- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-15-2022 11:16 PM
Hello,
We have 2 IPsec tunnels s2s between 2 Palo Alto firewalls.
We are using ike-v2 gateways, and liveness check : 5s
The WAN on one of the side is flapping, sometimes disconnect around 10min. After this disconnection, the tunnel does not re-establish immediately, it takes around 15min.
We have also configured tunnel monitors on both sides, we have assigned IP addresses on tunnel interfaces, and we are monitoring these IPs, the monitor are UP and active.
Do you know why it's not reconnecting immediately after the WAN back up ? Is there something to do in terms of config ?
02-15-2023 10:56 AM
I am seeing a similar issue that I'm trying to work through. In your setup, is there is a single WAN interface at the site, or are you failing over to another WAN interface? Is either side of the tunnel in dynamic, or passive mode?
Do you have "Liveness Check" enabled in the IKE settings?
02-15-2023 10:58 AM
Also is there any NAT involved and if so, do you have NAT-T enabled?
02-20-2023 02:43 AM
Better enable IKE debugs and to see what is happening as to not make wild suggestions:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcKCAS
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PORsCAO
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!