IPSec VPN issue

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

IPSec VPN issue

L3 Networker

Hi All,

 

We have configured IPSec VPN between PAN and AWS. 

 

When i iniate the tunnel, IPSec and IKE SA installed successfully as a initiator.

then, IKE protocol IPSec SA delete message sent to peer. SPI:0x...

After a second, IPSec key deleted. Deleted SA..... please suggest 

 

 

6 REPLIES 6

L6 Presenter

Soundslike some reachibility test fails. Check if you are dropping something towards AWS peers.

 

L5 Sessionator

Does the phase one is comming up? If yes then the issue with proxy ID.

Have you opened the udp port 500 and udp 4500 on the AWS?

Are you able to ping the public IP address?

Can you set vpn on Palo into passive mode and initiate vpn from other side?

System log on Palo shows pretty exactly at what state vpn fails.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

The only options are Main, Auto, and Agressive. You can play with those. But like pakumar pointed out. If its phase 2, it could be proxy id's.

 

Its under Ike Gateway -> Advanced Phase 1 options.

Of course i didnt look very hard, Yes there is a Passive option in the IKE gateway.

According to original post (Quote:"When i iniate the tunnel, IPSec and IKE SA installed successfully as a initiator.") I'd say all parameters are ok and IPSEC is esatblished sucesfully but DPD mechanism kicks in and takes it down. 

  • 2898 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!