<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPSec VPN and Dead Peer Detection (DPD) in IKEv1 and Liveness check in IKEv2 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-and-dead-peer-detection-dpd-in-ikev1-and-liveness/m-p/373715#M88951</link>
    <description>&lt;P&gt;I have two different IPSec VPN tunnels between a PAN and two different Cisco devices, let call them R1 and R2, as folllows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN IPSec IKEv1 &amp;lt;&amp;lt;----&amp;gt;&amp;gt; Cisco R2 IKEv1&lt;/P&gt;&lt;P&gt;PAN IPSec IKEv2 &amp;lt;&amp;lt;----&amp;gt;&amp;gt; Cisco R1 IKEv2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I enable Dead Peer Dection (DPD) in the IKE gateway between the PAN IKEv1 and Cisco R2 router.&amp;nbsp; On the Dead Peer interval and retry, i set it to 5 and 5, respectively.&amp;nbsp; On the Cisco router R2, I set "set crypto isakmp keepalive 10".&amp;nbsp; On the IKE gateway between the PAN and Cisco R1 IKEv2, I set the "liveness check" to 5.&amp;nbsp; I also set "crypto isakmp keepalive 10" on the R2 cisco router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well, on the IKEv2 VPN tunnels, I see traffics every 5 seconds between the PAN and Cisco R2 even when there is no traffic going across the tunnel which is expected.&amp;nbsp; However, I am not seeing traffics between the PAN and Cisco R1 even with DPD enable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that expected?&amp;nbsp; If not, is this another bug in PAN? &amp;nbsp; I am running 8.1.15 hotfix 3.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Dec 2020 00:44:09 GMT</pubDate>
    <dc:creator>dtran</dc:creator>
    <dc:date>2020-12-11T00:44:09Z</dc:date>
    <item>
      <title>IPSec VPN and Dead Peer Detection (DPD) in IKEv1 and Liveness check in IKEv2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-and-dead-peer-detection-dpd-in-ikev1-and-liveness/m-p/373715#M88951</link>
      <description>&lt;P&gt;I have two different IPSec VPN tunnels between a PAN and two different Cisco devices, let call them R1 and R2, as folllows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN IPSec IKEv1 &amp;lt;&amp;lt;----&amp;gt;&amp;gt; Cisco R2 IKEv1&lt;/P&gt;&lt;P&gt;PAN IPSec IKEv2 &amp;lt;&amp;lt;----&amp;gt;&amp;gt; Cisco R1 IKEv2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I enable Dead Peer Dection (DPD) in the IKE gateway between the PAN IKEv1 and Cisco R2 router.&amp;nbsp; On the Dead Peer interval and retry, i set it to 5 and 5, respectively.&amp;nbsp; On the Cisco router R2, I set "set crypto isakmp keepalive 10".&amp;nbsp; On the IKE gateway between the PAN and Cisco R1 IKEv2, I set the "liveness check" to 5.&amp;nbsp; I also set "crypto isakmp keepalive 10" on the R2 cisco router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well, on the IKEv2 VPN tunnels, I see traffics every 5 seconds between the PAN and Cisco R2 even when there is no traffic going across the tunnel which is expected.&amp;nbsp; However, I am not seeing traffics between the PAN and Cisco R1 even with DPD enable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that expected?&amp;nbsp; If not, is this another bug in PAN? &amp;nbsp; I am running 8.1.15 hotfix 3.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 00:44:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-and-dead-peer-detection-dpd-in-ikev1-and-liveness/m-p/373715#M88951</guid>
      <dc:creator>dtran</dc:creator>
      <dc:date>2020-12-11T00:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN and Dead Peer Detection (DPD) in IKEv1 and Liveness check in IKEv2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-and-dead-peer-detection-dpd-in-ikev1-and-liveness/m-p/373739#M88955</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41973"&gt;@dtran&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;DPD on the PAN side isn't persistent and is only triggered by a phase 2 rekey; as long as phase 2 is up, the PAN won't check to see if IKE-SA is active. If you want/need to have traffic traverse from the PAN side constantly you would want to setup tunnel monitoring.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 03:21:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-and-dead-peer-detection-dpd-in-ikev1-and-liveness/m-p/373739#M88955</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-12-11T03:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN and Dead Peer Detection (DPD) in IKEv1 and Liveness check in IKEv2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-and-dead-peer-detection-dpd-in-ikev1-and-liveness/m-p/373854#M88968</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;:&amp;nbsp; "If you want/need to have traffic traverse from the PAN side constantly you would want to setup tunnel monitoring. "&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN VPN Peer is 1.1.1.1 and Cisco VPN Peer is 2.2.2.2&lt;/P&gt;&lt;P&gt;PAN Encryption Domain is 192.168.1.1 and Cisco VPN Encryption Domain is 192.168.2.&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/vpns/set-up-site-to-site-vpn/set-up-tunnel-monitoring/define-a-tunnel-monitoring-profile.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/vpns/set-up-site-to-site-vpn/set-up-tunnel-monitoring/define-a-tunnel-monitoring-profile.html&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;What IP address do I put in the box?&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 12:43:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-and-dead-peer-detection-dpd-in-ikev1-and-liveness/m-p/373854#M88968</guid>
      <dc:creator>dtran</dc:creator>
      <dc:date>2020-12-11T12:43:21Z</dc:date>
    </item>
  </channel>
</rss>

