<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tunnel monitor Prisma Access in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/tunnel-monitor-prisma-access/m-p/420178#M210</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I build a service connection with Prisma Access (Panorama Managed) and on-prem PA firewall.&lt;/P&gt;&lt;P&gt;As I would like to setup a tunnel monitor, but it is required a IP address for tunnel interface and destination.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What IP should I input for destination? "Tunnel Monitor IP Address" show in "Service Infrastructure"?&lt;/P&gt;&lt;P&gt;And what IP should I assign for op-prem firewall tunnel interface? Since I cannot use any IP inside "infrastructure subnet" of Prisma Acess according to the deployment document.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 18 Jul 2021 04:32:28 GMT</pubDate>
    <dc:creator>JoeKwok</dc:creator>
    <dc:date>2021-07-18T04:32:28Z</dc:date>
    <item>
      <title>Tunnel monitor Prisma Access</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/tunnel-monitor-prisma-access/m-p/420178#M210</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I build a service connection with Prisma Access (Panorama Managed) and on-prem PA firewall.&lt;/P&gt;&lt;P&gt;As I would like to setup a tunnel monitor, but it is required a IP address for tunnel interface and destination.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What IP should I input for destination? "Tunnel Monitor IP Address" show in "Service Infrastructure"?&lt;/P&gt;&lt;P&gt;And what IP should I assign for op-prem firewall tunnel interface? Since I cannot use any IP inside "infrastructure subnet" of Prisma Acess according to the deployment document.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jul 2021 04:32:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/tunnel-monitor-prisma-access/m-p/420178#M210</guid>
      <dc:creator>JoeKwok</dc:creator>
      <dc:date>2021-07-18T04:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel monitor Prisma Access</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/tunnel-monitor-prisma-access/m-p/424704#M222</link>
      <description>&lt;P&gt;For the prisma access you need to see under the Service Infrastructure as it automatically gives ip addresses to it objects like the Service Infrastructure CAN or Remote Network SPN&amp;nbsp; or the Mobile Gateway. You can also select your local firewall to ping an IP address with the tunnel monitor that is in another site of yours that is again connected to the Prisma access as the idea for the tunnel monitor is to ping an ip address that the ping passthrough the tunnel to reach it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the Prisma Access side can you try to specify the tunnel monitor ip address to be a DNS server, LDAP server etc. that is in your local Data Center behind the Service Connection.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 10:39:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/tunnel-monitor-prisma-access/m-p/424704#M222</guid>
      <dc:creator>NikolayDimitrov</dc:creator>
      <dc:date>2021-08-05T10:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel monitor Prisma Access</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/tunnel-monitor-prisma-access/m-p/424990#M228</link>
      <description>&lt;P&gt;Hi Nikolay,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know what IP should I assign for "&lt;SPAN&gt;tunnel interface" in on-prem firewall site?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For a normal both on-prem firewall site-to-site VPN setting, I would assign two side firewall&amp;nbsp;tunnel interface&amp;nbsp;IP in a same subnet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However,&amp;nbsp;"infrastructure subnet" of Prisma Access cannot be assigned in on-prem side according to the deployment document, that mean I cannot use the same subnet IP for both site-to-site VPN interface&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 01:42:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/tunnel-monitor-prisma-access/m-p/424990#M228</guid>
      <dc:creator>JoeKwok</dc:creator>
      <dc:date>2021-08-06T01:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel monitor Prisma Access</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/tunnel-monitor-prisma-access/m-p/425051#M231</link>
      <description>&lt;P&gt;Hello Just check the Palo Alto Prisma documentation as it covers such cases:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prepare-the-prisma-access-infrastructure/create-a-service-connection" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prepare-the-prisma-access-infrastructure/create-a-service-connection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-for-networks/configure-prisma-access-for-networks" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-for-networks/configure-prisma-access-for-networks&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;%%%%%%%%%%%%%%%%%%%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;To enable tunnel monitoring for the service connection, select&lt;DIV&gt;Tunnel Monitor&lt;/DIV&gt;.&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;Enter a&lt;DIV&gt;Destination IP&lt;/DIV&gt;address.&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;Specify an IP address at your HQ or data center site to which Prisma Access can send ICMP ping requests for IPSec tunnel monitoring. Make sure that this address is reachable by ICMP from the entire Prisma Access infrastructure subnet. &amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;If you use tunnel monitoring with a peer device that uses multiple proxy IDs, specify a&lt;DIV&gt;Proxy ID&lt;/DIV&gt;or add a&lt;DIV&gt;New Proxy ID&lt;/DIV&gt;that allows access from the infrastructure subnet to your HQ or data center site.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;%%%%%%%%%%%%%%%%%%%%%%%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;%%%%%%%%%%%%%%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You must configure a static route on your CPE to the Tunnel Monitor IP Address for tunnel monitoring to function. To find the destination IP address to use for tunnel monitoring from your data center or HQ network to Prisma Access, select&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;Panorama&lt;/DIV&gt;&lt;DIV&gt;Cloud Services&lt;/DIV&gt;&lt;DIV&gt;Status&lt;/DIV&gt;&lt;DIV&gt;Network Details&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;, click the&lt;/P&gt;&lt;DIV&gt;Service Infrastructure&lt;/DIV&gt;&lt;P&gt;radio button, and find the&lt;/P&gt;&lt;DIV&gt;Tunnel Monitor IP Address&lt;/DIV&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;%%%%%%%%%%%%%%%%%%%&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 09:49:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/tunnel-monitor-prisma-access/m-p/425051#M231</guid>
      <dc:creator>NikolayDimitrov</dc:creator>
      <dc:date>2021-08-06T09:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel monitor Prisma Access</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/tunnel-monitor-prisma-access/m-p/425207#M235</link>
      <description>&lt;P&gt;I know the destination IP of CPE side for tunnel monitor is "&lt;SPAN&gt;Tunnel Monitor IP Address" and how to find it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My question is what is the IP should I assign for tunnel interface of CPE side (the source IP) which is required to enable tunnel monitoring function, Since Prisma access not allow me to use the IP of "infrastructure subnet".&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Aug 2021 08:46:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/tunnel-monitor-prisma-access/m-p/425207#M235</guid>
      <dc:creator>JoeKwok</dc:creator>
      <dc:date>2021-08-07T08:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel monitor Prisma Access</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/tunnel-monitor-prisma-access/m-p/433174#M251</link>
      <description>&lt;P&gt;If I have not been mistaken, you can use the tunnel monitor IP address under the &amp;gt;status &amp;gt;network deatils&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 18:15:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/tunnel-monitor-prisma-access/m-p/433174#M251</guid>
      <dc:creator>ManojV5</dc:creator>
      <dc:date>2021-09-10T18:15:34Z</dc:date>
    </item>
  </channel>
</rss>

