<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with traffic on specific proxy id in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-traffic-on-specific-proxy-id/m-p/338343#M85090</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Thanks for your responses and time, really appreciate it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have issue with other proxy id on the same VPN tunnel. Ping works either way. Its just this specific one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no disconnection on other proxy ids&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jul 2020 04:41:34 GMT</pubDate>
    <dc:creator>yshaikh</dc:creator>
    <dc:date>2020-07-14T04:41:34Z</dc:date>
    <item>
      <title>Issue with traffic on specific proxy id</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-traffic-on-specific-proxy-id/m-p/338293#M85078</link>
      <description>&lt;P&gt;We have VPN between Palo Alto and Cisco FMC/FTD.&lt;/P&gt;&lt;P&gt;There is user and server traffic on VPN. VPN status is stable. I don't have any user complaining about disconnection.&lt;/P&gt;&lt;P&gt;But I am seeing disconnection on specific proxyid. All of sudden I am getting ICMP request time out on working connection.&lt;/P&gt;&lt;P&gt;Facing request time out when ping is from Server which is behind Palo Alto.&lt;/P&gt;&lt;P&gt;To make connection up, either I need to generate Interesting traffic from FMC or ping from Server which is behind FMC. This restore request time out issue from the Server which is behind Palo Alto.&lt;/P&gt;&lt;P&gt;I don't undertstand what could be reason for behind this specific connection.&lt;/P&gt;&lt;P&gt;yshaikhadmin@SPDORC-FW02(active)&amp;gt; show vpn flow tunnel-id 358&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Request time out started, checked vpn flow:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;yshaikhadmin@SPDORC-FW02(active)&amp;gt; show vpn flow tunnel-id 358&lt;/P&gt;&lt;P&gt;tunnel Orbit:test-mig-1&lt;BR /&gt;id: 358&lt;BR /&gt;type: IPSec&lt;BR /&gt;gateway id: 9&lt;BR /&gt;local ip: x&lt;BR /&gt;peer ip: x&lt;BR /&gt;inner interface: tunnel.17&lt;BR /&gt;outer interface: ethernet1/1&lt;BR /&gt;state: active&lt;BR /&gt;session: 444419&lt;BR /&gt;tunnel mtu: 1428&lt;BR /&gt;lifetime remain: 2475 sec&lt;BR /&gt;lifesize remain: 4607944 kb&lt;BR /&gt;latest rekey: 1125 seconds ago&lt;BR /&gt;monitor: off&lt;BR /&gt;monitor packets seen: 0&lt;BR /&gt;monitor packets reply:0&lt;BR /&gt;en/decap context: 5679&lt;BR /&gt;local spi: 9F518E95&lt;BR /&gt;remote spi: 8EBEAD75&lt;BR /&gt;key type: auto key&lt;BR /&gt;protocol: ESP&lt;BR /&gt;auth algorithm: SHA1&lt;BR /&gt;enc algorithm: AES256&lt;BR /&gt;proxy-id:&lt;BR /&gt;local ip: x&lt;BR /&gt;remote ip: x&lt;BR /&gt;protocol: 0&lt;BR /&gt;local port: 0&lt;BR /&gt;remote port: 0&lt;BR /&gt;anti replay check: no&lt;BR /&gt;copy tos: no&lt;BR /&gt;authentication errors: 0&lt;BR /&gt;decryption errors: 0&lt;BR /&gt;inner packet warnings: 0&lt;BR /&gt;replay packets: 0&lt;BR /&gt;packets received&lt;BR /&gt;when lifetime expired:0&lt;BR /&gt;when lifesize expired:0&lt;BR /&gt;sending sequence: 645&lt;BR /&gt;receive sequence: 0&lt;BR /&gt;encap packets: 58580&lt;BR /&gt;decap packets: 14429&lt;BR /&gt;encap bytes: 5230576&lt;BR /&gt;decap bytes: 1274216&lt;BR /&gt;key acquire requests: 1&lt;BR /&gt;owner state: 0&lt;BR /&gt;owner cpuid: s1dp0&lt;BR /&gt;ownership: 1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;when I started ping from server behind cisco FMC then ping restored. I can see that rekeying happens.&lt;/P&gt;&lt;P&gt;tunnel Orbit:test-mig-1&lt;BR /&gt;id: 358&lt;BR /&gt;type: IPSec&lt;BR /&gt;gateway id: 9&lt;BR /&gt;local ip: x&lt;BR /&gt;peer ip: x&lt;BR /&gt;inner interface: tunnel.17&lt;BR /&gt;outer interface: ethernet1/1&lt;BR /&gt;state: active&lt;BR /&gt;session: 197328&lt;BR /&gt;tunnel mtu: 1428&lt;BR /&gt;lifetime remain: 3594 sec&lt;BR /&gt;lifesize remain: 4607999 kb&lt;BR /&gt;latest rekey: 6 seconds ago&lt;BR /&gt;monitor: off&lt;BR /&gt;monitor packets seen: 0&lt;BR /&gt;monitor packets reply:0&lt;BR /&gt;en/decap context: 391&lt;BR /&gt;local spi: 8D78AF05&lt;BR /&gt;remote spi: 90040096&lt;BR /&gt;key type: auto key&lt;BR /&gt;protocol: ESP&lt;BR /&gt;auth algorithm: SHA1&lt;BR /&gt;enc algorithm: AES256&lt;BR /&gt;proxy-id:&lt;BR /&gt;local ip: x&lt;BR /&gt;remote ip: x&lt;BR /&gt;protocol: 0&lt;BR /&gt;local port: 0&lt;BR /&gt;remote port: 0&lt;BR /&gt;anti replay check: no&lt;BR /&gt;copy tos: no&lt;BR /&gt;authentication errors: 0&lt;BR /&gt;decryption errors: 0&lt;BR /&gt;inner packet warnings: 0&lt;BR /&gt;replay packets: 0&lt;BR /&gt;packets received&lt;BR /&gt;when lifetime expired:0&lt;BR /&gt;when lifesize expired:0&lt;BR /&gt;sending sequence: 4&lt;BR /&gt;receive sequence: 0&lt;BR /&gt;encap packets: 58593&lt;BR /&gt;decap packets: 14433&lt;BR /&gt;encap bytes: 5231720&lt;BR /&gt;decap bytes: 1274568&lt;BR /&gt;key acquire requests: 1&lt;BR /&gt;owner state: 0&lt;BR /&gt;owner cpuid: s1dp0&lt;BR /&gt;ownership: 1&lt;/P&gt;&lt;P&gt;yshaikhadmin@SPDORC-FW02(active)&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I think after rekeying process, some how Palo Alto not able to keep this connection alive, not sure why&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 02:31:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-traffic-on-specific-proxy-id/m-p/338293#M85078</guid>
      <dc:creator>yshaikh</dc:creator>
      <dc:date>2020-07-14T02:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with traffic on specific proxy id</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-traffic-on-specific-proxy-id/m-p/338311#M85079</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/148961"&gt;@yshaikh&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;While it's odd that your ICMP request isn't keeping the connection alive by itself, since that should be generating interesting traffic to keep the tunnel up on the Cisco side, it sounds like Cisco is really who you should be reaching out to in this scenario.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 02:44:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-traffic-on-specific-proxy-id/m-p/338311#M85079</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-14T02:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with traffic on specific proxy id</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-traffic-on-specific-proxy-id/m-p/338314#M85081</link>
      <description>&lt;P&gt;if I do icmp from server behind PA firewall nothing happens.&lt;/P&gt;&lt;P&gt;if I do icmp from server behind Cisco firewall, ping becomes ok&lt;BR /&gt;&lt;BR /&gt;I discussed with Cisco also, they are saying you need to check with Palo Alto why Palo Alto doesn't send anything on VPN for that specific connection, why connection gets alive when do ping from Cisco Server&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Cisco:&lt;/P&gt;&lt;P&gt;&amp;gt; Found no debug logs for the specific SA until we start it manually&lt;/P&gt;&lt;P&gt;&amp;gt; Looks like the remote end is unable to start an SA for the particular traffic&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 02:49:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-traffic-on-specific-proxy-id/m-p/338314#M85081</guid>
      <dc:creator>yshaikh</dc:creator>
      <dc:date>2020-07-14T02:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with traffic on specific proxy id</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-traffic-on-specific-proxy-id/m-p/338337#M85088</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/148961"&gt;@yshaikh&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The connection is re-established when you ping from the Cisco side because Cisco will bring their side back up when it has interested traffic. By default, if it hasn't seen any interesting traffic it will bring that tunnel offline until such time that interesting traffic is passed. This isn't a PAN behavior, you could have absolutely no interesting traffic traverse that tunnel and PAN doesn't care and will keep the tunnel up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have the PAN side monitoring the connection and actively sending ICMP traffic down that SA at regular intervals, or are you only checking once something is reported as non-reachable? Do you see regular traffic crossing the firewall for that SA or is the traffic minimal? I'd be very surprised to see this be an issue on the PAN side of things to be honest; this sounds like the Cisco side is collapsing the SA due to non-interesting traffic.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 03:31:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-traffic-on-specific-proxy-id/m-p/338337#M85088</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-14T03:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with traffic on specific proxy id</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-traffic-on-specific-proxy-id/m-p/338343#M85090</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Thanks for your responses and time, really appreciate it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have issue with other proxy id on the same VPN tunnel. Ping works either way. Its just this specific one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no disconnection on other proxy ids&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 04:41:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-traffic-on-specific-proxy-id/m-p/338343#M85090</guid>
      <dc:creator>yshaikh</dc:creator>
      <dc:date>2020-07-14T04:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with traffic on specific proxy id</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-traffic-on-specific-proxy-id/m-p/367232#M88809</link>
      <description>&lt;P&gt;HI!&lt;/P&gt;&lt;P&gt;I have the same issue..&lt;/P&gt;&lt;P&gt;have you found a way around for this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Pramod&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 06:33:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-traffic-on-specific-proxy-id/m-p/367232#M88809</guid>
      <dc:creator>pramodl</dc:creator>
      <dc:date>2020-12-04T06:33:01Z</dc:date>
    </item>
  </channel>
</rss>

