<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to establish tunnel during Service Connection configuration (Details Added with Screenshot) in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/unable-to-establish-tunnel-during-service-connection/m-p/1245447#M1259</link>
    <description>&lt;P&gt;Dear Community Expert Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This my first post in Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I really enjoy the Palo Alto Prisma Access SASE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Find the below details:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before I am going to production configuration I plan to test in my LAB environment for multiple of POC.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Requirement:&lt;/STRONG&gt; Service Connection configuration&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Setup&lt;/STRONG&gt;:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Palo Alto NGFW hosted in GCP (Google Cloud Platform)&lt;/LI&gt;
&lt;LI&gt;Strata Cloud Manager (Prisma Access)&lt;/LI&gt;
&lt;LI&gt;The internet facing interface is private IP address (10.233.2.x) and that IP address NAT on the GCP.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;LAB IP Address Details:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Palo Alto FW (Hosted in GCP) interface details:&lt;/P&gt;
&lt;P&gt;Ethernet1/1 : &lt;STRONG&gt;10.233.2.x/24&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Ethernet1/2 : &lt;STRONG&gt;10.235.2.6/24&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Service Connection in Prisma Access Strata cloud manager Configuration details:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I&lt;/P&gt;
&lt;P&gt;n General section:&lt;/P&gt;
&lt;P&gt;Select - &lt;STRONG&gt;From Preferred Region&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prisma Access Location: &lt;STRONG&gt;India North PA-G&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Data Traffic Source NAT: &lt;STRONG&gt;Not Enabled&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Infrastructure Traffic Source NAT: &lt;STRONG&gt;Not Enabled&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;In&lt;/STRONG&gt; &lt;STRONG&gt;Primary Tunnel:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Branch Device Type&lt;STRONG&gt;: Palo Alto Networks NGFW&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;NOTE: &lt;/STRONG&gt;As by default when I select Palo Alto Networks NGFW then its automatically select the below Profile:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PaloAlto-Networks-IPSec-Crypto:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_0-1768299362753.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70328i7FA64C27919C0CDA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_0-1768299362753.png" alt="chinmayanaik_0-1768299362753.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_1-1768299362754.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70327i84E1A9AE46F9481F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_1-1768299362754.png" alt="chinmayanaik_1-1768299362754.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PaloAlto-Networks-IKE-Crypto&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_2-1768299362758.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70329i5D1230899379DCF3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_2-1768299362758.png" alt="chinmayanaik_2-1768299362758.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_3-1768299362759.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70330iD30753E1C3715663/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_3-1768299362759.png" alt="chinmayanaik_3-1768299362759.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;IKE Local Identification&lt;STRONG&gt; :&amp;nbsp; None&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;IKE Peer Identification: IP Address &amp;gt;&amp;gt; &lt;STRONG&gt;35.246.250.xxx&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;KE Passive Mode: &lt;STRONG&gt;Unchecked&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Authentication: &lt;STRONG&gt;Pre-Shared Key&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;IKE Gateway: Branch Device Public IP Address &amp;gt;&amp;gt; Static IP &amp;gt;&amp;gt; &lt;STRONG&gt;35.246.250.xxx&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Proxy ID: &lt;STRONG&gt;Not configured&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Turn on Tunnel Monitoring: &lt;STRONG&gt;Unchecked&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;In Routing Section:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Static Routing &amp;gt;&amp;gt; 10.35.2.0/24 (This is the Palo Alto NGFW behind Network which going to my private resources for mobile users)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After configuration I get the &lt;STRONG&gt;Service FQDN &lt;/STRONG&gt;and &lt;STRONG&gt;Service IP Address (130.41.114.xxx)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_4-1768299362761.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70331i204BB0C434C55E9B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_4-1768299362761.png" alt="chinmayanaik_4-1768299362761.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Now PUSH also done and getting below:&lt;/P&gt;
&lt;P&gt;Config show : &lt;STRONG&gt;In Sync&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_5-1768299362767.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70332i9711663ED314B84E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_5-1768299362767.png" alt="chinmayanaik_5-1768299362767.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Now in Palo Alto NGFW hosted in GCP:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IKE Crypto parameters is same as Prisma Access configured side.&lt;/P&gt;
&lt;P&gt;IPSec crypto parameters also same as Prisma Access configured side.&lt;/P&gt;
&lt;P&gt;Version: &lt;STRONG&gt;IKE v2 mode&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In IKE Gateway &amp;gt;&amp;gt; &amp;nbsp;Local IP Address: &lt;STRONG&gt;Ethernet1/1 : 10.233.2.x&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In IKE Gateway &amp;gt;&amp;gt; &amp;nbsp;Authentication: &lt;STRONG&gt;Pre-Shared Key&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In IKE Gateway &amp;gt;&amp;gt; Local Identification: &amp;nbsp;&lt;STRONG&gt;35.246.250.xxx (Public IP address)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In IKE Gateway &amp;gt;&amp;gt; Peer Identification: &amp;nbsp;&lt;STRONG&gt;130.41.114.xxx (Prism Access Public IP address)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In IKE Gateway &amp;gt;&amp;gt; Advanced Options &amp;gt;&amp;gt; Enable NAT Traversal&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_6-1768299362774.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70334i62F6064DB64F1D0B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_6-1768299362774.png" alt="chinmayanaik_6-1768299362774.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Zone created as below :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_7-1768299362783.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70335i23D40F28776E8C76/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_7-1768299362783.png" alt="chinmayanaik_7-1768299362783.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Logical Router configure as below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_8-1768299362787.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70333iD374A438C77E1772/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_8-1768299362787.png" alt="chinmayanaik_8-1768299362787.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;QUESTION-1:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I am unable to find the Destination IP address from Prisma Access Strata Cloud Manager.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_9-1768299362793.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70336i9D242608BAC252BE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_9-1768299362793.png" alt="chinmayanaik_9-1768299362793.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;QUESTION-2:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Below is the Tunnel Down Status in NGFW (Hosted in GCP):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_10-1768299362800.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70337i50D213621E0D9883/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_10-1768299362800.png" alt="chinmayanaik_10-1768299362800.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;QUESTION - 3:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Also, I am unable to find the Prisma Access Infrastructure Subnet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please guide me after review my configuration details and let me known if need any additional details to established IPSec Tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank You in Advanced&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1547381563"&gt;@chinmaya.naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jan 2026 10:32:11 GMT</pubDate>
    <dc:creator>chinmaya.naik</dc:creator>
    <dc:date>2026-01-13T10:32:11Z</dc:date>
    <item>
      <title>Unable to establish tunnel during Service Connection configuration (Details Added with Screenshot)</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/unable-to-establish-tunnel-during-service-connection/m-p/1245447#M1259</link>
      <description>&lt;P&gt;Dear Community Expert Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This my first post in Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I really enjoy the Palo Alto Prisma Access SASE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Find the below details:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before I am going to production configuration I plan to test in my LAB environment for multiple of POC.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Requirement:&lt;/STRONG&gt; Service Connection configuration&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Setup&lt;/STRONG&gt;:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Palo Alto NGFW hosted in GCP (Google Cloud Platform)&lt;/LI&gt;
&lt;LI&gt;Strata Cloud Manager (Prisma Access)&lt;/LI&gt;
&lt;LI&gt;The internet facing interface is private IP address (10.233.2.x) and that IP address NAT on the GCP.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;LAB IP Address Details:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Palo Alto FW (Hosted in GCP) interface details:&lt;/P&gt;
&lt;P&gt;Ethernet1/1 : &lt;STRONG&gt;10.233.2.x/24&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Ethernet1/2 : &lt;STRONG&gt;10.235.2.6/24&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Service Connection in Prisma Access Strata cloud manager Configuration details:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I&lt;/P&gt;
&lt;P&gt;n General section:&lt;/P&gt;
&lt;P&gt;Select - &lt;STRONG&gt;From Preferred Region&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prisma Access Location: &lt;STRONG&gt;India North PA-G&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Data Traffic Source NAT: &lt;STRONG&gt;Not Enabled&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Infrastructure Traffic Source NAT: &lt;STRONG&gt;Not Enabled&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;In&lt;/STRONG&gt; &lt;STRONG&gt;Primary Tunnel:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Branch Device Type&lt;STRONG&gt;: Palo Alto Networks NGFW&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;NOTE: &lt;/STRONG&gt;As by default when I select Palo Alto Networks NGFW then its automatically select the below Profile:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PaloAlto-Networks-IPSec-Crypto:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_0-1768299362753.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70328i7FA64C27919C0CDA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_0-1768299362753.png" alt="chinmayanaik_0-1768299362753.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_1-1768299362754.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70327i84E1A9AE46F9481F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_1-1768299362754.png" alt="chinmayanaik_1-1768299362754.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PaloAlto-Networks-IKE-Crypto&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_2-1768299362758.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70329i5D1230899379DCF3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_2-1768299362758.png" alt="chinmayanaik_2-1768299362758.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_3-1768299362759.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70330iD30753E1C3715663/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_3-1768299362759.png" alt="chinmayanaik_3-1768299362759.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;IKE Local Identification&lt;STRONG&gt; :&amp;nbsp; None&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;IKE Peer Identification: IP Address &amp;gt;&amp;gt; &lt;STRONG&gt;35.246.250.xxx&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;KE Passive Mode: &lt;STRONG&gt;Unchecked&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Authentication: &lt;STRONG&gt;Pre-Shared Key&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;IKE Gateway: Branch Device Public IP Address &amp;gt;&amp;gt; Static IP &amp;gt;&amp;gt; &lt;STRONG&gt;35.246.250.xxx&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Proxy ID: &lt;STRONG&gt;Not configured&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Turn on Tunnel Monitoring: &lt;STRONG&gt;Unchecked&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;In Routing Section:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Static Routing &amp;gt;&amp;gt; 10.35.2.0/24 (This is the Palo Alto NGFW behind Network which going to my private resources for mobile users)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After configuration I get the &lt;STRONG&gt;Service FQDN &lt;/STRONG&gt;and &lt;STRONG&gt;Service IP Address (130.41.114.xxx)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_4-1768299362761.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70331i204BB0C434C55E9B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_4-1768299362761.png" alt="chinmayanaik_4-1768299362761.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Now PUSH also done and getting below:&lt;/P&gt;
&lt;P&gt;Config show : &lt;STRONG&gt;In Sync&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_5-1768299362767.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70332i9711663ED314B84E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_5-1768299362767.png" alt="chinmayanaik_5-1768299362767.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Now in Palo Alto NGFW hosted in GCP:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IKE Crypto parameters is same as Prisma Access configured side.&lt;/P&gt;
&lt;P&gt;IPSec crypto parameters also same as Prisma Access configured side.&lt;/P&gt;
&lt;P&gt;Version: &lt;STRONG&gt;IKE v2 mode&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In IKE Gateway &amp;gt;&amp;gt; &amp;nbsp;Local IP Address: &lt;STRONG&gt;Ethernet1/1 : 10.233.2.x&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In IKE Gateway &amp;gt;&amp;gt; &amp;nbsp;Authentication: &lt;STRONG&gt;Pre-Shared Key&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In IKE Gateway &amp;gt;&amp;gt; Local Identification: &amp;nbsp;&lt;STRONG&gt;35.246.250.xxx (Public IP address)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In IKE Gateway &amp;gt;&amp;gt; Peer Identification: &amp;nbsp;&lt;STRONG&gt;130.41.114.xxx (Prism Access Public IP address)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In IKE Gateway &amp;gt;&amp;gt; Advanced Options &amp;gt;&amp;gt; Enable NAT Traversal&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_6-1768299362774.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70334i62F6064DB64F1D0B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_6-1768299362774.png" alt="chinmayanaik_6-1768299362774.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Zone created as below :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_7-1768299362783.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70335i23D40F28776E8C76/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_7-1768299362783.png" alt="chinmayanaik_7-1768299362783.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Logical Router configure as below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_8-1768299362787.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70333iD374A438C77E1772/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_8-1768299362787.png" alt="chinmayanaik_8-1768299362787.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;QUESTION-1:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I am unable to find the Destination IP address from Prisma Access Strata Cloud Manager.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_9-1768299362793.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70336i9D242608BAC252BE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_9-1768299362793.png" alt="chinmayanaik_9-1768299362793.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;QUESTION-2:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Below is the Tunnel Down Status in NGFW (Hosted in GCP):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmayanaik_10-1768299362800.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70337i50D213621E0D9883/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmayanaik_10-1768299362800.png" alt="chinmayanaik_10-1768299362800.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;QUESTION - 3:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Also, I am unable to find the Prisma Access Infrastructure Subnet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please guide me after review my configuration details and let me known if need any additional details to established IPSec Tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank You in Advanced&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1547381563"&gt;@chinmaya.naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 10:32:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/unable-to-establish-tunnel-during-service-connection/m-p/1245447#M1259</guid>
      <dc:creator>chinmaya.naik</dc:creator>
      <dc:date>2026-01-13T10:32:11Z</dc:date>
    </item>
  </channel>
</rss>

