<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ipsec down after enabled tunnel monitor in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-down-after-enabled-tunnel-monitor/m-p/374576#M89070</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/142850"&gt;@Thyrion&lt;/a&gt;&amp;nbsp;Thanks for your reply&lt;/P&gt;&lt;P&gt;for the monitoring profile it configured as fail over&lt;/P&gt;&lt;P&gt;and we can reach the pear tunnel IP before enable tunnel monitor&amp;nbsp;&lt;/P&gt;&lt;P&gt;and there is a policy to allow ping&amp;nbsp;&lt;/P&gt;&lt;P&gt;but after enable&amp;nbsp;&amp;nbsp;tunnel monitor&amp;nbsp; the status goes down with no reason&lt;/P&gt;&lt;P&gt;and when we try to ping the peer tunnel IP in this time the reply is Destination Host Unreachable&lt;/P&gt;</description>
    <pubDate>Tue, 15 Dec 2020 20:04:04 GMT</pubDate>
    <dc:creator>MoatasemMetwaly</dc:creator>
    <dc:date>2020-12-15T20:04:04Z</dc:date>
    <item>
      <title>Ipsec down after enabled tunnel monitor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-down-after-enabled-tunnel-monitor/m-p/374499#M89063</link>
      <description>&lt;P&gt;I have tunnel ipsec site to site vpn after enabling tunnel monitor tunnel status is down although phase 1 and phase 2 are up.&lt;/P&gt;&lt;P&gt;Version 9.0.9-h1&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 12:48:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-down-after-enabled-tunnel-monitor/m-p/374499#M89063</guid>
      <dc:creator>Ahmad_ElKilany</dc:creator>
      <dc:date>2020-12-15T12:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec down after enabled tunnel monitor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-down-after-enabled-tunnel-monitor/m-p/374574#M89068</link>
      <description>&lt;P&gt;if both phases are still showing green ,the tunnel is actually up&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how did you set the monitoring profile? have you tested pinging the remote IP for reachability before enabling tunnel monitoring?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;double check if your security policy allows pinging the remote IP, double check if there is a need for additional routes or proxy-IDs for the remote IP, check if the IP is accepting ping (it may require a profile to be activated, or an ACL/security policy to be updated before you are able to ping it&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 19:07:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-down-after-enabled-tunnel-monitor/m-p/374574#M89068</guid>
      <dc:creator>Thyrion</dc:creator>
      <dc:date>2020-12-15T19:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec down after enabled tunnel monitor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-down-after-enabled-tunnel-monitor/m-p/374576#M89070</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/142850"&gt;@Thyrion&lt;/a&gt;&amp;nbsp;Thanks for your reply&lt;/P&gt;&lt;P&gt;for the monitoring profile it configured as fail over&lt;/P&gt;&lt;P&gt;and we can reach the pear tunnel IP before enable tunnel monitor&amp;nbsp;&lt;/P&gt;&lt;P&gt;and there is a policy to allow ping&amp;nbsp;&lt;/P&gt;&lt;P&gt;but after enable&amp;nbsp;&amp;nbsp;tunnel monitor&amp;nbsp; the status goes down with no reason&lt;/P&gt;&lt;P&gt;and when we try to ping the peer tunnel IP in this time the reply is Destination Host Unreachable&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 20:04:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-down-after-enabled-tunnel-monitor/m-p/374576#M89070</guid>
      <dc:creator>MoatasemMetwaly</dc:creator>
      <dc:date>2020-12-15T20:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec down after enabled tunnel monitor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-down-after-enabled-tunnel-monitor/m-p/374578#M89071</link>
      <description>&lt;P&gt;The 'fail-over' action will bring down the tunnel when the remote peer is unavailable&lt;/P&gt;&lt;P&gt;Do you have a backup tunnel to take over? If not, it is better to hold-wait, else the tunnel has no way of recovering from a fault&lt;/P&gt;&lt;P&gt;Hold-wait will also allow you to troubleshoot your tunnel monitor as it will not kill the tunnel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 20:33:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-down-after-enabled-tunnel-monitor/m-p/374578#M89071</guid>
      <dc:creator>Thyrion</dc:creator>
      <dc:date>2020-12-15T20:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec down after enabled tunnel monitor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-down-after-enabled-tunnel-monitor/m-p/374658#M89082</link>
      <description>&lt;P&gt;yes, I have a backup but I reach the peer when I disable the monitor when I enable it the peer is unreachable.&lt;/P&gt;&lt;P&gt;when I enable monitor, the peer unreachable but phase 1&amp;amp;2 green.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 08:23:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-down-after-enabled-tunnel-monitor/m-p/374658#M89082</guid>
      <dc:creator>Ahmad_ElKilany</dc:creator>
      <dc:date>2020-12-16T08:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec down after enabled tunnel monitor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-down-after-enabled-tunnel-monitor/m-p/374693#M89090</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163477"&gt;@Ahmad_ElKilany&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;I want first to clarify something - The ICMP probes generated by the tunnel monitor are &lt;STRONG&gt;not passing through the flow module&lt;/STRONG&gt; (&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGtCAK" target="_self"&gt;as explained here).&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Which measn:&lt;/P&gt;&lt;P&gt;- The ICMP probes are not passing through the security rules (no need to explicetly allow them)&lt;/P&gt;&lt;P&gt;- No route lookup is performed for those packets&lt;/P&gt;&lt;P&gt;- No logs are generated&lt;/P&gt;&lt;P&gt;- Packet capture cannot capture those packets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163885"&gt;@MoatasemMetwaly&lt;/a&gt;, &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163477"&gt;@Ahmad_ElKilany&lt;/a&gt; , the whole purpose of the tunnel monitor is to logically mark the tunnel as not working even if the phases are up. So if you see phase1 and phase 2 green, but status is red, this means that the IPsec tunnel (and phase1 &amp;amp; 2 settings are correct), but for some reason the pings generated by the tunnel monitor are dropped and FW is not receiving replies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would suggest you to check my comments here - &lt;A href="https://live.paloaltonetworks.com/t5/general-topics/fail-over-vpn-site-to-site/m-p/249792/highlight/true#M71033" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/fail-over-vpn-site-to-site/m-p/249792/highlight/true#M71033&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But in summary - My experiance so far shows that in most cases the tunnel monitor fails, because it doesn't match the Proxy-ID/Interesting traffic/Encryption Domains. When you enable tunnel monitor, firewall will use the IP address assinged on the logical tunnel interface as source IP for the ping packet and destination the monitored IP you are using. After that it will send those packets over the tunnel (will encrypt them), however if the source and destination IP does not match the proxy-id the remote device will reject the pings and you end will not receive any reply - marking the tunnel as down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So:&lt;/P&gt;&lt;P&gt;- Check if the source and destination IP of the probe packets are matching your proxy-id (if you are using any).&lt;/P&gt;&lt;P&gt;- Check what IP are you monitoring, are you pinging the remote peer IP&amp;nbsp; - If I remember correctly long ago the different FW vendors were behaving differently for the traffic send/received to the IPsec tunnel peer IP (some vendors were automatically accepting traffic between peer IPs to be encrypted in the tunnel, but other not)&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 13:35:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-down-after-enabled-tunnel-monitor/m-p/374693#M89090</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2020-12-16T13:35:30Z</dc:date>
    </item>
  </channel>
</rss>

