<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Path monitor setup using tunnel interface in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/path-monitor-setup-using-tunnel-interface/m-p/528228#M799</link>
    <description>&lt;P&gt;Setting up a path monitor on a static route where source is a tunnel interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am able to ping from CLI with tunnel interface IP as source. But the route does not get installed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ping source 10.0.0.1 host 4.2.2.2&lt;BR /&gt;PING 4.2.2.2 (4.2.2.2) from 10.0.0.1 : 56(84) bytes of data.&lt;BR /&gt;64 bytes from 4.2.2.2: icmp_seq=280 ttl=57 time=21.4 ms&lt;BR /&gt;64 bytes from 4.2.2.2: icmp_seq=281 ttl=57 time=21.3 ms&lt;BR /&gt;64 bytes from 4.2.2.2: icmp_seq=282 ttl=57 time=21.5 ms&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Remote side is Azure and doesn't support tunnel interface with an IP. And I don't want to rely on any single Azure resource IP which might get deleted by someone else&amp;nbsp; bringing tunnel down.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With static route I would be able to use multiple remote IP's for monitoring.&lt;/P&gt;
&lt;P&gt;And I need to monitor it so I can remove associated routes so traffic transfers to 2nd tunnel using another internet link&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 558px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47346i5DBDA53728D185EB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jan 2023 20:42:16 GMT</pubDate>
    <dc:creator>raji_toor</dc:creator>
    <dc:date>2023-01-23T20:42:16Z</dc:date>
    <item>
      <title>Path monitor setup using tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/path-monitor-setup-using-tunnel-interface/m-p/528228#M799</link>
      <description>&lt;P&gt;Setting up a path monitor on a static route where source is a tunnel interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am able to ping from CLI with tunnel interface IP as source. But the route does not get installed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ping source 10.0.0.1 host 4.2.2.2&lt;BR /&gt;PING 4.2.2.2 (4.2.2.2) from 10.0.0.1 : 56(84) bytes of data.&lt;BR /&gt;64 bytes from 4.2.2.2: icmp_seq=280 ttl=57 time=21.4 ms&lt;BR /&gt;64 bytes from 4.2.2.2: icmp_seq=281 ttl=57 time=21.3 ms&lt;BR /&gt;64 bytes from 4.2.2.2: icmp_seq=282 ttl=57 time=21.5 ms&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Remote side is Azure and doesn't support tunnel interface with an IP. And I don't want to rely on any single Azure resource IP which might get deleted by someone else&amp;nbsp; bringing tunnel down.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With static route I would be able to use multiple remote IP's for monitoring.&lt;/P&gt;
&lt;P&gt;And I need to monitor it so I can remove associated routes so traffic transfers to 2nd tunnel using another internet link&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 558px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47346i5DBDA53728D185EB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 20:42:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/path-monitor-setup-using-tunnel-interface/m-p/528228#M799</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2023-01-23T20:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: Path monitor setup using tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/path-monitor-setup-using-tunnel-interface/m-p/528241#M800</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With the All condition you are saying that when there is no connectivity to 172.19.252. "and" 4.2.2.2.2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now the best recommendation is to ping at least 2 or 3 IPs from the other end. If the other end cannot place an IP on its tunnel interface, there is no problem, as long as that IP is allowed through the tunnel, i.e. through the interesting traffic of the IPSEC tunnel, there will be no problem if only from your source you ping the IP that you assign to your tunnel that is allowed in the tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now if you have a route with metric 10 and with a path-monitoring, the idea is that when this failure condition occurs, the route will be removed from the FIB and the route will be added, the route to the same destination, but with metric 30 for example, will take the place.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 23:37:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/path-monitor-setup-using-tunnel-interface/m-p/528241#M800</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2023-01-23T23:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: Path monitor setup using tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/path-monitor-setup-using-tunnel-interface/m-p/529347#M833</link>
      <description>&lt;P&gt;My mistake was I was not trying to ping IP on the other end of the tunnel. Instead just pinging a public IP. I was thinking if internet is down tunnel is down anyways.&amp;nbsp;Pinging an IP across the tunnel within Azure works.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 18:58:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/path-monitor-setup-using-tunnel-interface/m-p/529347#M833</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2023-01-31T18:58:45Z</dc:date>
    </item>
  </channel>
</rss>

