<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ZTNA Connector — Tunnel remains Inactive despite active Control Plane (NFR tenant) in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/ztna-connector-tunnel-remains-inactive-despite-active-control/m-p/1262167#M1320</link>
    <description>&lt;P&gt;Hello Evryone,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I'm tring to deploy a ztna connector on my home lab to prepare different use case for customer demo and i still have the same issue.&lt;/P&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal" dir="ltr"&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL class="[li_&amp;amp;]:mb-0 [li_&amp;amp;]:mt-1 [li_&amp;amp;]:gap-1 [&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3 print:block print:space-y-1" dir="ltr"&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Tenant type: NFR&amp;nbsp;&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;ZTNA Connector deployed on-prem via KVM (Proxmox VE), two-arm deployment&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Connector image: &lt;CODE class="bg-text-200/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]"&gt;200v-6.2.9-ztna-connector-b3-kvm.qcow2 (and try with 6.2.5 same issue)&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Port 1 (WAN/PublicWAN): static IP, valid gateway, DNS reachable&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Port 2 (LAN): static IP on isolated segment, reaching target app successfully via local NAT/firewall (NGFW in front)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal" dir="ltr"&gt;&lt;STRONG&gt;Steps already taken:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL class="[li_&amp;amp;]:mb-0 [li_&amp;amp;]:mt-1 [li_&amp;amp;]:gap-1 [&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-decimal flex flex-col gap-1 pl-8 mb-3 print:block print:space-y-1" dir="ltr"&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Onboarded ZTNA Connector via Strata Cloud Manager (Onboard Connectivity to Private Apps → ZTNA Connector)&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Created Connector Group, Connector, and FQDN Target (private app) successfully&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Deployed connector VM on Proxmox/KVM — required &lt;CODE class="bg-text-200/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]"&gt;--cpu kvm64&lt;/CODE&gt; (not &lt;CODE class="bg-text-200/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]"&gt;host&lt;/CODE&gt;) and a serial console (&lt;CODE class="bg-text-200/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]"&gt;serial0&lt;/CODE&gt;) to boot successfully; confirmed via LIVEcommunity forum post referencing this exact Proxmox setup&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Redeployed the connector fully from scratch (new Key/Secret, new Connector object in SCM) to rule out stale state — same result&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Verified via &lt;CODE class="bg-text-200/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]"&gt;ion toolkit&lt;/CODE&gt;: &lt;CODE class="bg-text-200/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]"&gt;dump interface config 1&lt;/CODE&gt; shows correct static IP/gateway/DNS&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;&lt;CODE class="bg-text-200/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]"&gt;nslookup locator.cgnx.net&lt;/CODE&gt; from the connector times out — no DNS response, despite DNS servers being reachable and correctly configured&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Verified no firewall blocking on local network path (NGFW + edge firewall logs show no drops for this traffic after rule adjustments)&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Home ISP router&amp;nbsp; configured in DMZ mode pointing to firewall WAN IP to rule out double-NAT interference&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal" dir="ltr"&gt;&lt;STRONG&gt;Observed status in Strata Cloud Manager:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL class="[li_&amp;amp;]:mb-0 [li_&amp;amp;]:mt-1 [li_&amp;amp;]:gap-1 [&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3 print:block print:space-y-1" dir="ltr"&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Control Plane:&amp;nbsp; Active&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Tunnel: consistently Inactive&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Config Status: "Tunnel Config Done"&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Diagnostic tools in SCM (Dump Overview, Packet Captures under Connector → Actions → Diagnostics) spin indefinitely and never load, across multiple connector redeployments&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal" dir="ltr"&gt;&lt;STRONG&gt;Question:&lt;/STRONG&gt; Is there a known limitation for ZTNA Connector tunnel establishment or SCM diagnostic tooling on NFR tenants? Or is there a specific requirement (e.g., licensing scope, region availability) we may be missing for tunnel establishment to complete?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thank's for your help&lt;/P&gt;</description>
    <pubDate>Tue, 18 Aug 2026 10:20:10 GMT</pubDate>
    <dc:creator>M.Salah734756</dc:creator>
    <dc:date>2026-08-18T10:20:10Z</dc:date>
    <item>
      <title>ZTNA Connector — Tunnel remains Inactive despite active Control Plane (NFR tenant)</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/ztna-connector-tunnel-remains-inactive-despite-active-control/m-p/1262167#M1320</link>
      <description>&lt;P&gt;Hello Evryone,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I'm tring to deploy a ztna connector on my home lab to prepare different use case for customer demo and i still have the same issue.&lt;/P&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal" dir="ltr"&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL class="[li_&amp;amp;]:mb-0 [li_&amp;amp;]:mt-1 [li_&amp;amp;]:gap-1 [&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3 print:block print:space-y-1" dir="ltr"&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Tenant type: NFR&amp;nbsp;&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;ZTNA Connector deployed on-prem via KVM (Proxmox VE), two-arm deployment&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Connector image: &lt;CODE class="bg-text-200/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]"&gt;200v-6.2.9-ztna-connector-b3-kvm.qcow2 (and try with 6.2.5 same issue)&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Port 1 (WAN/PublicWAN): static IP, valid gateway, DNS reachable&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Port 2 (LAN): static IP on isolated segment, reaching target app successfully via local NAT/firewall (NGFW in front)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal" dir="ltr"&gt;&lt;STRONG&gt;Steps already taken:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL class="[li_&amp;amp;]:mb-0 [li_&amp;amp;]:mt-1 [li_&amp;amp;]:gap-1 [&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-decimal flex flex-col gap-1 pl-8 mb-3 print:block print:space-y-1" dir="ltr"&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Onboarded ZTNA Connector via Strata Cloud Manager (Onboard Connectivity to Private Apps → ZTNA Connector)&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Created Connector Group, Connector, and FQDN Target (private app) successfully&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Deployed connector VM on Proxmox/KVM — required &lt;CODE class="bg-text-200/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]"&gt;--cpu kvm64&lt;/CODE&gt; (not &lt;CODE class="bg-text-200/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]"&gt;host&lt;/CODE&gt;) and a serial console (&lt;CODE class="bg-text-200/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]"&gt;serial0&lt;/CODE&gt;) to boot successfully; confirmed via LIVEcommunity forum post referencing this exact Proxmox setup&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Redeployed the connector fully from scratch (new Key/Secret, new Connector object in SCM) to rule out stale state — same result&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Verified via &lt;CODE class="bg-text-200/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]"&gt;ion toolkit&lt;/CODE&gt;: &lt;CODE class="bg-text-200/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]"&gt;dump interface config 1&lt;/CODE&gt; shows correct static IP/gateway/DNS&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;&lt;CODE class="bg-text-200/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]"&gt;nslookup locator.cgnx.net&lt;/CODE&gt; from the connector times out — no DNS response, despite DNS servers being reachable and correctly configured&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Verified no firewall blocking on local network path (NGFW + edge firewall logs show no drops for this traffic after rule adjustments)&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Home ISP router&amp;nbsp; configured in DMZ mode pointing to firewall WAN IP to rule out double-NAT interference&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal" dir="ltr"&gt;&lt;STRONG&gt;Observed status in Strata Cloud Manager:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL class="[li_&amp;amp;]:mb-0 [li_&amp;amp;]:mt-1 [li_&amp;amp;]:gap-1 [&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3 print:block print:space-y-1" dir="ltr"&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Control Plane:&amp;nbsp; Active&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Tunnel: consistently Inactive&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Config Status: "Tunnel Config Done"&lt;/LI&gt;
&lt;LI class="font-claude-response-body whitespace-normal break-words pl-2"&gt;Diagnostic tools in SCM (Dump Overview, Packet Captures under Connector → Actions → Diagnostics) spin indefinitely and never load, across multiple connector redeployments&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="font-claude-response-body break-words whitespace-normal" dir="ltr"&gt;&lt;STRONG&gt;Question:&lt;/STRONG&gt; Is there a known limitation for ZTNA Connector tunnel establishment or SCM diagnostic tooling on NFR tenants? Or is there a specific requirement (e.g., licensing scope, region availability) we may be missing for tunnel establishment to complete?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thank's for your help&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2026 10:20:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/ztna-connector-tunnel-remains-inactive-despite-active-control/m-p/1262167#M1320</guid>
      <dc:creator>M.Salah734756</dc:creator>
      <dc:date>2026-08-18T10:20:10Z</dc:date>
    </item>
  </channel>
</rss>

