IPsec tunnel takes long time to re-establish

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

IPsec tunnel takes long time to re-establish

L0 Member

Hello,

 

We have 2 IPsec tunnels s2s between 2 Palo Alto firewalls.

We are using ike-v2 gateways, and liveness check : 5s

 

The WAN on one of the side is flapping, sometimes disconnect around 10min. After this disconnection, the tunnel does not re-establish immediately, it takes around 15min.

 

We have also configured tunnel monitors on both sides, we have assigned IP addresses on tunnel interfaces, and we are monitoring these IPs, the monitor are UP and active.

 

Do you know why it's not reconnecting immediately after the WAN back up ? Is there something to do in terms of config ?

4 REPLIES 4

L0 Member

In fact, when the public IP is reachable again, we can see the tunnel is briefly re-established then go down again, and we need to bounce it manually to have it reconnected.

L3 Networker

I am seeing a similar issue that I'm trying to work through. In your setup, is there is a single WAN interface at the site, or are you failing over to another WAN interface? Is either side of the tunnel in dynamic, or passive mode?

Do you have "Liveness Check" enabled in the IKE settings?

L3 Networker

Also is there any NAT involved and if so, do you have NAT-T enabled?

L6 Presenter
  • 1963 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!