3rd party tunnel keeps flapping intermittently between two data centers

3rd party tunnel keeps flapping intermittently between two data centers

1571
Created On 06/25/21 11:49 AM - Last Modified 02/29/24 00:19 AM


Symptom


  • 3rd party tunnel keeps flapping intermittently between 2 Data Centers (DCs) when both side IONs act initiator as 'NO'.
  • Alerts thrown in UI are shared below in the screenshot:
User-added image
  •  Reasons for 3rd party tunnel flaps will show the extended state as "Multiple IKE Session".
  •  In tunnelmgr (CLI command: file view logs tunnelmgr) error logs will be as:  
"_fac":"tunnelmgr","_level":"INFO","_msgid":"SetServiceLinkStatus","_pid":2627,"_prog":"tunnelmgr","_ts":"2021-06-17T11:54:00.231Z","sl":"sl1","state":{"extended_state":"multiple_ike_session","local_ip":"xx.yy.zz.mm","remote_ip":"xx.yy.zz.qq","state":"down"}}
{"_fac":"tunnelmgr","_level":"INFO","_msgid":"StateTunnelDown","_pid":2627,"_prog":"tunnelmgr","_ts":"2021-06-17T11:54:00.232Z","event":"EVENT_TUNNEL_DOWN","sl":"sl1"}
{"_fac":"tunnelmgr","_level":"INFO","_msgid":"ignore this event","_pid":2627,"_prog":"tunnelmgr","_ts":"2021-06-17T11:54:00.232Z","event":"EVENT_TUNNEL_DOWN","sl":"sl1","state":"TUNNEL_DOWN"}
  • As DC-to-DC native VPNs are not supported so we build a 3rd party tunnel between 2 DC's.



Environment


  • Prisma SD-WAN
  • VPNs
  • Tunnel between Data Centers
 


Cause


  • 3rd party tunnel keeps flapping intermittently between 2 DC's when both the side IONs act initiators as NO (as seen in tunnelmgr logs)
  • Between DC TO DC service links can run into multiple IKE session hence the flap


Resolution


  1. For Temporary fix, Make one site as default config and another DC site as "initiator only =Yes", then the 3rd party tunnel remains UP and stable.
  2. For Permanent Fix, Upgrade the Ion device to 5.6.1. The issue has been resolved in code 5.6.1. 


Additional Information


28 Feb 24 (Vijay) - Article reviewed with Namratha and published external.

Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oMEoCAM&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail