<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tunnel Monitoring in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/tunnel-monitoring/m-p/1244074#M6530</link>
    <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have two ISP for site A and site B. we have configured tunnel.1,2,3,4. for all the tunnels i configured tunnel monitoring for failover.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;My primary tunnel is up and working fine. However, all the backup tunnels are down the tunnel status are showing red.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;anyone tell me is this expected?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jhussain1_0-1765985998674.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70127i25E7FB2153919F21/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jhussain1_0-1765985998674.png" alt="jhussain1_0-1765985998674.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jhussain1_1-1765991082868.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70128i414F9950DDA8944E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jhussain1_1-1765991082868.png" alt="jhussain1_1-1765991082868.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Dec 2025 17:04:51 GMT</pubDate>
    <dc:creator>jhussain1</dc:creator>
    <dc:date>2025-12-17T17:04:51Z</dc:date>
    <item>
      <title>Tunnel Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/tunnel-monitoring/m-p/1244074#M6530</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have two ISP for site A and site B. we have configured tunnel.1,2,3,4. for all the tunnels i configured tunnel monitoring for failover.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;My primary tunnel is up and working fine. However, all the backup tunnels are down the tunnel status are showing red.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;anyone tell me is this expected?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jhussain1_0-1765985998674.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70127i25E7FB2153919F21/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jhussain1_0-1765985998674.png" alt="jhussain1_0-1765985998674.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jhussain1_1-1765991082868.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70128i414F9950DDA8944E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jhussain1_1-1765991082868.png" alt="jhussain1_1-1765991082868.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 17:04:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/tunnel-monitoring/m-p/1244074#M6530</guid>
      <dc:creator>jhussain1</dc:creator>
      <dc:date>2025-12-17T17:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/tunnel-monitoring/m-p/1244076#M6531</link>
      <description>&lt;H3 data-start="108" data-end="183"&gt;Why the “backup” tunnels can show RED/DOWN while the primary is working&lt;/H3&gt;
&lt;P data-start="184" data-end="335"&gt;On Palo Alto Networks firewalls, the &lt;STRONG data-start="221" data-end="254"&gt;IPSec tunnel interface status&lt;/STRONG&gt; can be driven &lt;STRONG data-start="269" data-end="293"&gt;by tunnel monitoring&lt;/STRONG&gt;, not just by whether IKE/IPSec SAs exist.&lt;/P&gt;
&lt;UL data-start="337" data-end="828"&gt;
&lt;LI data-start="337" data-end="577"&gt;
&lt;P data-start="339" data-end="577"&gt;&lt;STRONG data-start="339" data-end="351"&gt;Red/DOWN&lt;/STRONG&gt; can mean: &lt;STRONG data-start="362" data-end="428"&gt;tunnel monitor is enabled and the monitoring IP is unreachable&lt;/STRONG&gt;, so PAN-OS brings the &lt;EM data-start="451" data-end="469"&gt;tunnel interface&lt;/EM&gt; down (especially when the monitor profile action is &lt;STRONG data-start="522" data-end="535"&gt;Fail Over&lt;/STRONG&gt;).&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="578" data-end="828"&gt;
&lt;P data-start="580" data-end="828"&gt;In a “primary/backup” design, if the &lt;STRONG data-start="617" data-end="645"&gt;routing prefers Tunnel.1&lt;/STRONG&gt;, then the firewall may have &lt;STRONG data-start="674" data-end="717"&gt;no valid working path over Tunnel.2/3/4&lt;/STRONG&gt; to reach the &lt;EM data-start="731" data-end="755"&gt;monitor destination(s)&lt;/EM&gt; you configured for those tunnels—so their monitors fail and they go red.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="830" data-end="996"&gt;This is a common misconfiguration pattern: &lt;STRONG data-start="873" data-end="936"&gt;the monitor destination is reachable via the primary tunnel&lt;/STRONG&gt;, but &lt;STRONG data-start="942" data-end="995"&gt;not reachable via each backup tunnel specifically&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-start="1033" data-end="1312"&gt;Palo Alto can absolutely have &lt;STRONG data-start="1063" data-end="1103"&gt;multiple tunnels UP at the same time&lt;/STRONG&gt;, but &lt;STRONG data-start="1109" data-end="1178"&gt;tunnel monitoring can intentionally force a tunnel interface DOWN&lt;/STRONG&gt; if its monitor destination is not reachable (by design, to remove routes and trigger failover).&lt;/P&gt;
&lt;H3 data-start="1314" data-end="1355"&gt;What to validate (most common causes)&lt;/H3&gt;
&lt;OL data-start="1356" data-end="1393"&gt;
&lt;LI data-start="1356" data-end="1393"&gt;
&lt;P data-start="1359" data-end="1393"&gt;&lt;STRONG data-start="1359" data-end="1393"&gt;Monitor destination per tunnel&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL data-start="1394" data-end="1677"&gt;
&lt;LI data-start="1394" data-end="1545"&gt;
&lt;P data-start="1396" data-end="1545"&gt;Each tunnel should monitor an IP that is &lt;STRONG data-start="1437" data-end="1471"&gt;reachable only via that tunnel&lt;/STRONG&gt; (typical: the &lt;STRONG data-start="1486" data-end="1516"&gt;remote tunnel interface IP&lt;/STRONG&gt; when using route-based VPN).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1546" data-end="1677"&gt;
&lt;P data-start="1548" data-end="1677"&gt;If the monitored IP is “behind” the far side, make sure it’s actually reachable through that specific tunnel during steady state.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL start="2" data-start="1679" data-end="1747"&gt;
&lt;LI data-start="1679" data-end="1747"&gt;
&lt;P data-start="1682" data-end="1747"&gt;&lt;STRONG data-start="1682" data-end="1747"&gt;Ensure the monitor traffic is forced over the intended tunnel&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL data-start="1748" data-end="2043"&gt;
&lt;LI data-start="1748" data-end="1889"&gt;
&lt;P data-start="1750" data-end="1889"&gt;The monitor probe follows forwarding; if the “best” route to the monitor destination points at Tunnel.1, then Tunnel.2’s monitor will fail.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1890" data-end="2043"&gt;
&lt;P data-start="1892" data-end="2043"&gt;Fix by using a monitor destination that is topologically tied to that tunnel (again: remote tunnel interface IP is the usual approach for route-based).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL start="3" data-start="2045" data-end="2080"&gt;
&lt;LI data-start="2045" data-end="2080"&gt;
&lt;P data-start="2048" data-end="2080"&gt;&lt;STRONG data-start="2048" data-end="2080"&gt;Policy-based VPN / Proxy-IDs&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL data-start="2081" data-end="2399"&gt;
&lt;LI data-start="2081" data-end="2399"&gt;
&lt;P data-start="2083" data-end="2399"&gt;If any of these are policy-based, ensure the &lt;STRONG data-start="2128" data-end="2197"&gt;monitor destination IPs are covered by Proxy-ID/traffic selectors&lt;/STRONG&gt;, otherwise the monitor pings may never match the IPsec SA and will fail. (PAN-OS tunnel monitoring guidance calls out proxy-ID considerations in failover designs.)&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 data-start="2401" data-end="2463"&gt;Useful verification commands (to include in your response)&lt;/H3&gt;
&lt;P data-start="2464" data-end="2543"&gt;From the firewall CLI, check whether it’s the &lt;EM data-start="2510" data-end="2519"&gt;monitor&lt;/EM&gt; driving the red status:&lt;/P&gt;
&lt;UL data-start="2544" data-end="2829"&gt;
&lt;LI data-start="2544" data-end="2829"&gt;
&lt;P data-start="2546" data-end="2829"&gt;&lt;CODE data-start="2546" data-end="2561"&gt;show vpn flow&lt;/CODE&gt; (PANW KB explicitly references using this to interpret monitor/tunnel status issues).&amp;nbsp;&lt;BR data-start="2685" data-end="2688" /&gt;Also review &lt;STRONG data-start="2700" data-end="2715"&gt;System logs&lt;/STRONG&gt; for tunnel monitor events (look for tunnel-status-down / monitor failures).&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL data-start="2882" data-end="3373"&gt;
&lt;LI data-start="2882" data-end="3373"&gt;
&lt;P data-start="2884" data-end="3373"&gt;“Red/DOWN on the backup tunnels is expected if tunnel monitoring is configured and the monitoring IP for those tunnels is not reachable via each tunnel. In PAN-OS, tunnel monitoring can intentionally bring a tunnel interface down (especially with Fail Over action) to withdraw routes and enable failover. We should adjust the monitor destination (typically remote tunnel interface IP) and/or routing/traffic-selectors so each tunnel’s monitor probe is reachable over that specific tunnel.”&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 17 Dec 2025 19:31:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/tunnel-monitoring/m-p/1244076#M6531</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2025-12-17T19:31:12Z</dc:date>
    </item>
  </channel>
</rss>

