<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ping Failed (aged out) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ping-failed-aged-out/m-p/585268#M116849</link>
    <description>&lt;P&gt;Hello friends,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I configured site-to-site vpn between two firewalls and the ping from network behind firewall (internal network) to other internal network is failed (timeout) while the traffic shows allowed in the firewall logs. The Tunnel is Up and Green status. The configuration is the same on both firewalls and straightforward.&lt;/P&gt;
&lt;P&gt;Policy allows all applications&lt;/P&gt;
&lt;P&gt;No NAT&lt;/P&gt;
&lt;P&gt;Static route between both sites and Peers are pingable&lt;/P&gt;
&lt;P&gt;Static route for the internal networks using the Tunnel interface&lt;/P&gt;
&lt;P&gt;The Tunnel interface does not have ip address&lt;/P&gt;
&lt;P&gt;Dedicate Zone for the S2SVPN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not sure if this is a Routing or Policy issue, but current setting is allowing everything. Please advise if you have seen this scenario before.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Apr 2024 01:01:41 GMT</pubDate>
    <dc:creator>Hayder</dc:creator>
    <dc:date>2024-04-30T01:01:41Z</dc:date>
    <item>
      <title>Ping Failed (aged out)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-failed-aged-out/m-p/585268#M116849</link>
      <description>&lt;P&gt;Hello friends,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I configured site-to-site vpn between two firewalls and the ping from network behind firewall (internal network) to other internal network is failed (timeout) while the traffic shows allowed in the firewall logs. The Tunnel is Up and Green status. The configuration is the same on both firewalls and straightforward.&lt;/P&gt;
&lt;P&gt;Policy allows all applications&lt;/P&gt;
&lt;P&gt;No NAT&lt;/P&gt;
&lt;P&gt;Static route between both sites and Peers are pingable&lt;/P&gt;
&lt;P&gt;Static route for the internal networks using the Tunnel interface&lt;/P&gt;
&lt;P&gt;The Tunnel interface does not have ip address&lt;/P&gt;
&lt;P&gt;Dedicate Zone for the S2SVPN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not sure if this is a Routing or Policy issue, but current setting is allowing everything. Please advise if you have seen this scenario before.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 01:01:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-failed-aged-out/m-p/585268#M116849</guid>
      <dc:creator>Hayder</dc:creator>
      <dc:date>2024-04-30T01:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: Ping Failed (aged out)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-failed-aged-out/m-p/585306#M116855</link>
      <description>&lt;P&gt;did you also set a route for the remote network to egress into the tunnel interface on both sides:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_0-1714467041615.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59349i3F2D4511FF78074E/image-size/large?v=v2&amp;amp;px=999" role="button" title="reaper_0-1714467041615.png" alt="reaper_0-1714467041615.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;are you seein gthe ping arrive on the remote side? if you do, look at the session details if the next hop interface is the correct one etc&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 08:51:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-failed-aged-out/m-p/585306#M116855</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-04-30T08:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: Ping Failed (aged out)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-failed-aged-out/m-p/585383#M116871</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp; Thank you for your response. There was a network issue and firewall configuration was fine.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 17:22:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-failed-aged-out/m-p/585383#M116871</guid>
      <dc:creator>Hayder</dc:creator>
      <dc:date>2024-04-30T17:22:06Z</dc:date>
    </item>
  </channel>
</rss>

