IPSec-ESP No matching record

Reply
L2 Linker

IPSec-ESP No matching record

The last few weeks I have noticed a large amount of traffic on the Network Monitor coming from IPSec-ESP.  I moved several VPN tunnels off our old WatchGuard to our Palo Alto PA-3020 around the time this started.  When I click on the application itself to filter it I see that it cannot identify anything about the traffic.  Is this normal?  Shouldn't it at least be able to identify the source or destination of the traffic?

ipsec.png

Tags (1)
L7 Applicator

Re: IPSec-ESP No matching record

Hello Clint,

ESP traffic is encrypted, hence, you would not be able to see the content of the packet. There might be an another possibility, if users are conneting through any VPN client, in that case also, firewall will identify as ESP traffic.

Thanks

L2 Linker

Re: IPSec-ESP No matching record

Hey Hulk,

Yeah that's what I figured but it just seems weird it can't even tell where it's coming from.  No VPN clients in this case.  Just regular VPN tunnels.

Thanks!

L6 Presenter

Re: IPSec-ESP No matching record

Hi Clint,

To get source and destination information of traffic, go to Monitor > Traffic > Type application "IPSec-ESP". You will find number of logs.

You will have to take Educated guess to find out origin of the traffic.

If Origin of the traffic is your own firewall, than dont worry its intended IPsec Traffic.

If not than there should be something behind the firewall, try to locate IP.

Regards,

Hardik Shah

L7 Applicator

Re: IPSec-ESP No matching record

Hello Clint,

You are correct. The ACC report will not show the traffic details i.e source, destination etc. As HArdik said, you can filter traffic in Logs to get details information.

FYI:

ipsec-esp.jpg

Hope this helps.

Thanks

L2 Linker

Re: IPSec-ESP No matching record

That's the thing is I see absolutely nothing with that application type that matches today's traffic and nothing in the amount I am seeing.  The latest entry filtering by that app is six days ago.

ipsec2.png

L4 Transporter

Re: IPSec-ESP No matching record

Hello Clint.leatherman,

What version of PAN-OS are you running?

Are the VPN tunnel interfaces in a separate zone or part of your untrust zone?

Regards,

David

L2 Linker

Re: IPSec-ESP No matching record

Hey David,

We are running 6.0.3 and the tunnel interfaces are in their own zone.

L7 Applicator

Re: IPSec-ESP No matching record

Hello Clint,

Is there any active session present on this PAN FW..? You may apply below mentioned CLI command:

> show session all filter protocol 50

ACC will give you the live session information, where traffic log will give you session information at the start or end.

Thanks

L2 Linker

Re: IPSec-ESP No matching record

Yes I see about ten entries.  If I filter the traffic monitor by the VPN zone I can see traffic destined for the different proxy-IDs.  I only see that large amount of traffic classified as IPSec-ESP 2-3 times per day, sometimes early in the morning when no one is here.  I have a feeling it is some backup job running on our SQL databases to a remote site but I just want to be sure.

ipsec3.png

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!