IPSec Tunnel goes Down After Few Minutes

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

IPSec Tunnel goes Down After Few Minutes

hi All,

 

I am facing a strange issue with IPSec tunnels built on Palo Alto firewalls.

 

Scenario:

1. On both ends we have Palo Alto firewalls(various models PA-220, PA440, PA-3220, PA-VM(AWS))

2. Public IP addresses of both ends are always reachable.

3. Tunnel lights always look GREEN.

4. Routing also is in place, either with Static or OSPF routes.

 

Issue seen:

Once tunnel is brought up with 'test vpn' command on CLI, connectivity gets established. However, after few minutes(5 to 10), connectivity automatically breaks and tunnel lights on firewalls on both ends are GREEN.

 

I tried:

- With various PAN-OS 10.x.x, no help.

- With various hardware and VM, no help.

- By changing routing protocols, no help.

- With and without assigning IP address to tunnel interfaces, but no help.

 

Please let me know if you have seen this issue or any guidance would be helpful.

3 REPLIES 3

Cyber Elite
Cyber Elite

It sounds like the test vpn cli command is enough to get P1 and P2 up, but without active traffic on it, is a security feature to down the VPN (but interfaces may still show green)

 

Suggestion is to setup tunnel monitoring, to ping a destination IP, to keep the tunnel up.

 

What other questions can we answer for you?

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Yeah, this is a work around I agree. But this is not an actual fix.

Cyber Elite
Cyber Elite

Are you saying that test vpn brings tunnel up but generating interesting traffic does not (pinging across the tunnel to other side for example)?

What do you see in traffic log if you ping. Is traffic destination correct tunnel interface?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 2858 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!