- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-02-2013 05:35 AM
Hi,
After side to side vpn established correctly after sometime(I do not know how many hours) Phase1 becomes passive.Side1 cannot access Side2.
when we try to use test vpn command for ike it becomes up and it works.What can be reason for that ?
08-02-2013 06:18 AM
Good Morning,
There are couple of reasons for that:
1) The sites lost networks connectivity between them for a certain duration and during that time the ike and esp sessions timed out on the firewall
2) Either of the site did not rekey and hence after the session key became invalid, that the sites couldnt process the ike traffic.
How long were the VPNs up and running prior to seeing this issue. Are both the devices PANFWs?
08-02-2013 06:23 AM
juniper other side
I don't know how long but I'll look forward to catch time details.
08-02-2013 06:31 AM
I would suspect that either site did not rekey, to be the primary reason. Its not a mandatory setting for the rekeying timing to match on both the devices, but keeping the same value on both the devices, would force both the devices to rekey after the lifetime of the session keys have expired.
Did you notice just the phase 1 going down, with the actual tunnel traffic still flowing (phase-2 being up and passing ESP traffic), or were both phase 1 and phase 2 down?
If its the latter, then I would suspect the lost internet connectivity between them
BR,
Karthik
08-02-2013 10:36 AM
If there was no traffic passing through the tunnel the tunnel might have come down.
As you said as soon as you ran test command the tunnel came back up.
Next time if you see tunnel go down. I will suggest rather than running the test command send some traffic from the host machines over the tunnel and see if the traffic is dropped or if it pass through and tunnel comes up.
If this is the case then it should be working as expected,
Hope this helps.
Thanks
08-02-2013 01:32 PM
I already wrote it does not work when tunnel is down.(with ping or something etc.)
08-02-2013 01:49 PM
We can enable tunnel monitoring so that there is at least some traffic flowing through the tunnel. ( tunnel monitoring forces the firewalls to rekey ). The system logs on the PANFW is the best place to look for the reasons the tunnel going down. Similarly the kmd logs ( >show log kmd ) on the Juniper ( if its an SRX ) will give you the reasons for the tunnel to go down.
BR,
Karthik RP
08-02-2013 01:53 PM
That will work I think.Thanks.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!