<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ALERT WHEN VPN DESTINATION STOP WORKING in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/alert-when-vpn-destination-stop-working/m-p/436665#M96291</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110075"&gt;@larry2019&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;When you say traffic to the specific host is lost, is that the only host you are monitoring or attempting to hit? When you experience this issue have you verified that traffic to other hosts across that VPN tunnel actually works?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would still recommend that you setup a tunnel monitoring profile and define the specific host as your monitored IP. The firewall will simply attempt to send ICMP traffic to the host and will alert you if the tunnel monitor IP goes down that you can setup alert forwarding for. I would leave the action on the tunnel monitor profile as Wait Recover and see if the firewall attempting to recover by renegotiating new keys solves the issue, because it seems like it would in this particular case. Give it a go and see if it doesn't at least give you a RTO without manual intervention.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 26 Sep 2021 05:30:06 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-09-26T05:30:06Z</dc:date>
    <item>
      <title>ALERT WHEN VPN DESTINATION STOP WORKING</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-when-vpn-destination-stop-working/m-p/436028#M96224</link>
      <description>&lt;P&gt;Hi everybody&lt;/P&gt;&lt;P&gt;Currently&amp;nbsp; have a vpn connection to a remote site , and now we are transferring many info along the day&lt;/P&gt;&lt;P&gt;But sometimes connection closes and transfer interrupts&lt;/P&gt;&lt;P&gt;So we want to sent alerts when this connection o transfer interrupts to be able to sends a kind of email alert&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 23:02:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-when-vpn-destination-stop-working/m-p/436028#M96224</guid>
      <dc:creator>larry2019</dc:creator>
      <dc:date>2021-09-22T23:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: ALERT WHEN VPN DESTINATION STOP WORKING</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-when-vpn-destination-stop-working/m-p/436044#M96225</link>
      <description>&lt;P&gt;Thank you for posting question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110075"&gt;@larry2019&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There might be different ways to do it, but probably most straightforward way is to configure new alert under: Device &amp;gt; Log Settings &amp;gt;&amp;nbsp; System&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can use for example following filter:&amp;nbsp;( subtype eq vpn ) and ( eventid eq tunnel-status-down )&lt;/P&gt;&lt;P&gt;and set email profile for alerting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1632355799421.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36575iD5B1FDCE69F7D662/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1632355799421.png" alt="PavelK_0-1632355799421.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 00:12:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-when-vpn-destination-stop-working/m-p/436044#M96225</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-09-23T00:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: ALERT WHEN VPN DESTINATION STOP WORKING</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-when-vpn-destination-stop-working/m-p/436350#M96256</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110075"&gt;@larry2019&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;In addition to what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;already mentioned, you can also configure &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/vpns/set-up-site-to-site-vpn/set-up-tunnel-monitoring.html" target="_self"&gt;tunnel monitoring&lt;/A&gt;&amp;nbsp;to have the firewall actually monitor traffic across that tunnel and alert when it goes down. The benefit of tunnel monitoring is that some non-PAN vendors (Cisco as an example) will actually bring down the tunnel if they don't have any traffic going across it for a set amount of time by default. By configuring tunnel monitoring you could potentially have the entire issue go away depending on how the other side is configured.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2021 01:59:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-when-vpn-destination-stop-working/m-p/436350#M96256</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-09-24T01:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: ALERT WHEN VPN DESTINATION STOP WORKING</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-when-vpn-destination-stop-working/m-p/436542#M96274</link>
      <description>&lt;P&gt;Thanks guys for the prompt reply.&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I comment in more detail on the scenario.&lt;BR /&gt;What happens is that although it is true, traffic is being transferred through the VPN, the tunnel never falls, connectivity to the specific destination is lost.&lt;BR /&gt;What I have to do is restart phase 2 to have connectivity, however returning I also require that when I lose connection to the vpn destination it sends me an alert.&lt;BR /&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2021 21:14:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-when-vpn-destination-stop-working/m-p/436542#M96274</guid>
      <dc:creator>larry2019</dc:creator>
      <dc:date>2021-09-24T21:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: ALERT WHEN VPN DESTINATION STOP WORKING</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-when-vpn-destination-stop-working/m-p/436665#M96291</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110075"&gt;@larry2019&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;When you say traffic to the specific host is lost, is that the only host you are monitoring or attempting to hit? When you experience this issue have you verified that traffic to other hosts across that VPN tunnel actually works?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would still recommend that you setup a tunnel monitoring profile and define the specific host as your monitored IP. The firewall will simply attempt to send ICMP traffic to the host and will alert you if the tunnel monitor IP goes down that you can setup alert forwarding for. I would leave the action on the tunnel monitor profile as Wait Recover and see if the firewall attempting to recover by renegotiating new keys solves the issue, because it seems like it would in this particular case. Give it a go and see if it doesn't at least give you a RTO without manual intervention.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Sep 2021 05:30:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-when-vpn-destination-stop-working/m-p/436665#M96291</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-09-26T05:30:06Z</dc:date>
    </item>
  </channel>
</rss>

