Intermittent IPsec connection

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Intermittent IPsec connection

L1 Bithead

We recently setup IPsec tunnel between PA-1410 and 3rd party device. We can see the tunnel is up, but when testing ping between endpoint on our side to endpoint on the peer's side there are frequents request timed out.

Our configuration for IKE crypto using sha256, aes-256-cbc, DH group 19, lifetime 24 hours. For IPsec crypto we use sha256, aes-256-cbc, DH group 19 and key lifetime 1 hours. Our local IP is 10.121.0.78 and peer IP 10.250.30.50.

 

From traffic log there are no packet drop, even packet capture from tunnel interface and the endpoint IP for destination doesn't show any packet drop.

I have collected the debug using these following commands:

debug ike global on debug
debug ike pcap on

 

On ikemgr.log I have found that there is frequent IPSEC KEY LIFETIME EXPIRED, even happened only a few seconds. From the system log, I didn't found tunnel down or tunnel up on a frequent basis. But, what I found weird is that IPSEC KEY LIFETIME EXPIRED is happened frequently.
Below is the example of the log

2026/08/04 15:18:12 2026-08-04 15:18:12.000 +0700  [DEBG]: 10.86.51.3[500] - 10.86.51.1[500]:(nil) 1 times of 80 bytes message will be sent over socket 1025
2026/08/04 15:18:12 2026-08-04 15:18:12.000 +0700  [PNTF]: {    4:   27}: ====> IPSEC KEY LIFETIME EXPIRED; tunnel ALTO-IPSEC-TUNNEL-DRC <====
2026/08/04 15:18:12                                                       ====> Expired SA: 10.121.0.78[500]-10.250.30.50[500] SPI:0xFC61DEB1/0x9AD641EC <====
2026/08/04 15:18:12 2026-08-04 15:18:12.000 +0700  [PNTF]: {    4:   27}: ====> IKEv2 CHILD SA DELETED AS RESPONDER, non-rekey; tunnel ALTO-IPSEC-TUNNEL-DRC <====
2026/08/04 15:18:12                                                       ====> Deleted SA: 10.121.0.78[500]-10.250.30.50[500] message id:0x00008536, SPI:0xFC61DEB1/0x9AD641EC parent SN:10069 <====
2026/08/04 15:18:12 2026-08-04 15:18:12.000 +0700  [INFO]: {    4:     }: ikev2_request_initiator_start: SA state ESTABLISHED type 3 caller ikev2_child_delete
2026/08/04 15:18:12 2026-08-04 15:18:12.000 +0700  [INFO]: {    4:     }: IKEv2 INFO transmit: gateway Alto-DRC, message_id: 0x00008535, type 3 SA state ESTABLISHED
2026/08/04 15:18:12 2026-08-04 15:18:12.000 +0700  [DEBG]: 10.121.0.78[500] - 10.250.30.50[500]:(nil) 1 times of 80 bytes message will be sent over socket 1024
2026/08/04 15:18:12 2026-08-04 15:18:12.000 +0700  [PNTF]: {    4:   27}: ====> IPSEC KEY DELETED; tunnel ALTO-IPSEC-TUNNEL-DRC <====
2026/08/04 15:18:12                                                       ====> Deleted SA: 10.121.0.78[500]-10.250.30.50[500] SPI:0xFC61DEB1/0x9AD641EC <====
2026/08/04 15:18:12 2026-08-04 15:18:12.000 +0700  [INFO]: {    4:   27}: SADB_DELETE proto=255 src=10.250.30.50[0] dst=10.121.0.78[0] ESP spi=0xFC61DEB1
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: processing isakmp packet
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: ===
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: 80 bytes message received from 10.250.30.50
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: {    4:     }: [IKE Initiator] response message_id 34101 expected 34101
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: {    4:     }: response exch type 37
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: {    4:     }: update response message_id 0x8535
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [INFO]: {    4:     }: received DELETE payload, protocol ESP, num of SPI: 1 IKE SA state ESTABLISHED
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [INFO]: {    4:     }: delete proto ESP spi 0x9AD641EC
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [PWRN]: {    4:     }: can't find sa for proto ESP spi 0x9AD641EC
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: processing isakmp packet
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: ===
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: 80 bytes message received from 10.86.51.1
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: {    1:     }: [IKE Initiator] response message_id 2818 expected 2818
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: {    1:     }: response exch type 37
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: {    1:     }: update response message_id 0xb02
2026/08/04 15:18:13 2026-08-04 15:18:13.000 +0700  [PNTF]: {    4:   27}: ====> IPSEC KEY LIFETIME EXPIRED; tunnel ALTO-IPSEC-TUNNEL-DRC <====
2026/08/04 15:18:13                                                       ====> Expired SA: 10.121.0.78[500]-10.250.30.50[500] SPI:0x9DC44DCA/0x9AD6423B <====

2026/08/04 15:18:13 2026-08-04 15:18:13.358 +0700  [DEBG]: processing isakmp packet
2026/08/04 15:18:13 2026-08-04 15:18:13.358 +0700  [DEBG]: ===
2026/08/04 15:18:13 2026-08-04 15:18:13.358 +0700  [DEBG]: 272 bytes message received from 10.250.30.50
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:     }: [IKE Responder] request message_id 34105 expected 34105
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:     }: request exch type 36
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:     }: update request message_id 0x8539
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: Parse Proposal: proposal #1 len=48
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [PNTF]: {    4:     }: ====> IKEv2 CHILD SA NEGOTIATION STARTED AS RESPONDER, non-rekey; gateway Alto-DRC <====
2026/08/04 15:18:13                                                       ====> Initiated SA: 10.121.0.78[500]-10.250.30.50[500] message id:0x00008539 parent SN:10069 <====
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [WARN]: {    4:   27}: selector ALTO-IPSEC-TUNNEL-DRC src is ambiguous, using the first one of the expanded addresses
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [WARN]: {    4:   27}: selector ALTO-IPSEC-TUNNEL-DRC dst is ambiguous, using the first one of the expanded addresses
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: TS matching for configured selector ALTO-IPSEC-TUNNEL-DRC 0.0.0.0[0]/0-0.0.0.0[0]/0 proto 0
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: .. check local TS (num 1, TS0 is not specific) against selector 0:0.0.0.0[0]/0
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {     :   27}: ... TS 0: 10.125.22.36->10.125.22.36[0-65535](ts) is used as it is narrower
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: ... result: local TS < 0.0.0.0[0]/0
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: .. check remote TS (num 1, TS0 is not specific) against selector 0:0.0.0.0[0]/0
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {     :   27}: ... TS 0: 192.168.155.11->192.168.155.11[0-65535](ts) is used as it is narrower
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: ... result: remote TS < 0.0.0.0[0]/0
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: TS matching result: TS_l match(<), TS_r match(<) *
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: selector chosen ALTO-IPSEC-TUNNEL-DRC: tid 27
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: see whether there's matching transform
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: found same ID(12,12). compare attributes
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: ikev2_compare_attributes:   Matched ENCR kenlen 256
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}:  Matched ENCR: my  [12], peer  [12]
2026/08/04 15:18:13 OK; advance to next of my transform type

2026/08/04 15:18:15 2026-08-04 15:18:15.000 +0700  [PNTF]: {    4:   27}: ====> IPSEC KEY LIFETIME EXPIRED; tunnel ALTO-IPSEC-TUNNEL-DRC <====
2026/08/04 15:18:15                                                       ====> Expired SA: 10.121.0.78[500]-10.250.30.50[500] SPI:0x8C1EB246/0x9AD64247 <====
2026/08/04 15:18:15 2026-08-04 15:18:15.000 +0700  [PNTF]: {    4:   27}: ====> IKEv2 CHILD SA DELETED AS RESPONDER, non-rekey; tunnel ALTO-IPSEC-TUNNEL-DRC <====
2026/08/04 15:18:15                                                       ====> Deleted SA: 10.121.0.78[500]-10.250.30.50[500] message id:0x00008538, SPI:0x8C1EB246/0x9AD64247 parent SN:10069 <====
2026/08/04 15:18:15 2026-08-04 15:18:15.000 +0700  [INFO]: {    4:     }: ikev2_request_initiator_start: SA state ESTABLISHED type 3 caller ikev2_child_delete
2026/08/04 15:18:15 2026-08-04 15:18:15.000 +0700  [INFO]: {    4:     }: IKEv2 INFO transmit: gateway Alto-DRC, message_id: 0x00008537, type 3 SA state ESTABLISHED
2026/08/04 15:18:15 2026-08-04 15:18:15.000 +0700  [DEBG]: 10.121.0.78[500] - 10.250.30.50[500]:(nil) 1 times of 80 bytes message will be sent over socket 1024
2026/08/04 15:18:15 2026-08-04 15:18:15.000 +0700  [PNTF]: {    4:   27}: ====> IPSEC KEY DELETED; tunnel ALTO-IPSEC-TUNNEL-DRC <====
2026/08/04 15:18:15                                                       ====> Deleted SA: 10.121.0.78[500]-10.250.30.50[500] SPI:0x8C1EB246/0x9AD64247 <====
2026/08/04 15:18:15 2026-08-04 15:18:15.000 +0700  [INFO]: {    4:   27}: SADB_DELETE proto=255 src=10.250.30.50[0] dst=10.121.0.78[0] ESP spi=0x8C1EB246
2026/08/04 15:18:15 2026-08-04 15:18:15.003 +0700  [DEBG]: processing isakmp packet
2026/08/04 15:18:15 2026-08-04 15:18:15.003 +0700  [DEBG]: ===
2026/08/04 15:18:15 2026-08-04 15:18:15.003 +0700  [DEBG]: 80 bytes message received from 10.250.30.50
2026/08/04 15:18:15 2026-08-04 15:18:15.003 +0700  [DEBG]: {    4:     }: [IKE Initiator] response message_id 34103 expected 34103
2026/08/04 15:18:15 2026-08-04 15:18:15.003 +0700  [DEBG]: {    4:     }: response exch type 37
2026/08/04 15:18:15 2026-08-04 15:18:15.003 +0700  [DEBG]: {    4:     }: update response message_id 0x8537
2026/08/04 15:18:15 2026-08-04 15:18:15.003 +0700  [INFO]: {    4:     }: received DELETE payload, protocol ESP, num of SPI: 1 IKE SA state ESTABLISHED
2026/08/04 15:18:15 2026-08-04 15:18:15.003 +0700  [INFO]: {    4:     }: delete proto ESP spi 0x9AD64247


I don't know if this is the reason why intermittent connection between our side and peer side.

3 REPLIES 3

Cyber Elite

Continuous rekey can be caused by ProxyID(s) (encryption domain, TS) not matching.

 

Do you have 10.125.22.36/32 and 192.168.155.11/32 (and only this single one) at both sides?

Principal Architect @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Hi, @Raido_Rattameister, thank you for pointing this out. We have tried to add remote IP 192.168.155.11/32 for Proxy ID and after that we did not found request timed out when pinging.
May I know why we need to setup Proxy ID in this case? I'm not really understand about Proxy ID, all I know is we need to use Proxy ID is the peer is using policy-based VPN.

Regards,
Moch. Imam Rifai

Cyber Elite

Do you manage other side to check what subnets are in VPN policy?

 

You can switch Palo side to passive mode (in IKE gateway settings), initiate traffic from peer side so that Palo would be responder and then you see in logs what TS (ProxyID) peer side has configured. This allows to match Palo side to peer side.

Principal Architect @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 63 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!