<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec tunnel connectivity issues in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-connectivity-issues/m-p/401261#M91676</link>
    <description>&lt;P&gt;Also check the system logs from the firewall that is a responder or just make one the responder and then check from it:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMZCA0" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMZCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If th system logs don't help then enable pcap on the ike process. If the pcap is empty eiither the security policy blocks the ike or the packets don't reach the palo alto devices, so check the network between them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Apr 2021 13:53:45 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2021-04-22T13:53:45Z</dc:date>
    <item>
      <title>IPsec tunnel connectivity issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-connectivity-issues/m-p/401002#M91655</link>
      <description>&lt;P&gt;Hi, I have an IPsec Tunnel between 2 PA's and the status of tunnel and iKE shows red but the interface is green. Please advice on the troubleshooting steps.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 19:32:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-connectivity-issues/m-p/401002#M91655</guid>
      <dc:creator>Akhil_B</dc:creator>
      <dc:date>2021-04-21T19:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel connectivity issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-connectivity-issues/m-p/401023#M91657</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;If the status of the tunnel is red, then it is not established. Check the System logs to see if there are any errors relating to the IKE or IPSec. Also here is a link I of things I typically use to troubleshoot tunnels.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 21:40:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-connectivity-issues/m-p/401023#M91657</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-04-21T21:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel connectivity issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-connectivity-issues/m-p/401261#M91676</link>
      <description>&lt;P&gt;Also check the system logs from the firewall that is a responder or just make one the responder and then check from it:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMZCA0" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMZCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If th system logs don't help then enable pcap on the ike process. If the pcap is empty eiither the security policy blocks the ike or the packets don't reach the palo alto devices, so check the network between them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 13:53:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-connectivity-issues/m-p/401261#M91676</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-04-22T13:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel connectivity issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-connectivity-issues/m-p/401541#M91721</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/173136"&gt;@Akhil_B&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;Interface status (the icon in the very right) is showing the status of the logical tunnel interface associated with that IPsec VPN. This tunnel is logical (something like loopback interface) it will never go done by itself.&lt;/P&gt;&lt;P&gt;The other two icons (green/red dots) are representing the actual IPsec Phase1 and Phase2 status.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So if you see any of the dots red this means that this phase failed to negotiate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Going back to the interface status. In short you can completely ignore this status &lt;U&gt;unless you are using tunnel monitor&lt;/U&gt;. Without tunnel monitor the tunnel interface will always be up. Tunnel monitor is a feature which will "shutdown" the tunnel interface if it detects issue with the tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 16:07:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-connectivity-issues/m-p/401541#M91721</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-04-23T16:07:35Z</dc:date>
    </item>
  </channel>
</rss>

