We help IT Professionals succeed at work.

Palo Alto site-to-site vpn monitoring

235 Views
Last Modified: 2017-03-24
Hello all,

on A Palo Alto FW after executing "show vpn ike-sa gateway gateway_id" command I receive the output such as below
show vpn
Does the "Established" time suggest that the VPN was down and reestablished at 08:01:55 or does it only mean that rekeying of phase 1 happened at that time due to SA lifetime expiry?
Comment
Watch Question

Dan CraciunIT Consultant
CERTIFIED EXPERT
Commented:
This problem has been solved!
(Unlock this solution with a 7-day Free Trial)
UNLOCK SOLUTION

Author

Commented:
thanks for your comment. the SA lifetime is 24 hours indeed. A new key is also negotiated when a tunnel is established. from what I understand that output is not telling us the reason for rekey, is that correct?
IT Consultant
CERTIFIED EXPERT
Commented:
This problem has been solved!
(Unlock this solution with a 7-day Free Trial)
UNLOCK SOLUTION

Author

Commented:
thanks Dan
Dan CraciunIT Consultant
CERTIFIED EXPERT

Commented:
You're welcome.

Glad I could help!