<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S2S VPN 2 VRs not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-2-vrs-not-working/m-p/487375#M104705</link>
    <description>&lt;P&gt;That was my initial though but there is no other device between the 2 boxes...&lt;/P&gt;&lt;P&gt;The first one is sending paccket, second is accepting them and replies.&lt;/P&gt;&lt;P&gt;But no replies on the first one (no drops no nothing) I will keep on searching.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In any case is this a valid approach (assuming that is done correctly should it be working)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason is the integration of 2 networks (one is quite sensitive). I want to have different routing table for each VR...&lt;/P&gt;</description>
    <pubDate>Mon, 16 May 2022 09:48:45 GMT</pubDate>
    <dc:creator>Pantelis</dc:creator>
    <dc:date>2022-05-16T09:48:45Z</dc:date>
    <item>
      <title>S2S VPN 2 VRs not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-2-vrs-not-working/m-p/486793#M104649</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an external IP /30 network. I also have another external IP /28.&lt;/P&gt;&lt;P&gt;I have created 2 VRs (with their ZONES).&lt;/P&gt;&lt;P&gt;VR1 is the main router with the /30 IP used for Internet connection.&lt;/P&gt;&lt;P&gt;VR2 is the second router (the one I just created)&lt;/P&gt;&lt;P&gt;I assigned one of the /28 IP to the second VR. When I terminate a S2S vpn (from another PA Box) to this IP(/28) the IPSEC tunnel is up but there is no inbound interesting traffic .&lt;/P&gt;&lt;P&gt;There is outbound traffic, the other site tries to reply to the ping request but no incoming traffic is captured on the box I have the problem(no drops, no nothing).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the other side there both in/out bound traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I terminate the S2S tunnel with the /30 IP (eventhough the tunnel is assigned to a zone on the second VR) the IPSEC tunnel is working as expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestion/thoughts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 14:00:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-2-vrs-not-working/m-p/486793#M104649</guid>
      <dc:creator>Pantelis</dc:creator>
      <dc:date>2022-05-12T14:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN 2 VRs not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-2-vrs-not-working/m-p/486832#M104657</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;My guess would be asymmetric routing. Any reason you are using 2 VR's? Just asking since I usually like to keep things simple.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 16:26:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-2-vrs-not-working/m-p/486832#M104657</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-05-12T16:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN 2 VRs not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-2-vrs-not-working/m-p/487375#M104705</link>
      <description>&lt;P&gt;That was my initial though but there is no other device between the 2 boxes...&lt;/P&gt;&lt;P&gt;The first one is sending paccket, second is accepting them and replies.&lt;/P&gt;&lt;P&gt;But no replies on the first one (no drops no nothing) I will keep on searching.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In any case is this a valid approach (assuming that is done correctly should it be working)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason is the integration of 2 networks (one is quite sensitive). I want to have different routing table for each VR...&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2022 09:48:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-2-vrs-not-working/m-p/487375#M104705</guid>
      <dc:creator>Pantelis</dc:creator>
      <dc:date>2022-05-16T09:48:45Z</dc:date>
    </item>
  </channel>
</rss>

