<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring SD-WAN Tunnel-IF via ping in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/monitoring-sd-wan-tunnel-if-via-ping/m-p/644344#M5048</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/552708373"&gt;@D.Henze&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You don't have to set up the zone on the PBF. Once you send the traffic through the right tunnel, it will go through the right zone. In your situation, here's what I suggest:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Set up 3 PBFs, one for each ISP connection, to make sure the traffic to the server goes through the correct tunnel.&lt;/LI&gt;
&lt;LI&gt;Arrange the PBF policies in the order you need, keeping in mind that the policy at the top will be the one that matches the traffic, while the others won't work for this traffic.&lt;/LI&gt;
&lt;LI&gt;Set up path monitoring with the option "Disable this rule if the next hop/monitor IP is unreachable" for the first two PBF policies.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This way, the traffic will go to tunnel 1. If it fails, the traffic will switch to tunnel 2, and if that fails too, then it will go to tunnel 3. Let me know if you have any issues with this setup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Thu, 21 Nov 2024 16:20:12 GMT</pubDate>
    <dc:creator>jpomachagua</dc:creator>
    <dc:date>2024-11-21T16:20:12Z</dc:date>
    <item>
      <title>Monitoring SD-WAN Tunnel-IF via ping</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/monitoring-sd-wan-tunnel-if-via-ping/m-p/616747#M4985</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;We're looking to connect multiple Palo Alto devices to our core Palo Alto via SD-WAN. In some cases, we have three internet connections at the customer site, each connected through a different ISP.&lt;/P&gt;
&lt;P&gt;Our goal is to monitor each tunnel by pinging the destination tunnel interface IP address from our Monitoring Tool throught our Core Palo Alto and displaying the results in our monitoring tool. Unfortunately, this doesn’t work because the core Palo Alto doesn’t have the destination IP address in its routing table.&lt;/P&gt;
&lt;P&gt;However, if we ping directly from the core Palo Alto using the source IP address of the corresponding tunnel interface, the ping works.&lt;/P&gt;
&lt;P&gt;Does anyone have an explanation for this?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DHenze_0-1731336658860.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63893iB1ECEB8F226CE882/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DHenze_0-1731336658860.png" alt="DHenze_0-1731336658860.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I know, the Panorama is monitoring the sd-wan connections too &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thanks and best regards,&lt;BR /&gt;Dirk&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2024 14:52:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/monitoring-sd-wan-tunnel-if-via-ping/m-p/616747#M4985</guid>
      <dc:creator>D.Henze</dc:creator>
      <dc:date>2024-11-11T14:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring SD-WAN Tunnel-IF via ping</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/monitoring-sd-wan-tunnel-if-via-ping/m-p/624250#M5024</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/552708373"&gt;@D.Henze&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on the images you provided, I have observed the following behavior:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;You are able to successfully ping the IP on the destination tunnel because you are using an IP within the same zone. Both IPs, as shown in the images, belong to the "zone-to-branch" zone and share the same network.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;However, when you attempt to ping with the IP 10.1.0.X, it appears that this IP belongs to a different zone and does not have a route to reach 172.17.5.204. As a result, the traffic is being sent through the untrust zone.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Considering these findings, it seems to be a networking issue. I recommend trying a PBF (Policy-Based Forwarding) rule that forces the traffic to go through the "zone-to-branch" zone when attempting to reach the IP 172.17.5.204.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2024 21:25:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/monitoring-sd-wan-tunnel-if-via-ping/m-p/624250#M5024</guid>
      <dc:creator>jpomachagua</dc:creator>
      <dc:date>2024-11-18T21:25:06Z</dc:date>
    </item>
    <item>
      <title>Betreff: Monitoring SD-WAN Tunnel-IF via ping</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/monitoring-sd-wan-tunnel-if-via-ping/m-p/640388#M5043</link>
      <description>&lt;P&gt;Hi Jpomachagua,&lt;/P&gt;
&lt;P&gt;Thank you very much for your input!&lt;/P&gt;
&lt;P&gt;You are absolutely right. I have now configured a PBF rule to route traffic destined for 172.17.5.204 via the tunnel.910 interface. With this setup, I am able to reach the IP address using ping.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DHenze_0-1732122947538.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64159iB8A6AA1C8088243B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DHenze_0-1732122947538.png" alt="DHenze_0-1732122947538.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;17:49:42: Without PBF&lt;BR /&gt;17:54:12: With PBF&lt;/P&gt;
&lt;P&gt;However, I’ve encountered an problem for me: If I understand correctly, I would need to configure a separate PBF rule for each destination tunnel interface. Additionally, I’m concerned that the IP addresses of the tunnel interfaces might change after a reboot on the hub, or spoke side, which could complicate things further.&lt;/P&gt;
&lt;P&gt;Could you clarify what you mean exactly by the following statement?&lt;/P&gt;
&lt;P&gt;"Considering these findings, it seems to be a networking issue. I recommend trying a PBF (Policy-Based Forwarding) rule that forces the traffic to go through the 'zone-to-branch' zone when attempting to reach the IP 172.17.5.204."&lt;/P&gt;
&lt;P&gt;In the PBF configuration, I can only specify a destination address, application, and service, as well as an egress interface to forward the traffic. There doesn’t seem to be an option to select a destination zone.&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 17:16:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/monitoring-sd-wan-tunnel-if-via-ping/m-p/640388#M5043</guid>
      <dc:creator>D.Henze</dc:creator>
      <dc:date>2024-11-20T17:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring SD-WAN Tunnel-IF via ping</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/monitoring-sd-wan-tunnel-if-via-ping/m-p/643469#M5044</link>
      <description>&lt;P&gt;Sorry, I had forgotten to add the PBF&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DHenze_0-1732180947952.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64189iE5CA2955DC6C3C29/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DHenze_0-1732180947952.png" alt="DHenze_0-1732180947952.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 09:23:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/monitoring-sd-wan-tunnel-if-via-ping/m-p/643469#M5044</guid>
      <dc:creator>D.Henze</dc:creator>
      <dc:date>2024-11-21T09:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring SD-WAN Tunnel-IF via ping</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/monitoring-sd-wan-tunnel-if-via-ping/m-p/644344#M5048</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/552708373"&gt;@D.Henze&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You don't have to set up the zone on the PBF. Once you send the traffic through the right tunnel, it will go through the right zone. In your situation, here's what I suggest:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Set up 3 PBFs, one for each ISP connection, to make sure the traffic to the server goes through the correct tunnel.&lt;/LI&gt;
&lt;LI&gt;Arrange the PBF policies in the order you need, keeping in mind that the policy at the top will be the one that matches the traffic, while the others won't work for this traffic.&lt;/LI&gt;
&lt;LI&gt;Set up path monitoring with the option "Disable this rule if the next hop/monitor IP is unreachable" for the first two PBF policies.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This way, the traffic will go to tunnel 1. If it fails, the traffic will switch to tunnel 2, and if that fails too, then it will go to tunnel 3. Let me know if you have any issues with this setup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 16:20:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/monitoring-sd-wan-tunnel-if-via-ping/m-p/644344#M5048</guid>
      <dc:creator>jpomachagua</dc:creator>
      <dc:date>2024-11-21T16:20:12Z</dc:date>
    </item>
  </channel>
</rss>

