Palo Alto Site to Site IPsec VPN went down

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Palo Alto Site to Site IPsec VPN went down

L1 Bithead

Hi ,


We've setup Site to Site IPsec VPN between Palo Alto Firewalls. The tunnel was up and working but it went down after some time.

Look like the tunnel went down because there is no traffic passing through the tunnel. Everytime we need to trigger IPsec tunnel by using >test vpn ike-sa gateway to bring up.

How can we configure the tunnel to be up all the time even there is no traffic passing through the tunnel?

Do we need to enable tunnel-monitor ? Are there any other ways to make the tunnel up all the time?

We are using IKEv2 preferred mode and we already enabled DPD for Ikev1 and liveliness check for ikev2.


Please help suggest.




Cyber Elite
Cyber Elite

Either tunnel monitor or path monitoring inside virtual router.

Without them tunnel will not be renegotiated if no interesting traffic.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

L1 Bithead

After Checking Config , the issue is DH value mismatch. Change both side to same DH Value and now working fine 

  • 2 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!