[prisma sd-wan] standard vpn flap during rekey with an 'multiple_ike_session' event

[prisma sd-wan] standard vpn flap during rekey with an 'multiple_ike_session' event

2131
Created On 01/10/23 09:06 AM - Last Modified 10/05/23 02:53 AM


Symptom


  • multiple_ike_session event is seen every time the IKE rekeys.
  • Logs similar to below are seen in tunnelmgr (file view log tunnelmgr)
{"_fac":"tunnelmgr","_level":"INFO","_msgid":"SetServiceLinkStatus","_pid":4429,"_prog":"tunnelmgr","_ts":"2022-12-12T21:56:15.179Z","sl":"sl2","state":
{"extended_state":"tunnel_up","ike_algo":"AES_CBC_128HMAC_SHA2_256_128","ike_next_rekey":"2022-12-12T22
:18:08.918811574Z","ipsec_algo":"AES_CBC_128_HMAC_SHA2_256_128","ipsec_last_rekeyed":"2022-12-12T21:56:15.179010672Z","ipsec_next_rekey":"2022-12-12T22:45:26.179012982Z","local_ip":"xx.yy.zz.qq","remote_ip":"xx.yy.zz.mm","state":"up"}}
{"_fac":"tunnelmgr","_level":"INFO","_msgid":"Audit timer, tunnel state up, multiike detected in charon","_pid":4429,"_prog":"tunnelmgr","_ts":"2022-12-12T21:56:21.836Z","sldev":"sl1"}
{"_fac":"tunnelmgr","_level":"INFO","_msgid":"StateTunnelUp","_pid":4429,"_prog":"tunnelmgr","_ts":"2022-12-12T21:56:21.836Z","event":"EVENT_TUNNEL_MULTIPLE_SESSION_CHECK","sl":"sl1"}


 


Environment


  • Prisma SD-WAN
  • IPSec VPN
  • Standard VPN


Cause


IKEv1 compatibility Issue.

Resolution


  1. Configure ikev2 as documented in Step4 of documentation.
  2. Issue will be resolved after configuration change.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kG9vCAE&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail