07-05-2012 09:47 AM
Hello guys
We have a few VPN tunnels between our PA-2050 (in HA cluster) and some WatchGuard firewalls (different models). We migrated these tunnels to the PA-2050 a few weeks ago and they ran stable. Now suddenly two of 10 tunnels are down and we don't get them back up.
Here's what we tried so far:
- Rebooting the WatchGuard firewalls
- Suspending the active PA-2050 so the standby HA device takes over
- Removing the VPN config on the WatchGuards and rebuild them (only VPN part)
- Overwrite the PSK on both ends
- On the PA-2050 CLI: clear vpn ike-sa gateway <gw-name> and clear vpn ipsec-sa tunnel <tunnel-name>
- some more small stuff
The config is the same on all tunnels, including the two not working...
Any inputs would on how we can further troubleshoot the issue would be much appreciated. The connection by the way is working. We can ping the endpoints mutually and we can also access the external admin interface of the remote WatchGuard firewalls...
Thanks!
Oliver
07-06-2012 10:41 AM
Oliver,
In your case it was the combination of downgrading and clearing the ike session in Discard state.
Tunnels did not come up after downgrade as their was a stale ike session on the firewall.
Typically in this case ike-manager logs would show message "Phase-2 rekey request ignored: previous request still in progress"
07-05-2012 11:42 AM
Could you try downgrading to Content version : 315-1427
Saw couple of cases where this worked for me.
Regards,
Ameya
07-05-2012 01:12 PM
We managed to get one of the two tunnels up by changing the external IP address of the tunnel endpoint on the PA-2050 side. We have multiple external IP addresses and all tunnels were configured to use the same IP. At the time we changed the IP on one of the tunnels not working it came back up... We tried the same for the other tunnel still down and it didn't help...
None of the reverts back to any of the following versions worked for us:
- 316-1432
- 315-1427
- 314-1424
For the last two (315 and 314) we could only install the Content package using Panorama. It was not possible to also install the App package of that version (error message we got was: No matching contents package found in panupv2-all-apps-<version>).
Thanks,
Oliver
07-05-2012 02:14 PM
After countless trials we finally got the last tunnel up as well. It came back up when we cleared the IPSec/IKE session for that tunnel on the PA-2050.
07-06-2012 05:21 AM
A longshot here but did these problems start last sunday (1st july)?
Im thinking of the leapsecond stuff...
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!