<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global protect vpn traffic to azure site to site vpn not working as expected in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-vpn-traffic-to-azure-site-to-site-vpn-not-working/m-p/540768#M3990</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue i'm encountering is related to one our vpn client(server) which cannot use directly a S2S connection and must use a P2S connection that is always activated at all time.&lt;/P&gt;
&lt;P&gt;We want from one of our virtual machine in azure to access this server through the S2S vpn and then through the global protect to reach the server at the end.&lt;/P&gt;
&lt;P&gt;Our achitecture is currently with a virtual machine set up with&amp;nbsp; a point to site connection to our onpremise datacenter and a site to site vpn to azure(virtual network gateway).&lt;/P&gt;
&lt;P&gt;Unfortunately, even after creating static routes i see the traffic is allowed through our security policies but always end with an aged-out message and no connectivity between the vpn client and the azure network is established.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does someone know if that setup is supported with static routes configured or do we need to use another way of routing our traffic with bgp for exemple ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance for all your help or advices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cordially,&lt;/P&gt;
&lt;P&gt;Alexis DINET&lt;/P&gt;
&lt;P&gt;OHC&lt;/P&gt;</description>
    <pubDate>Tue, 02 May 2023 12:48:56 GMT</pubDate>
    <dc:creator>FS-EXP</dc:creator>
    <dc:date>2023-05-02T12:48:56Z</dc:date>
    <item>
      <title>Global protect vpn traffic to azure site to site vpn not working as expected</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-vpn-traffic-to-azure-site-to-site-vpn-not-working/m-p/540768#M3990</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue i'm encountering is related to one our vpn client(server) which cannot use directly a S2S connection and must use a P2S connection that is always activated at all time.&lt;/P&gt;
&lt;P&gt;We want from one of our virtual machine in azure to access this server through the S2S vpn and then through the global protect to reach the server at the end.&lt;/P&gt;
&lt;P&gt;Our achitecture is currently with a virtual machine set up with&amp;nbsp; a point to site connection to our onpremise datacenter and a site to site vpn to azure(virtual network gateway).&lt;/P&gt;
&lt;P&gt;Unfortunately, even after creating static routes i see the traffic is allowed through our security policies but always end with an aged-out message and no connectivity between the vpn client and the azure network is established.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does someone know if that setup is supported with static routes configured or do we need to use another way of routing our traffic with bgp for exemple ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance for all your help or advices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cordially,&lt;/P&gt;
&lt;P&gt;Alexis DINET&lt;/P&gt;
&lt;P&gt;OHC&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 12:48:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-vpn-traffic-to-azure-site-to-site-vpn-not-working/m-p/540768#M3990</guid>
      <dc:creator>FS-EXP</dc:creator>
      <dc:date>2023-05-02T12:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect vpn traffic to azure site to site vpn not working as expected</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-vpn-traffic-to-azure-site-to-site-vpn-not-working/m-p/541137#M4004</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Check the logs and see if the PAN is seeing applications or if it just says 'incomplete'. If it says incomplete, there is a routing issue as the PAN has not seen enough packets to make an application determination (this is what I have seen as the most common reason for this). Perhaps its asymetric routing?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 21:59:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-vpn-traffic-to-azure-site-to-site-vpn-not-working/m-p/541137#M4004</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-05-04T21:59:50Z</dc:date>
    </item>
  </channel>
</rss>

