<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic trouble with GRE tunnel to Netskope in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-with-gre-tunnel-to-netskope/m-p/591507#M117791</link>
    <description>&lt;P&gt;Scenario: Panorama managed VM-700s. 10.2.9-h1.&amp;nbsp;using template stack. Netskope is a cloud web proxy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We setup new tunnel interface, GRE tunnel, static route, network monitor, allow rule, no-NAT rule, and PBF. We use a PBF because Netskope requires it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Clients don't go down the tunnel. I can't ping the probe IP from the clients nor from the firewall using &lt;EM&gt;ping source [tunnel_IP] host [probe_IP]&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I enable Keep Alive the tunnel goes down because&amp;nbsp;I can't ping the probe IP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Coworkers, Netskope support, Palo support, and a 3rd party consultant can't find anything wrong.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any known gotchas with this? Troubleshooting ideas?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jul 2024 20:34:20 GMT</pubDate>
    <dc:creator>1treelanedrv</dc:creator>
    <dc:date>2024-07-09T20:34:20Z</dc:date>
    <item>
      <title>trouble with GRE tunnel to Netskope</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-with-gre-tunnel-to-netskope/m-p/591507#M117791</link>
      <description>&lt;P&gt;Scenario: Panorama managed VM-700s. 10.2.9-h1.&amp;nbsp;using template stack. Netskope is a cloud web proxy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We setup new tunnel interface, GRE tunnel, static route, network monitor, allow rule, no-NAT rule, and PBF. We use a PBF because Netskope requires it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Clients don't go down the tunnel. I can't ping the probe IP from the clients nor from the firewall using &lt;EM&gt;ping source [tunnel_IP] host [probe_IP]&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I enable Keep Alive the tunnel goes down because&amp;nbsp;I can't ping the probe IP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Coworkers, Netskope support, Palo support, and a 3rd party consultant can't find anything wrong.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any known gotchas with this? Troubleshooting ideas?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 20:34:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-with-gre-tunnel-to-netskope/m-p/591507#M117791</guid>
      <dc:creator>1treelanedrv</dc:creator>
      <dc:date>2024-07-09T20:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: trouble with GRE tunnel to Netskope</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-with-gre-tunnel-to-netskope/m-p/592328#M117901</link>
      <description>&lt;P&gt;Netskope escalated the ticket and said I should change the static route destination to their public IP. but no change in the problem. New drawing attached.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Keep in mind we have the Keep Alives disabled because if they are enabled the Tunnel interfaces goes DOWN.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We then disabled the PBF Rule Monitoring option, and then the PBF rules goes UP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At that point, the test client started hitting the PBF, but no websites are working. Packet Capture shows no return traffic. Netskope then said it's a Palo problem. Palo ticket is still open and pcaps are being looked at.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 16:25:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-with-gre-tunnel-to-netskope/m-p/592328#M117901</guid>
      <dc:creator>1treelanedrv</dc:creator>
      <dc:date>2024-07-17T16:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: trouble with GRE tunnel to Netskope</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-with-gre-tunnel-to-netskope/m-p/593510#M118127</link>
      <description>&lt;P&gt;The solution was to create an additional No-NAT rule. We already had No-NAT from our test clients to Any destination with interface being the tunnel.1.&lt;/P&gt;
&lt;P&gt;However, the packet diagnostics found the need to have an inbound rule from Netskope's Peer IP to our public interface Source IP. Untrust to untrust zone. Any service (because GRE is a protocol not available for selection). And targeting that Ethernet1/1 interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Inbound: Netskope Peer (4.1.1.4) to Palo Ethernet 1/1 (3.1.1.3). Zone untrust to untrust. Any service. interface Eth1/1.&lt;BR /&gt;Last piece to allow tunnel traffic inside.&lt;/P&gt;
&lt;P&gt;Outbound: Inside Test Clients to Any destination. Zone trusted to untrust. Service tcp 80/443. interface Tunnel.1.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 13:44:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-with-gre-tunnel-to-netskope/m-p/593510#M118127</guid>
      <dc:creator>1treelanedrv</dc:creator>
      <dc:date>2024-07-30T13:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: trouble with GRE tunnel to Netskope</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-with-gre-tunnel-to-netskope/m-p/594885#M118388</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We are in a very similar situation to the one you describe in your case. After applying the "No-NAT" solution, were you able to re-enable the Keep Alives in the tunnels?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 08:01:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-with-gre-tunnel-to-netskope/m-p/594885#M118388</guid>
      <dc:creator>jzsaiz</dc:creator>
      <dc:date>2024-08-14T08:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: trouble with GRE tunnel to Netskope</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-with-gre-tunnel-to-netskope/m-p/594924#M118404</link>
      <description>&lt;P&gt;Yes, we were able to enable Keep Alives on the GRE Tunnels and the PBF Monitor. Funny thing is, I have since disabled the inbound NAT rule and the tunnel stays up. I also engaged a new consultant and he said he's never heard of that being necessary to get the tunnel working. I found the only way I could break the tunnel was by deleting the GRE Tunnel at Panorama. Disabling it wasn't enough. Kinda making me crazy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd love to hear if that solves your problem. Let us know.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 14:32:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-with-gre-tunnel-to-netskope/m-p/594924#M118404</guid>
      <dc:creator>1treelanedrv</dc:creator>
      <dc:date>2024-08-14T14:32:45Z</dc:date>
    </item>
  </channel>
</rss>

