Palo Alto Networks Knowledgebase: Site-to-Site IPSec VPN between Palo Alto Networks Firewall and Cisco Router is Unstable or Intermittent

Site-to-Site IPSec VPN between Palo Alto Networks Firewall and Cisco Router is Unstable or Intermittent

3757
Created On 02/07/19 23:56 PM - Last Updated 02/07/19 23:56 PM
VPNs
Resolution

Symptoms

Site-to-Site IPSec VPN has been configured between a Palo Alto Networks firewall and a Cisco router. However, the VPN is unstable or intermittent.

Cause

The issue may be due to a Dead Peer Detection (DPD) configuration mismatch.

Resolution

Check and modify the Palo Alto Networks firewall and Cisco router to have the same DPD configuration.

On the Palo Alto Networks firewall, go to Network > Network Profiles > IKE Gateways as follows:

  1.jpg

Confirm that the same configuration is made on the Cisco router:

2.jpg

owner: jlunario



Attachments
Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClLVCA0&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Attachments
Choose Language