IPsec tunnel connectivity issues

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

IPsec tunnel connectivity issues

L2 Linker

Hi, I have an IPsec Tunnel between 2 PA's and the status of tunnel and iKE shows red but the interface is green. Please advice on the troubleshooting steps.

3 REPLIES 3

Cyber Elite
Cyber Elite

Hello,

If the status of the tunnel is red, then it is not established. Check the System logs to see if there are any errors relating to the IKE or IPSec. Also here is a link I of things I typically use to troubleshoot tunnels.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC

 

Regards,

L6 Presenter

Also check the system logs from the firewall that is a responder or just make one the responder and then check from it:

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMZCA0

 

 

If th system logs don't help then enable pcap on the ike process. If the pcap is empty eiither the security policy blocks the ike or the packets don't reach the palo alto devices, so check the network between them.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC

Hi @Akhil_B ,

Interface status (the icon in the very right) is showing the status of the logical tunnel interface associated with that IPsec VPN. This tunnel is logical (something like loopback interface) it will never go done by itself.

The other two icons (green/red dots) are representing the actual IPsec Phase1 and Phase2 status.

 

So if you see any of the dots red this means that this phase failed to negotiate.

 

Going back to the interface status. In short you can completely ignore this status unless you are using tunnel monitor. Without tunnel monitor the tunnel interface will always be up. Tunnel monitor is a feature which will "shutdown" the tunnel interface if it detects issue with the tunnel.

 

  • 3179 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!