Headsup: AZURE VPN not comming up again, session discarding

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Headsup: AZURE VPN not comming up again, session discarding

L1 Bithead

Hi,

 

I just want to share a problem i have been troubleshooting. I have lots of vpn's terminating on our FW, haven't had real problems until i started to connect Azure VPN's. After a network hickup they usually did not come up again. I had the hardest time in finding out why. It seems that Azure sends so many IKE initiation packets that if for some reason (network hickup) we get a discard session in the session table it will allmost never get rid of this session by itself (i guess because the default session timout for udp discarding is 60 seconds and Azure sends an init at least 1 every 15 seconds.) So to get your vpn up and running again, go to sessions on the monitor pane, filter 'state eq discard', clear the session from your peer (should be port udp 500, and in my case the app was unknown-udp, that was the reason it started to discard in the first place). I am testing with a udp discard timout of 10 seconds now.

 

Hope this helps some of you!

2 REPLIES 2

L6 Presenter

l had something similar with SIP session before:

 

https://live.paloaltonetworks.com/t5/General-Topics/SIP-aged-out-session-being-left-in-the-DISCARD-s...

 

You are not running 7.1.3 or any lower PAN-OS release, are you?

No, we are running 8.0.1 at the moment

  • 1888 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!