<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Prisma Access Service Connection to Palo Alto FW in HA-AA in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-service-connection-to-palo-alto-fw-in-ha-aa/m-p/1248932#M1279</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We were able to make the tunnels up under 1 Service Connection (with 2 tunnels, primary and secondary) in Prisma Access and 2 tunnels in Palo Alto FW with Active-Active HA setup. If both tunnels are up, loopback IP in FW1 is accessible from GP user. But when the primary went down and secondary tunnel is still up, GP user in unable to reach/access the loopback IP of FW2. What would be the reason of this? Did we make the correct setup with regards to the tunnel? Appreciate your inputs. Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Feb 2026 00:40:43 GMT</pubDate>
    <dc:creator>IBalaro</dc:creator>
    <dc:date>2026-02-25T00:40:43Z</dc:date>
    <item>
      <title>Prisma Access Service Connection to Palo Alto FW in HA-AA</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-service-connection-to-palo-alto-fw-in-ha-aa/m-p/1248932#M1279</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We were able to make the tunnels up under 1 Service Connection (with 2 tunnels, primary and secondary) in Prisma Access and 2 tunnels in Palo Alto FW with Active-Active HA setup. If both tunnels are up, loopback IP in FW1 is accessible from GP user. But when the primary went down and secondary tunnel is still up, GP user in unable to reach/access the loopback IP of FW2. What would be the reason of this? Did we make the correct setup with regards to the tunnel? Appreciate your inputs. Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Feb 2026 00:40:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-service-connection-to-palo-alto-fw-in-ha-aa/m-p/1248932#M1279</guid>
      <dc:creator>IBalaro</dc:creator>
      <dc:date>2026-02-25T00:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Service Connection to Palo Alto FW in HA-AA</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-service-connection-to-palo-alto-fw-in-ha-aa/m-p/1249052#M1280</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you set up tunnel mon itoring? that actively helps to disable rouytes when a tunnel goes down&lt;/P&gt;
&lt;P&gt;ideally use BGP instead of static routes as well (but tunnel monitor should help you out in this)&lt;/P&gt;</description>
      <pubDate>Thu, 26 Feb 2026 12:01:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-service-connection-to-palo-alto-fw-in-ha-aa/m-p/1249052#M1280</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2026-02-26T12:01:14Z</dc:date>
    </item>
  </channel>
</rss>

