[prisma sd-wan] standard vpn flap during rekey with an 'multiple_ike_session' event
1944
Created On 01/10/23 09:06 AM - Last Modified 10/05/23 02:53 AM
Symptom
- multiple_ike_session event is seen every time the IKE rekeys.
- Logs similar to below are seen in tunnelmgr (file view log tunnelmgr)
{"_fac":"tunnelmgr","_level":"INFO","_msgid":"SetServiceLinkStatus","_pid":4429,"_prog":"tunnelmgr","_ts":"2022-12-12T21:56:15.179Z","sl":"sl2","state":
{"extended_state":"tunnel_up","ike_algo":"AES_CBC_128HMAC_SHA2_256_128","ike_next_rekey":"2022-12-12T22
:18:08.918811574Z","ipsec_algo":"AES_CBC_128_HMAC_SHA2_256_128","ipsec_last_rekeyed":"2022-12-12T21:56:15.179010672Z","ipsec_next_rekey":"2022-12-12T22:45:26.179012982Z","local_ip":"xx.yy.zz.qq","remote_ip":"xx.yy.zz.mm","state":"up"}}
{"_fac":"tunnelmgr","_level":"INFO","_msgid":"Audit timer, tunnel state up, multiike detected in charon","_pid":4429,"_prog":"tunnelmgr","_ts":"2022-12-12T21:56:21.836Z","sldev":"sl1"}
{"_fac":"tunnelmgr","_level":"INFO","_msgid":"StateTunnelUp","_pid":4429,"_prog":"tunnelmgr","_ts":"2022-12-12T21:56:21.836Z","event":"EVENT_TUNNEL_MULTIPLE_SESSION_CHECK","sl":"sl1"}
Environment
- Prisma SD-WAN
- IPSec VPN
- Standard VPN
Cause
IKEv1 compatibility Issue.
Resolution
- Configure ikev2 as documented in Step4 of documentation.
- Issue will be resolved after configuration change.