Enable, Disable, Refresh, or Restart an IKE Gateway or IPSec Tunnel (2024)

Enable, Disable, Refresh, or Restart an IKE Gateway or IPSec Tunnel

Updated on

Apr 4, 2024

Focus

Download PDF

Updated on

Apr 4, 2024

Focus

  1. Home
  2. Network Security
  3. Monitor Your IPSec VPN Tunnel
  4. Enable, Disable, Refresh, or Restart an IKE Gateway or IPSec Tunnel

Download PDF

Network Security

Table of Contents

Previous View the Tunnel Status
Next Site-to-Site VPN Configuration Examples

Where Can I Use This?

What Do I Need?

  • PAN-OS

No license required

You can enable, disable, refresh, or restart an IKE gateway or VPN tunnel to make troubleshooting easier.

Enable or Disable an IKE Gateway or IPSec Tunnel

Enable or disable an IKE gateway or IPSec tunnel to make troubleshooting easier.

  • Enable or disable an IKE gateway.

    1. Select

      Network

      Network Profiles

      IKE Gateways

      and select the gateway you want to enable or disable.

    2. At the bottom of the screen, click

      Enable

      or

      Disable

      .

  • Enable or disable an IPSec tunnel.

    1. Select

      Network

      IPSec Tunnels

      and select the tunnel you want to enable or disable.

    2. At the bottom of the screen, click

      Enable

      or

      Disable

      .

Refresh or Restart an IKE Gateway or IPSec Tunnel

You can refresh or restart an IKE gateway or IPSec tunnel. The refresh and restart behaviors for an IKE gateway and IPSec tunnel are as follows:

Phase

Refresh

Restart

IKE Gateway (IKE Phase 1)

Updates the onscreen statistics for the selected IKE gateway.

Equivalent to issuing a second

show

command in the CLI (after an initial

show

command).

Restarts the selected IKE gateway.

IKEv2

: Also restarts any associated child IPSec security associations (SAs).

IKEv1

: Doesn’t restart the associated IPSec SAs.

A restart is disruptive to all existing sessions.

Equivalent to issuing a

clear

,

test

,

show

command sequence in the CLI.

IPSec Tunnel (IKE Phase 2)

Updates the onscreen statistics for the selected IPSec tunnel.

Equivalent to issuing a second

show

command in the CLI (after an initial

show

command).

Restarts the IPSec tunnel.

A restart is disruptive to all existing sessions.

Equivalent to issuing a

clear

,

test

,

show

command sequence in the CLI.

Keep in mind that the result of restarting an IKE gateway depends on whether its IKEv1 or IKEv2.

  • Refresh or restart an IKE gateway.

    1. Select

      Network

      IPSec Tunnels

      and select the tunnel for the gateway you want to refresh or restart.

    2. In the row for that tunnel, under the Status column, click

      IKE Info

      .

    3. At the bottom of the IKE Info screen, click the action you want:

      • Refresh

        —Updates the statistics on the screen.

      • Restart

        —Clears the SAs, so traffic is dropped until the IKE negotiation starts over and the tunnel is recreated.

  • Refresh or restart an IPSec tunnel.

    You might determine that the tunnel needs to be refreshed or restarted because you use the tunnel monitor to monitor the tunnel status, or you use an external network monitor to monitor network connectivity through the IPSec tunnel.

    1. Select

      Network

      IPSec Tunnels

      and select the tunnel you want to refresh or restart.

    2. In the row for that tunnel, under the Status column, click

      Tunnel Info

      .

    3. At the bottom of the Tunnel Info screen, click the action you want:

      • Refresh

        —Updates the onscreen statistics.

      • Restart

        —Clears the SAs, so traffic is dropped until the IKE negotiation starts over and the tunnel is recreated.

"); adBlockNotification.append($( "Thanks for visiting https://docs.paloaltonetworks.com. To improve your experience when accessing content across our site, please add the domain to the allow list on your ad blocker application." )); let adBlockNotificationClose = $("x"); adBlockNotification.prepend(adBlockNotificationClose) $('body').append(adBlockNotification); setTimeout(function (e) { adBlockNotification.addClass('open'); }, 10); adBlockNotificationClose.on('click', function (e) { adBlockNotification.removeClass('open'); }) } }, 5000)

Previous View the Tunnel Status
Next Site-to-Site VPN Configuration Examples

Recommended For You

{{ if(( raw.pantechdoctype != "techdocsAuthoredContentPage" && raw.objecttype != "Knowledge" && raw.pancommonsourcename != "TD pan.dev Docs")) { }} {{ if (raw.panbooktype) { }} {{ if (raw.panbooktype.indexOf('PANW Yellow Theme') != -1){ }}

{{ } else if (raw.panbooktype.indexOf('PANW Green Theme') != -1){ }}

{{ } else if (raw.panbooktype.indexOf('PANW Blue Theme') != -1){ }}

{{ } else { }}

{{ } }} {{ } else { }}

{{ } }} {{ } else { }} {{ if (raw.pantechdoctype == "pdf"){ }}

{{ } else if (raw.objecttype == "Knowledge") { }}

{{ } else if (raw.pancommonsourcename == "TD pan.dev Docs") { }}

{{ } else if (raw.pancommonsourcename == "LIVEcommunity Public") { }}

{{ } else { }}

{{ } }} {{ } }}

{{ if (raw.pancommonsourcename == "LIVEcommunity Public") { }}

{{ if (raw.pantechdoctype == "pdf"){ }}

{{ } }}

{{ } else { }}

{{ if (raw.pantechdoctype == "pdf"){ }}

{{ } }}

{{ } }}

{{ if (raw.pancommonsourcename != "TD pan.dev Docs"){ }} {{ if (raw.pandevdocsosversion){ }} {{ } else { }} {{ if ((_.size(raw.panosversion)>0) && !(_.isNull(raw.panconversationid )) && (!(_.isEmpty(raw.panconversationid ))) && !(_.isNull(raw.otherversions ))) { }} (See other versions) {{ } }} {{ } }} {{ } }}

{{ } }}{{ if (raw.pantechdoctype == "bookDetailPage"){ }}

{{ } }}{{ if (raw.pantechdoctype == "bookLandingPage"){ }}

{{ } }}{{ if (raw.pantechdoctype == "productLanding"){ }}

{{ } }}{{ if (raw.pantechdoctype == "techdocsAuthoredContentPage"){ }}

{{ } }}{{ if (raw.pantechdoctype == "pdf"){ }}

{{ } }}

© 2024 Palo Alto Networks, Inc. All rights reserved.

Enable, Disable, Refresh, or Restart an IKE Gateway or IPSec Tunnel (2024)
Top Articles
Real Estate Market Size & Trends Report, 2022-2030
4 Fastest Way to Transfer Files from PC to Android [2024]
Use Copilot in Microsoft Teams meetings
craigslist: kenosha-racine jobs, apartments, for sale, services, community, and events
P2P4U Net Soccer
Samsung 9C8
Craigslist - Pets for Sale or Adoption in Zeeland, MI
Texas (TX) Powerball - Winning Numbers & Results
Over70Dating Login
Mawal Gameroom Download
Aktuelle Fahrzeuge von Autohaus Schlögl GmbH & Co. KG in Traunreut
Craigslist Cars Nwi
Raleigh Craigs List
Louisiana Sportsman Classifieds Guns
Les Rainwater Auto Sales
Craigslist Free Stuff Santa Cruz
ARK: Survival Evolved Valguero Map Guide: Resource Locations, Bosses, & Dinos
Bank Of America Financial Center Irvington Photos
Vandymania Com Forums
Barber Gym Quantico Hours
Www.dunkinbaskinrunsonyou.con
Prey For The Devil Showtimes Near Ontario Luxe Reel Theatre
Scripchat Gratis
Pawn Shop Moline Il
Malluvilla In Malayalam Movies Download
Xpanas Indo
The Powers Below Drop Rate
Delta Math Login With Google
Busted! 29 New Arrests in Portsmouth, Ohio – 03/27/22 Scioto County Mugshots
Salons Open Near Me Today
Housing Assistance Rental Assistance Program RAP
P3P Orthrus With Dodge Slash
EST to IST Converter - Time Zone Tool
24 slang words teens and Gen Zers are using in 2020, and what they really mean
Afspraak inzien
Midsouthshooters Supply
SF bay area cars & trucks "chevrolet 50" - craigslist
Atlanta Musicians Craigslist
PruittHealth hiring Certified Nursing Assistant - Third Shift in Augusta, GA | LinkedIn
“To be able to” and “to be allowed to” – Ersatzformen von “can” | sofatutor.com
Three V Plymouth
Charli D'amelio Bj
How I Passed the AZ-900 Microsoft Azure Fundamentals Exam
Jaefeetz
3500 Orchard Place
Lightfoot 247
Rubmaps H
10 Bedroom Airbnb Kissimmee Fl
sin city jili
Frank 26 Forum
Secondary Math 2 Module 3 Answers
Volstate Portal
Latest Posts
Article information

Author: Ouida Strosin DO

Last Updated:

Views: 6106

Rating: 4.6 / 5 (76 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Ouida Strosin DO

Birthday: 1995-04-27

Address: Suite 927 930 Kilback Radial, Candidaville, TN 87795

Phone: +8561498978366

Job: Legacy Manufacturing Specialist

Hobby: Singing, Mountain biking, Water sports, Water sports, Taxidermy, Polo, Pet

Introduction: My name is Ouida Strosin DO, I am a precious, combative, spotless, modern, spotless, beautiful, precious person who loves writing and wants to share my knowledge and understanding with you.