<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why should tunnel monitoring be considered when there is already a predefined tunnel status report available in Prisma Access? in Prisma Access Insights Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-insights/why-should-tunnel-monitoring-be-considered-when-there-is-already/m-p/567217#M12</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/230645"&gt;@AkashThangavel&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Please note that I don't have any experience with Prisma Access, but I can make an educated guess:"&lt;BR /&gt;&lt;BR /&gt;- I would assume Prisma Access "Tunnel Monitoring" to work exactly the same way as self-hosted/managed Palo Alto firewall. When tunnel monitor is enabled, firewall will generate ping probe packets to the destination IP, and if there is no reply firewall will consider this tunnel as down, even if the IPsec SA (phase1 and phase2) are actually still up. One of the use case of such monitor is to "disable" any static or policy based routes associated with that tunnel and failover the traffic to redundant path. Another benefit is that the constant ping will keep the tunnel up even if there is no actual traffic, which is equivalent to "aways-up" for the VPN tunnel.&lt;BR /&gt;&lt;BR /&gt;- While the email alert will only indicate that the tunnel is down and most importantly to trigger such alert, IPsec SAs needs to be down (no phase1 or phase2).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You&amp;nbsp; are correct that both can triggers an alert event indicating issues with the tunnel, but tunnel monitor take a step further by verifying of the layer3 path over that tunnel is indeed working and provide a way to dynamically switch to redundant path (if you have such in your setup).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Nov 2023 14:12:43 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2023-11-27T14:12:43Z</dc:date>
    <item>
      <title>Why should tunnel monitoring be considered when there is already a predefined tunnel status report available in Prisma Access?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-insights/why-should-tunnel-monitoring-be-considered-when-there-is-already/m-p/567196#M11</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;
&lt;P&gt;Why should tunnel monitoring be considered when there is already a predefined tunnel status report available in Prisma Access?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AkashThangavel_0-1701087947010.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55433iA5C07E6C93C00386/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AkashThangavel_0-1701087947010.png" alt="AkashThangavel_0-1701087947010.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AkashThangavel_2-1701090527421.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55437i97986FE64AA89A52/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AkashThangavel_2-1701090527421.png" alt="AkashThangavel_2-1701090527421.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The setup is already predefined; you just need to input the respective email IDs to ensure the timely delivery of the reports.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AkashThangavel_1-1701089096193.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55434iE549CF4F13BDEF59/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AkashThangavel_1-1701089096193.png" alt="AkashThangavel_1-1701089096193.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AkashThangavel_0-1701090350984.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55435i4D96876C45E72BAD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AkashThangavel_0-1701090350984.png" alt="AkashThangavel_0-1701090350984.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Tunnel monitoring aims to generate critical logs, a task that is already accomplished through the use of these predefined alert codes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please distinguish this variation&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;
&lt;P&gt;Akash Thangavel&lt;/P&gt;
&lt;P&gt;Network Security Engineer&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 13:09:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-insights/why-should-tunnel-monitoring-be-considered-when-there-is-already/m-p/567196#M11</guid>
      <dc:creator>AkashThangavel</dc:creator>
      <dc:date>2023-11-27T13:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why should tunnel monitoring be considered when there is already a predefined tunnel status report available in Prisma Access?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-insights/why-should-tunnel-monitoring-be-considered-when-there-is-already/m-p/567217#M12</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/230645"&gt;@AkashThangavel&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Please note that I don't have any experience with Prisma Access, but I can make an educated guess:"&lt;BR /&gt;&lt;BR /&gt;- I would assume Prisma Access "Tunnel Monitoring" to work exactly the same way as self-hosted/managed Palo Alto firewall. When tunnel monitor is enabled, firewall will generate ping probe packets to the destination IP, and if there is no reply firewall will consider this tunnel as down, even if the IPsec SA (phase1 and phase2) are actually still up. One of the use case of such monitor is to "disable" any static or policy based routes associated with that tunnel and failover the traffic to redundant path. Another benefit is that the constant ping will keep the tunnel up even if there is no actual traffic, which is equivalent to "aways-up" for the VPN tunnel.&lt;BR /&gt;&lt;BR /&gt;- While the email alert will only indicate that the tunnel is down and most importantly to trigger such alert, IPsec SAs needs to be down (no phase1 or phase2).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You&amp;nbsp; are correct that both can triggers an alert event indicating issues with the tunnel, but tunnel monitor take a step further by verifying of the layer3 path over that tunnel is indeed working and provide a way to dynamically switch to redundant path (if you have such in your setup).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 14:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-insights/why-should-tunnel-monitoring-be-considered-when-there-is-already/m-p/567217#M12</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-11-27T14:12:43Z</dc:date>
    </item>
  </channel>
</rss>

