site-to-site VPN between Meraki and Palo Alto

Phi1001
Here to help

site-to-site VPN between Meraki and Palo Alto

We have an ikev1 site-to-site VPN between client's Meraki and our Palo ALto.

 

The issue is as follows :

 

The VPN goes down after the phase 2 lifetime expires and doesn't renegotiate on its own.

It only comes up when the traffic is initiated from Meraki's side and remains active until the pings from Meraki are going on.

Please advise. How do we fix this issue.

7 Replies 7
ww
Kind of a big deal
Kind of a big deal
Main10ence
Meraki Employee
Meraki Employee

Hello @Phi1001,

 

I've heard of customers leveraging free applications (like DataDog) to ping across the tunnel are certain intervals to keep the tunnel up. 

 

If you are REALLY fancy, you could use a CRON job that sends out pings at or during times when traffic is minimal. 

.ılı.ılı. Cisco Meraki
Network Support Engineer

"The future favors the bold."
Phi1001
Here to help

Thanks Sir.

BrandonD
Meraki Employee
Meraki Employee

Hi @Phi1001,

 

Thanks for the post :). I can confirm this is indeed expected behavior for our Non-Meraki VPN peers as outlined below:

 

 

As some of the other members have noted this can be done with 3rd party tools, or live data within your environment, whichever best serves your environment! 

If you found this post helpful, please give it kudos. If my answer solved your problem, click "accept as solution" so that others can benefit from it.
Phi1001
Here to help

Thank You, Sir.

I'll try that.

alemabrahao
Kind of a big deal
Kind of a big deal

Check the tunnel lifetime configuration.

 

IPsec VPN Lifetimes - Cisco Meraki Documentation

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Phi1001
Here to help

Thanks for the information.

Currently, phase 1 lifetime is set to 28800 seconds for phase 1 and 3600 seconds for phase 2.

But, as per your article, both lifetimes are set to 28800 by default. I will change the phase 2 lifetime to 28800 seconds and try again.

Get notified when there are additional replies to this discussion.