<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec VPN phase2 partial up in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase2-partial-up/m-p/401527#M91718</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/111465"&gt;@DongQu&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;I am not sure I understadn your last comment.&lt;/P&gt;&lt;P&gt;Run&lt;/P&gt;&lt;P&gt;&amp;gt; test vpn ipsec-sa tunnel tu-ITIVIT:tu-ITIVIT&lt;BR /&gt;&amp;gt; show vpn flow&lt;/P&gt;&lt;P&gt;What is that status of this tunnel?&lt;/P&gt;&lt;P&gt;Immediately run&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; test vpn ipsec-sa tunnel tu-ITIVIT:tu-ITIVIT-2&lt;BR /&gt;&amp;gt; show vpn flow&lt;/P&gt;&lt;P&gt;What is the status of second tunnel?&lt;/P&gt;&lt;P&gt;If you execute "test vpn" for both proxy-id immediately one after another, are one still showing inactive?&lt;/P&gt;&lt;P&gt;Have you checked the logs? Go to system logs (where the ipsec s2s log are located) and you can add this filter&lt;/P&gt;&lt;P&gt;( object contains tu-ITIVIT )&lt;/P&gt;</description>
    <pubDate>Fri, 23 Apr 2021 15:30:25 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2021-04-23T15:30:25Z</dc:date>
    <item>
      <title>IPSec VPN phase2 partial up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase2-partial-up/m-p/401295#M91682</link>
      <description>&lt;P&gt;hello everyone&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a IPSec tunnel with Cisco ASA, and the proxy-id config is:&lt;/P&gt;&lt;P&gt;entry1: local 1.1.1.1 remote 2.2.2.2&lt;/P&gt;&lt;P&gt;entry2: local 1.1.1.1 remote 2.2.2.3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The very annoying things the phase2 is partial UP, when "show vpn flow", either entry1 is active and entry2 is inactive OR entry2 is active or entry1 is inactive.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DongQu_0-1619102922750.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32403i0B7DC020F0E64DD3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DongQu_0-1619102922750.png" alt="DongQu_0-1619102922750.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this due to the incorrect config in somewhere?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 14:48:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase2-partial-up/m-p/401295#M91682</guid>
      <dc:creator>DongQu</dc:creator>
      <dc:date>2021-04-22T14:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN phase2 partial up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase2-partial-up/m-p/401330#M91684</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/111465"&gt;@DongQu&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most probably you don't have constant traffic running for both remote networks.&lt;/P&gt;&lt;P&gt;If you see both active at different time this means negotiation is successfull for both and if there is real traffic tunnel should be fine.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 15:49:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase2-partial-up/m-p/401330#M91684</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-04-22T15:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN phase2 partial up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase2-partial-up/m-p/401446#M91700</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to use "test vpn ipsec-sa tunnel" to&amp;nbsp;Initiate the IPSec SA, after 1 of them getting "active", the other 1 cannot get up anymore.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 01:40:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase2-partial-up/m-p/401446#M91700</guid>
      <dc:creator>DongQu</dc:creator>
      <dc:date>2021-04-23T01:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN phase2 partial up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase2-partial-up/m-p/401464#M91707</link>
      <description>&lt;P&gt;First your proxy id seems wrong as it should be the private sybnets that&amp;nbsp; are internal for the firewalls (also check the ipsec timers if they match like the "lifetime"):&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClJ3CAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClJ3CAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClE6CAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClE6CAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If you still have issue:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;%%%%%%%%%%%%%%%%%%%%%%%&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Can you make the Palo Alto the responder as this way you will get more data in the GUI System log (or Globalprotect log in newer version)?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMZCA0" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMZCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also you can do a debug on the ikemgr:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;gt; debug ike global on debug&lt;BR /&gt;&amp;gt; less mp-log ikemgr.log&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Also check if DPD is disabled as maybe the ASA may have issues with it and test without it.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFaCAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFaCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;%%%%%%%%%%%%%%%%%%%%%%%%&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 07:29:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase2-partial-up/m-p/401464#M91707</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-04-23T07:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN phase2 partial up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase2-partial-up/m-p/401510#M91716</link>
      <description>&lt;P&gt;the palo told me that the DH group for the phase2 needs to use group 20 with Cisco while have multiple proxy-id, I was using group5.&lt;/P&gt;&lt;P&gt;The issue was gone after changing to group 20.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 13:23:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase2-partial-up/m-p/401510#M91716</guid>
      <dc:creator>DongQu</dc:creator>
      <dc:date>2021-04-23T13:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN phase2 partial up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase2-partial-up/m-p/401527#M91718</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/111465"&gt;@DongQu&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;I am not sure I understadn your last comment.&lt;/P&gt;&lt;P&gt;Run&lt;/P&gt;&lt;P&gt;&amp;gt; test vpn ipsec-sa tunnel tu-ITIVIT:tu-ITIVIT&lt;BR /&gt;&amp;gt; show vpn flow&lt;/P&gt;&lt;P&gt;What is that status of this tunnel?&lt;/P&gt;&lt;P&gt;Immediately run&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; test vpn ipsec-sa tunnel tu-ITIVIT:tu-ITIVIT-2&lt;BR /&gt;&amp;gt; show vpn flow&lt;/P&gt;&lt;P&gt;What is the status of second tunnel?&lt;/P&gt;&lt;P&gt;If you execute "test vpn" for both proxy-id immediately one after another, are one still showing inactive?&lt;/P&gt;&lt;P&gt;Have you checked the logs? Go to system logs (where the ipsec s2s log are located) and you can add this filter&lt;/P&gt;&lt;P&gt;( object contains tu-ITIVIT )&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 15:30:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase2-partial-up/m-p/401527#M91718</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-04-23T15:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN phase2 partial up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase2-partial-up/m-p/401530#M91719</link>
      <description>&lt;P&gt;while using the DH is group5 on the PA and Cisco ASA&lt;/P&gt;&lt;P&gt;&amp;gt; test vpn ipsec-sa tunnel tu-ITIVIT:tu-ITIVIT&lt;BR /&gt;&amp;gt; show vpn flow&lt;/P&gt;&lt;P&gt;What is that status of this tunnel?&amp;nbsp; &amp;nbsp;------&amp;nbsp;tu-ITIVIT:tu-ITIVIT -----&amp;gt; active&lt;/P&gt;&lt;P&gt;Immediately run&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; test vpn ipsec-sa tunnel tu-ITIVIT:tu-ITIVIT-2&lt;BR /&gt;&amp;gt; show vpn flow&lt;/P&gt;&lt;P&gt;What is the status of second tunnel?&amp;nbsp; &amp;nbsp;---------&amp;nbsp;&amp;nbsp;tu-ITIVIT:tu-ITIVIT-2------&amp;gt; inactive&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after changing DH to group20 on both sides.&lt;/P&gt;&lt;P&gt;&amp;gt; test vpn ipsec-sa tunnel tu-ITIVIT:tu-ITIVIT&lt;BR /&gt;&amp;gt; show vpn flow&lt;/P&gt;&lt;P&gt;What is that status of this tunnel?&amp;nbsp; &amp;nbsp;------&amp;nbsp;tu-ITIVIT:tu-ITIVIT -----&amp;gt; active&lt;/P&gt;&lt;P&gt;Immediately run&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; test vpn ipsec-sa tunnel tu-ITIVIT:tu-ITIVIT-2&lt;BR /&gt;&amp;gt; show vpn flow&lt;/P&gt;&lt;P&gt;What is the status of second tunnel?&amp;nbsp; &amp;nbsp;---------&amp;nbsp;&amp;nbsp;tu-ITIVIT:tu-ITIVIT-2------&amp;gt; active&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 15:34:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase2-partial-up/m-p/401530#M91719</guid>
      <dc:creator>DongQu</dc:creator>
      <dc:date>2021-04-23T15:34:35Z</dc:date>
    </item>
  </channel>
</rss>

