel monitor with VPN tunnel in passive mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-with-vpn-tunnel-in-passive-mode/m-p/313016#M80867</link>
      <description>&lt;P&gt;Thanks so much for your answers!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have another question:&lt;/P&gt;&lt;P&gt;Tunnel monitor is Palo Alto proprietary and as far as I know it should be use between Palo Alto peers to work optimally, am I right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Considering this if having a VPN between Palo Alto device and another vendor device, would path monitoring for a static route work similar than tunnel monitor?&amp;nbsp;&lt;/P&gt;&lt;P&gt;My idea is that sourcing the path-monitoring pings from the tunnel IP to remote peer´s IP could keep the tunnel up like tunnel monitoring does. (Not having the firewall in passive mode of course)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 09:15:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-with-vpn-tunnel-in-passive-mode/m-p/313016#M80867</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2020-02-26T09:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: tunnel monitor with VPN tunnel in passive mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-with-vpn-tunnel-in-passive-mode/m-p/313727#M80971</link>
      <description>&lt;P&gt;Q1 ) Tunnel monitor is Palo Alto proprietary and as far as I know it should be use between Palo Alto peers to work optimally, am I right?&lt;/P&gt;&lt;P&gt;Yes , tunnel monitor is Palo Alto Networks proprietary protocol.&lt;/P&gt;&lt;P&gt;Please see this link for more details.&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFaCAK#:~:text=" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFaCAK#:~:text=&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Q2 ) Considering this if having a VPN between Palo Alto device and another vendor device, would path monitoring for a static route work similar than tunnel monitor?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;In essence , the goal of path monitoring and tunnel monitoring are the same , but there are some differences.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;In Path Monitoring , If “all” or “any” of the monitored destinations for the static route are unreachable by ICMP, the firewall removes the static route from the RIB and FIB and adds the dynamic or static route that has the next lowest metric going to the same destination to the FIB.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;There are two possible actions that can be taken if a monitored destination fails with tunnel monitoring.&lt;BR /&gt;1) Wait recover. Wait for the tunnel to recover; do not take additional action.&lt;BR /&gt;2) Failover.Traffic will fail over to a backup path, if one is available. The firewall uses routing table lookup to determine routing for the duration of this session.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q) My idea is that sourcing the path-monitoring pings from the tunnel IP to remote peer´s IP could keep the tunnel up like tunnel monitoring does. (Not having the firewall in passive mode of course)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The function of Path monitoring and Tunnel monitoring is not to keep the “tunnel up” .&lt;BR /&gt;It is used to just monitor if a destination is reachable or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you still have any questions, please open a support ticket and one of us will help you.&lt;/P&gt;&lt;P&gt;Kavi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Mar 2020 02:47:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-with-vpn-tunnel-in-passive-mode/m-p/313727#M80971</guid>
      <dc:creator>kgopichand</dc:creator>
      <dc:date>2020-03-01T02:47:29Z</dc:date>
    </item>
  </channel>
</rss>

