<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic S2S between PA3250 and Azure VPN Gateway -1 way traffic in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/s2s-between-pa3250-and-azure-vpn-gateway-1-way-traffic/m-p/1231608#M5985</link>
    <description>&lt;P&gt;HI everyone, for a long time we have had a functioning VPN gateway between our on premise 3250 and and Azure VPN Gateway.&lt;/P&gt;
&lt;P&gt;Recently, we have observed that appear to be unable to send traffic from the PA side, to Azure. Including return traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here's what I am observing.&amp;nbsp; The Tunnel is up.&lt;/P&gt;
&lt;P&gt;When I send traffic from the Azure Side, I see it appearing on the on premise Palo. So for example a ping, I see it arrive in the traffic monitor, and pass between the correct zones to the destination as allowed traffic.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, the echo reply never gets back to Azure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Conversely, if I send a ping from the PA, top the azure side, on the PA I see the traffic pass through the correct zones, and if I look at the egress traffic on the interface (QOS monitor) I see the ping sessions.&amp;nbsp; However we never get a reply.&lt;/P&gt;
&lt;P&gt;All traffic both inbound and outbound reports as "aging out" on the PA.&amp;nbsp; I would expect the ping to age out on that anyway as per ICMP, but other types of traffic are also aging out. Such as RDP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I run a packet capture on destination machines on the azure side, I do not see any traffic originating from the PA side at all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I run a packet capture on the VPN Gateway, All i see is ESP traffic between both sides.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I run the network monitor on the azure side to check im not blocking anything on the NSG, this verifies the matching rule, with an allow.&lt;/P&gt;
&lt;P&gt;We are running 10.2.12-h6.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any input from anyone who has seen a similar issue would be great!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks,&lt;/P&gt;
&lt;P&gt;Graham.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Jun 2025 08:42:18 GMT</pubDate>
    <dc:creator>CyberEng</dc:creator>
    <dc:date>2025-06-12T08:42:18Z</dc:date>
    <item>
      <title>S2S between PA3250 and Azure VPN Gateway -1 way traffic</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/s2s-between-pa3250-and-azure-vpn-gateway-1-way-traffic/m-p/1231608#M5985</link>
      <description>&lt;P&gt;HI everyone, for a long time we have had a functioning VPN gateway between our on premise 3250 and and Azure VPN Gateway.&lt;/P&gt;
&lt;P&gt;Recently, we have observed that appear to be unable to send traffic from the PA side, to Azure. Including return traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here's what I am observing.&amp;nbsp; The Tunnel is up.&lt;/P&gt;
&lt;P&gt;When I send traffic from the Azure Side, I see it appearing on the on premise Palo. So for example a ping, I see it arrive in the traffic monitor, and pass between the correct zones to the destination as allowed traffic.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, the echo reply never gets back to Azure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Conversely, if I send a ping from the PA, top the azure side, on the PA I see the traffic pass through the correct zones, and if I look at the egress traffic on the interface (QOS monitor) I see the ping sessions.&amp;nbsp; However we never get a reply.&lt;/P&gt;
&lt;P&gt;All traffic both inbound and outbound reports as "aging out" on the PA.&amp;nbsp; I would expect the ping to age out on that anyway as per ICMP, but other types of traffic are also aging out. Such as RDP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I run a packet capture on destination machines on the azure side, I do not see any traffic originating from the PA side at all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I run a packet capture on the VPN Gateway, All i see is ESP traffic between both sides.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I run the network monitor on the azure side to check im not blocking anything on the NSG, this verifies the matching rule, with an allow.&lt;/P&gt;
&lt;P&gt;We are running 10.2.12-h6.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any input from anyone who has seen a similar issue would be great!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks,&lt;/P&gt;
&lt;P&gt;Graham.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2025 08:42:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/s2s-between-pa3250-and-azure-vpn-gateway-1-way-traffic/m-p/1231608#M5985</guid>
      <dc:creator>CyberEng</dc:creator>
      <dc:date>2025-06-12T08:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: S2S between PA3250 and Azure VPN Gateway -1 way traffic</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/s2s-between-pa3250-and-azure-vpn-gateway-1-way-traffic/m-p/1231610#M5986</link>
      <description>&lt;P&gt;Id just like to add, I have performed a packet capture on a machine inside the network, pinging from the azure side and I see the packets arrive on the machine itself.&amp;nbsp; I also see the echo reply go back out.&amp;nbsp; But it never arrives at the azure destination.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2025 09:47:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/s2s-between-pa3250-and-azure-vpn-gateway-1-way-traffic/m-p/1231610#M5986</guid>
      <dc:creator>CyberEng</dc:creator>
      <dc:date>2025-06-12T09:47:47Z</dc:date>
    </item>
  </channel>
</rss>

