<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Static route path monitor for dual IPSec tunnels not recovering in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-path-monitor-for-dual-ipsec-tunnels-not-recovering/m-p/554982#M112738</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/68439"&gt;@Layne-Corbett&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Can you post more detailed information in what you're actually doing so far? Prevents having to read through everything and assume that every step was followed, which can lead to improper assumptions about something you could be overlooking.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Aug 2023 04:49:04 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2023-08-24T04:49:04Z</dc:date>
    <item>
      <title>Static route path monitor for dual IPSec tunnels not recovering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-path-monitor-for-dual-ipsec-tunnels-not-recovering/m-p/554967#M112734</link>
      <description>&lt;P&gt;We have two ISP's and created redundant IPSec tunnels to our datacenter (one per ISP).&amp;nbsp; We followed this doc on how to setup tunnel failover even though it did not mention that the tunnel IP's needed to be added to allowed tunnel traffic via tunnel Proxy ID setting:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POO0CAO" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POO0CAO&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I thought I found the issue after reading this doc about monitor source address allowed thru tunnel, but even after adding the tunnel IP range to tunnel Proxy ID, monitor still shows route as down even though tunnel is up:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/static-route-path-monitoring-for-automated-vpn-failover/td-p/349743" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/static-route-path-monitoring-for-automated-vpn-failover/td-p/349743&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So at this point I don't know what I missed in the config's &lt;span class="lia-unicode-emoji" title=":persevering_face:"&gt;😣&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 02:24:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-path-monitor-for-dual-ipsec-tunnels-not-recovering/m-p/554967#M112734</guid>
      <dc:creator>Layne-Corbett</dc:creator>
      <dc:date>2023-08-24T02:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: Static route path monitor for dual IPSec tunnels not recovering</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-path-monitor-for-dual-ipsec-tunnels-not-recovering/m-p/554982#M112738</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/68439"&gt;@Layne-Corbett&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Can you post more detailed information in what you're actually doing so far? Prevents having to read through everything and assume that every step was followed, which can lead to improper assumptions about something you could be overlooking.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 04:49:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-path-monitor-for-dual-ipsec-tunnels-not-recovering/m-p/554982#M112738</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-08-24T04:49:04Z</dc:date>
    </item>
  </channel>
</rss>

