<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC to Azure establish but cannot use traceroute in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-to-azure-establish-but-cannot-use-traceroute/m-p/1252118#M126279</link>
    <description>&lt;P&gt;Packet capture was taken on Palo and you see it being dropped?&lt;/P&gt;
&lt;P&gt;Do you have IP configured on tunnel interface that is used for tunnel towards Azure?&lt;/P&gt;
&lt;P&gt;Do you have interface mgmt profile attached to tunnel interface permitting ping?&lt;/P&gt;</description>
    <pubDate>Tue, 14 Apr 2026 01:34:57 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2026-04-14T01:34:57Z</dc:date>
    <item>
      <title>IPSEC to Azure establish but cannot use traceroute</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-to-azure-establish-but-cannot-use-traceroute/m-p/1252029#M126276</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have PA 410&amp;nbsp;and has established an ipsec tunnel to Azure.&lt;BR /&gt;We testing from PA-410&amp;nbsp;to cloud that&amp;nbsp;ping, SSH, and traceroute are working normally.&lt;BR /&gt;However, when testing from cloud to PA-410, ping and SSH work as expected, but traceroute does not function.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp;A packet capture was performed and it was observed that the traffic UDP was dropped by the firewall. However, a security policy allowing the traffic has already been configured.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;We dont use Zone protection profile and i saw the Azure cloud limitation for traceroute.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any suggestion or advise?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2026 09:48:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-to-azure-establish-but-cannot-use-traceroute/m-p/1252029#M126276</guid>
      <dc:creator>Fariq_Zaidi</dc:creator>
      <dc:date>2026-04-10T09:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC to Azure establish but cannot use traceroute</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-to-azure-establish-but-cannot-use-traceroute/m-p/1252118#M126279</link>
      <description>&lt;P&gt;Packet capture was taken on Palo and you see it being dropped?&lt;/P&gt;
&lt;P&gt;Do you have IP configured on tunnel interface that is used for tunnel towards Azure?&lt;/P&gt;
&lt;P&gt;Do you have interface mgmt profile attached to tunnel interface permitting ping?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 01:34:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-to-azure-establish-but-cannot-use-traceroute/m-p/1252118#M126279</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2026-04-14T01:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC to Azure establish but cannot use traceroute</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-to-azure-establish-but-cannot-use-traceroute/m-p/1252122#M126280</link>
      <description>&lt;P&gt;Packet capture was taken on Palo and you see it being dropped?&lt;/P&gt;
&lt;P&gt;Yes, UDP packet&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Fariq_Zaidi_0-1776131699745.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71199iC2E42BDB1430AEF9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Fariq_Zaidi_0-1776131699745.png" alt="Fariq_Zaidi_0-1776131699745.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have IP configured on tunnel interface that is used for tunnel towards Azure? NO&lt;/P&gt;
&lt;P&gt;Do you have interface mgmt profile attached to tunnel interface permitting ping? NO&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Fariq_Zaidi_1-1776131734954.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71200i2321DE3D668C26F6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Fariq_Zaidi_1-1776131734954.png" alt="Fariq_Zaidi_1-1776131734954.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 01:57:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-to-azure-establish-but-cannot-use-traceroute/m-p/1252122#M126280</guid>
      <dc:creator>Fariq_Zaidi</dc:creator>
      <dc:date>2026-04-14T01:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC to Azure establish but cannot use traceroute</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-to-azure-establish-but-cannot-use-traceroute/m-p/1252130#M126281</link>
      <description>&lt;P&gt;You need to have IP on Palo tunnel interface if you want to see every hop on the way in your traceroute.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 02:35:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-to-azure-establish-but-cannot-use-traceroute/m-p/1252130#M126281</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2026-04-14T02:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC to Azure establish but cannot use traceroute</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-to-azure-establish-but-cannot-use-traceroute/m-p/1252135#M126282</link>
      <description>&lt;P&gt;Drops are expected.&lt;/P&gt;
&lt;P&gt;If you add destination into packet capture filter and then run command "show counter global filter delta yes packet-filter yes" then you see packets dropped with reason "Packets dropped: IP TTL reaches zero"&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 03:00:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-to-azure-establish-but-cannot-use-traceroute/m-p/1252135#M126282</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2026-04-14T03:00:43Z</dc:date>
    </item>
  </channel>
</rss>

