- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-21-2021 12:32 PM
Hi, I have an IPsec Tunnel between 2 PA's and the status of tunnel and iKE shows red but the interface is green. Please advice on the troubleshooting steps.
04-21-2021 02:40 PM
Hello,
If the status of the tunnel is red, then it is not established. Check the System logs to see if there are any errors relating to the IKE or IPSec. Also here is a link I of things I typically use to troubleshoot tunnels.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC
Regards,
04-22-2021 06:51 AM - edited 04-22-2021 06:53 AM
Also check the system logs from the firewall that is a responder or just make one the responder and then check from it:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMZCA0
If th system logs don't help then enable pcap on the ike process. If the pcap is empty eiither the security policy blocks the ike or the packets don't reach the palo alto devices, so check the network between them.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC
04-23-2021 09:07 AM
Hi @Akhil_B ,
Interface status (the icon in the very right) is showing the status of the logical tunnel interface associated with that IPsec VPN. This tunnel is logical (something like loopback interface) it will never go done by itself.
The other two icons (green/red dots) are representing the actual IPsec Phase1 and Phase2 status.
So if you see any of the dots red this means that this phase failed to negotiate.
Going back to the interface status. In short you can completely ignore this status unless you are using tunnel monitor. Without tunnel monitor the tunnel interface will always be up. Tunnel monitor is a feature which will "shutdown" the tunnel interface if it detects issue with the tunnel.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!