05-08-2020 06:47 AM
Hello
I am having an intermittent Connectivity issues between the my Cisco ASA Firewall and my Client Palo Alto Firewall.
Client Firewall:
Hardware: Palo Alto 850
Software: 8.1.6
My Firewall: Cisco ASA 5555, Software: 9.8.3.11
Randomly the VPN tunnel is going down for 5 Mins
In the Logs I see all the IPsec SA's are deleted followed by an error message "VPN Disconnected, Reason:Lost Service". Then approximately 5 mins later. The tunnel is re-established and everything works fine.
On Palo firewall end, during the 5 mins window when the tunnel is down we see the Palo firewall doing a liveness check by Sending an "R U THERE" message to Cisco Peer and after 10 tries (approximately 5 mins) if it doesn't get a response from Cisco it re-establishes the VPN tunnel.
Once the tunnel re-establishes everything is working fine. Since the outage window is very small and happening randomly it was difficult to understand why this is happening.
Any help to identify why this is happening would be much appreciated.
05-08-2020 06:56 AM
05-08-2020 07:08 AM
Hi
The IKE and IPsec SA timers configured matches on both ends.
I have DPD enabled on the Cisco Firewall.
05-08-2020 07:52 AM
VPN Disconnected, Reason:Lost Service. asa log message id 113019.
have look into this link here what ikev version you on 1 or 2?
05-08-2020 11:27 AM
The version is IKEv2
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide