<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problems with IPSec tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problems-with-ipsec-tunnel/m-p/356083#M87617</link>
    <description>&lt;P&gt;set the tunnel monitor from wait-recover to fail over so the tunnel gets torn down once the monitor fails&lt;/P&gt;</description>
    <pubDate>Tue, 13 Oct 2020 14:40:44 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2020-10-13T14:40:44Z</dc:date>
    <item>
      <title>Problems with IPSec tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problems-with-ipsec-tunnel/m-p/355764#M87582</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I have a PA VM100 which hangs behind a dynamic public IP and it creates an IPSec tunnel to a PA220 with static public IP.&amp;nbsp; So the tunnel can only be established by the VM100. On the PA220 I have activated "Enable Passive Mode" at IKE Gateway -&amp;gt; advanced Options. DPD Interval 5 and Retry 5.&lt;BR /&gt;I also set up a tunnel monitor and gave the tunnel interfaces IPs. As tunnel monitor profile I chose default (wait recover - interval 3sek - threshold 5).&lt;/P&gt;&lt;P&gt;Unfortunately the internet connection is not the best and there are always disconnections (more then 10 on a day). Sometimes the tunnel will rebuild itself, sometimes you have to take action yourself. Then you can see that on the pa220 under session there is still the session ipsec 4500. You can also see that the tunnel ipsec is still green but ike already red.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What can I do to ensure that the tunnel rebuilds as quickly as possible in the event of a failure?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 13:10:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problems-with-ipsec-tunnel/m-p/355764#M87582</guid>
      <dc:creator>clonesheep</dc:creator>
      <dc:date>2020-10-12T13:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with IPSec tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problems-with-ipsec-tunnel/m-p/356083#M87617</link>
      <description>&lt;P&gt;set the tunnel monitor from wait-recover to fail over so the tunnel gets torn down once the monitor fails&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 14:40:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problems-with-ipsec-tunnel/m-p/356083#M87617</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-10-13T14:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with IPSec tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problems-with-ipsec-tunnel/m-p/356088#M87619</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;You might want to try a DDNS, dynamic domain name ssytem, solution? This way the VM PAN will register istes automatically and then the PA-220 can just have a DNS name as its peer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/configure-dynamic-dns-for-firewall-interfaces" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/configure-dynamic-dns-for-firewall-interfaces&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/networking-features/dynamic-dns-nfg" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/networking-features/dynamic-dns-nfg&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just a thought.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 16:45:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problems-with-ipsec-tunnel/m-p/356088#M87619</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-10-13T16:45:34Z</dc:date>
    </item>
  </channel>
</rss>

