<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tunnel inside of Tunnel in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/tunnel-inside-of-tunnel/m-p/1225387#M5751</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/540963063"&gt;@skey4867&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/540963063"&gt;@skey4867&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;I have a site to site configure and tunnel established between palo alto and juniper vsrx.&amp;nbsp; I am trying to route an IPSec tunnel through the existing tunnel.&amp;nbsp; I am able to ping through the existing tunnels so connectivity exist.&amp;nbsp; I have applied and "ANY/ANY" policy as well.&amp;nbsp; The issue I is the traffic from the "spoke/remote" is able to send the IKEv2 Initiation through the tunnel but the Hub response is never making it back.&amp;nbsp; I see the session in the browser as being sent to the hub but again the return traffic is lost somewhere.&amp;nbsp; If I connect Palo Alto to Palo Alto the inner tunnel establishes just fine through the outter tunnel.&amp;nbsp; If I configure Juniper to Juniper same outcome.&amp;nbsp; No ACL's or anything like that that are applied either.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Are you trying to do some tunnel in a tunnel?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Also, you can refer to&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/pancast-episodes/pancast-episode-12-troubleshooting-ipsec-tunnels/ta-p/532287" target="_blank"&gt;https://live.paloaltonetworks.com/t5/pancast-episodes/pancast-episode-12-troubleshooting-ipsec-tunnels/ta-p/532287&lt;/A&gt;&amp;nbsp;for some initial troubleshooting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
    <pubDate>Wed, 02 Apr 2025 04:06:36 GMT</pubDate>
    <dc:creator>ozheng</dc:creator>
    <dc:date>2025-04-02T04:06:36Z</dc:date>
    <item>
      <title>Tunnel inside of Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/tunnel-inside-of-tunnel/m-p/1225054#M5745</link>
      <description>&lt;P&gt;I have a site to site configure and tunnel established between palo alto and juniper vsrx.&amp;nbsp; I am trying to route an IPSec tunnel through the existing tunnel.&amp;nbsp; I am able to ping through the existing tunnels so connectivity exist.&amp;nbsp; I have applied and "ANY/ANY" policy as well.&amp;nbsp; The issue I is the traffic from the "spoke/remote" is able to send the IKEv2 Initiation through the tunnel but the Hub response is never making it back.&amp;nbsp; I see the session in the browser as being sent to the hub but again the return traffic is lost somewhere.&amp;nbsp; If I connect Palo Alto to Palo Alto the inner tunnel establishes just fine through the outter tunnel.&amp;nbsp; If I configure Juniper to Juniper same outcome.&amp;nbsp; No ACL's or anything like that that are applied either.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Mar 2025 22:38:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/tunnel-inside-of-tunnel/m-p/1225054#M5745</guid>
      <dc:creator>skey4867</dc:creator>
      <dc:date>2025-03-28T22:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel inside of Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/tunnel-inside-of-tunnel/m-p/1225387#M5751</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/540963063"&gt;@skey4867&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/540963063"&gt;@skey4867&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;I have a site to site configure and tunnel established between palo alto and juniper vsrx.&amp;nbsp; I am trying to route an IPSec tunnel through the existing tunnel.&amp;nbsp; I am able to ping through the existing tunnels so connectivity exist.&amp;nbsp; I have applied and "ANY/ANY" policy as well.&amp;nbsp; The issue I is the traffic from the "spoke/remote" is able to send the IKEv2 Initiation through the tunnel but the Hub response is never making it back.&amp;nbsp; I see the session in the browser as being sent to the hub but again the return traffic is lost somewhere.&amp;nbsp; If I connect Palo Alto to Palo Alto the inner tunnel establishes just fine through the outter tunnel.&amp;nbsp; If I configure Juniper to Juniper same outcome.&amp;nbsp; No ACL's or anything like that that are applied either.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Are you trying to do some tunnel in a tunnel?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Also, you can refer to&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/pancast-episodes/pancast-episode-12-troubleshooting-ipsec-tunnels/ta-p/532287" target="_blank"&gt;https://live.paloaltonetworks.com/t5/pancast-episodes/pancast-episode-12-troubleshooting-ipsec-tunnels/ta-p/532287&lt;/A&gt;&amp;nbsp;for some initial troubleshooting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 04:06:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/tunnel-inside-of-tunnel/m-p/1225387#M5751</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2025-04-02T04:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel inside of Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/tunnel-inside-of-tunnel/m-p/1225854#M5772</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;Olivier,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for you reply.&amp;nbsp; Yes I am trying to establish an IPSec tunnel inside and already established IPSec Tunnel.&amp;nbsp; I have attached an example diagram to hopefully outline what I am trying to achieve.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 17:12:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/tunnel-inside-of-tunnel/m-p/1225854#M5772</guid>
      <dc:creator>skey4867</dc:creator>
      <dc:date>2025-04-07T17:12:00Z</dc:date>
    </item>
  </channel>
</rss>

