- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- ipSec VPN Tunnel to Azure, manually trigger Phase2...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ipSec VPN Tunnel to Azure, manually trigger Phase2 rekey?
I have a successful VPN Tunnel to Azure VPN Gateway. Everything is good, but after a recent internet outage I observed that the tunnel took some time to come up again. It seems that the tunnel came up when Phase2 rekeyed. Is there a manual way to trigger Phase2 rekey? (It may have been triggered by passing traffic, so if you can confirm this solution it would also be helpful.)
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unless you have some sort of DPD or tunnel monitoring traffic in place, an IPsec tunnel is only going to establish when traffic is going across it.
You can specifically clear the Phase 2 IKE SA's from the CLI, but that is not a rekey, rekeys happen at defined intervals, so you would need to generate some Phase 2 traffic after clearing them. If you need to reset a tunnel, that is done for both Phase 1 & 2.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you, I did need to delete all ike and ipsec associations then pass traffic. The command I was looking for was vpn tu
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unless you have some sort of DPD or tunnel monitoring traffic in place, an IPsec tunnel is only going to establish when traffic is going across it.
You can specifically clear the Phase 2 IKE SA's from the CLI, but that is not a rekey, rekeys happen at defined intervals, so you would need to generate some Phase 2 traffic after clearing them. If you need to reset a tunnel, that is done for both Phase 1 & 2.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you, I did need to delete all ike and ipsec associations then pass traffic. The command I was looking for was vpn tu
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Maybe try a policy push not 100% sure.
If you like this post please give a thumbs up(kudo)! 🙂
