vpn issue

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

vpn issue

L6 Presenter

Hi,

After side to side vpn established correctly after sometime(I do not know how many hours) Phase1 becomes passive.Side1 cannot access Side2.

when we try to use test vpn command for ike it becomes up and it works.What can be reason for that ?

7 REPLIES 7

L5 Sessionator

Good Morning,

There are couple of reasons for that:

1) The sites lost networks connectivity between them for a certain duration and during that time the ike and esp sessions timed out on the firewall

2) Either of the site did not rekey and hence after the session key became invalid, that the sites couldnt process the ike traffic.

How long were the VPNs up and running prior to seeing this issue. Are both the devices PANFWs?

juniper other side

I don't know how long but I'll look forward to catch time details.

I would suspect that either site did not rekey, to be the primary reason. Its not a mandatory setting for the rekeying timing to match on both the devices, but keeping the same value on both the devices, would force both the devices to rekey after the lifetime of the session keys have expired.

Did you notice just the phase 1 going down, with the actual tunnel traffic still flowing (phase-2 being up and passing ESP traffic), or were both phase 1 and phase 2 down?

If its the latter, then I would suspect the lost internet connectivity between them

BR,

Karthik

L5 Sessionator

If there was no traffic passing through the tunnel the tunnel might have come down.

As you said as soon as you ran test command the tunnel came back up.

Next time if you see tunnel go down. I will suggest rather than running the test command send some traffic from the host machines over the tunnel and see if the traffic is dropped or if it pass through and tunnel comes up.

If this is the case then it should be working as expected,

Hope this helps.

Thanks

I already wrote it does not work when tunnel is down.(with ping or something etc.)

We can enable tunnel monitoring so that there is at least some traffic flowing through the tunnel. ( tunnel monitoring forces the firewalls to rekey ). The system logs on the PANFW is the best place to look for the reasons the tunnel going down. Similarly the kmd logs ( >show log kmd )  on the Juniper ( if its an SRX ) will give you the reasons for the tunnel to go down.

BR,

Karthik RP

That will work I think.Thanks.

  • 3196 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!