<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Doubt about multiple SAs in IPSEC tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/doubt-about-multiple-sas-in-ipsec-tunnel/m-p/422297#M94051</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a tunnel working but looking in the logs we see many installed SAs. So we think it should be a SA for line in proxy ID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So why all these logs about "installed SA"?&amp;nbsp; Any idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpnjs.JPG" style="width: 255px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35252i1ADC9F1F9A3C4936/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vpnjs.JPG" alt="vpnjs.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Jul 2021 11:37:44 GMT</pubDate>
    <dc:creator>BigPalo</dc:creator>
    <dc:date>2021-07-27T11:37:44Z</dc:date>
    <item>
      <title>Doubt about multiple SAs in IPSEC tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/doubt-about-multiple-sas-in-ipsec-tunnel/m-p/422297#M94051</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a tunnel working but looking in the logs we see many installed SAs. So we think it should be a SA for line in proxy ID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So why all these logs about "installed SA"?&amp;nbsp; Any idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpnjs.JPG" style="width: 255px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35252i1ADC9F1F9A3C4936/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vpnjs.JPG" alt="vpnjs.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 11:37:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/doubt-about-multiple-sas-in-ipsec-tunnel/m-p/422297#M94051</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2021-07-27T11:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: Doubt about multiple SAs in IPSEC tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/doubt-about-multiple-sas-in-ipsec-tunnel/m-p/422510#M94069</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;What is the timestamp for each "installed SA" log?&lt;/P&gt;&lt;P&gt;It should be correct that you will have SA for each "proxy id line". But looking at your logs it seems that your Phase2 is configured with lifetime of one hour (3600sec)&amp;nbsp;&lt;U&gt;and&lt;/U&gt; lifesize of round 4,6GB. Which means that either of those end FW will delete the SA and negotiate new one. But if the SA aged out you should see log for deleting SA as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- What is the timestamp of the logs?&lt;/P&gt;&lt;P&gt;- Are you using log filter to list the above logs? What is the filter?&lt;/P&gt;&lt;P&gt;- How many proxy-ids do you have?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 22:21:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/doubt-about-multiple-sas-in-ipsec-tunnel/m-p/422510#M94069</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-07-27T22:21:59Z</dc:date>
    </item>
  </channel>
</rss>

