<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to Site VPN Tunnel is up, but no traffic pass through in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151561#M50180</link>
    <description>&lt;P&gt;Worth checking&amp;nbsp;the below article:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show vpn flow name - check encap/decap bytes&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just some additional info!&lt;/P&gt;</description>
    <pubDate>Thu, 06 Apr 2017 20:49:01 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-04-06T20:49:01Z</dc:date>
    <item>
      <title>Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151523#M50165</link>
      <description>&lt;P&gt;Hi all.&amp;nbsp; I am trying to setup a site to site VPN tunnel with one of our customer.&amp;nbsp; I've got the dedicated layer 3 zone, tunnel interface, IKE Gateway, Virtual Router etc. configured per the Palo Alto admin guide.&amp;nbsp; In the "IPSec Tunnels" section, it shows the VPN tunnel is up.&amp;nbsp; However, I cannot access any of the server located at the customer's environment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Traffic monitor tab, it shows the traffic is sending over to the customer's network, yet nothing is returning from them (Bytes Send = xxx; Bytes Received = 0; Packet Send = xxx, Packet Received = 0).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I missing something here?&lt;/P&gt;&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 18:17:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151523#M50165</guid>
      <dc:creator>UXPSystems</dc:creator>
      <dc:date>2017-04-06T18:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151531#M50166</link>
      <description>&lt;P&gt;Hi UXPSystems,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd say either the reply packet is getting dropped or we are simply not receiving any replies.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Take pcaps with filters:&lt;/P&gt;&lt;P&gt;1 - x.x.x.x - y.y.y.y&lt;/P&gt;&lt;P&gt;2 - y.y.y.y - x.x.x.x&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The numbers '1' and '2' are the 2 rows you will create in the packet filter. The addresses x.x.x.x and y.y.y.y are the source and destination (and back) for the actual IPs you are pinging from and to. Configure packet capture for the drop, receive and transmit stage. Refer to this KB for more information on pcaps -&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Run-a-Packet-Capture/ta-p/62390&amp;nbsp;" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Run-a-Packet-Capture/ta-p/62390&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we are simply not receiving packets, then the issue could be return route on the remote site. If we are receiving packets, then we'd have to check in the counters and flow basic (debug logs) to find out where it's going.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additionally, select more colums in the traffic logs, like ingress and egress interfaces, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anurag&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 18:29:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151531#M50166</guid>
      <dc:creator>ansharma</dc:creator>
      <dc:date>2017-04-06T18:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151561#M50180</link>
      <description>&lt;P&gt;Worth checking&amp;nbsp;the below article:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show vpn flow name - check encap/decap bytes&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just some additional info!&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 20:49:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151561#M50180</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-06T20:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151742#M50224</link>
      <description>&lt;P&gt;Hi.&amp;nbsp; The PCAP Receive filter file shows bunch of TCP Retransmission to the target server.&amp;nbsp; Wondering if the traffic doesn't know how to reach to the target ....&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 15:34:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151742#M50224</guid>
      <dc:creator>UXPSystems</dc:creator>
      <dc:date>2017-04-07T15:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151743#M50225</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Packets received by the firewall from your side, right? Do you have a static route configured pointing to the tunnel interface to reach another end subnet?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Perform-FIB-Lookup-for-a-Particular-Destination/ta-p/52188" target="_self"&gt;FIB&lt;/A&gt; lookup.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 15:44:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151743#M50225</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-07T15:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151744#M50226</link>
      <description>&lt;P&gt;is it a PA on both ends of the tunnel? or what device are they using? dunno if it's of any help, but just throwing it out there because there is the requirement of the use of proxy ids in order to establish a tunnel with a policy-based vpn device to essentially identify the interesting traffic.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 15:42:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151744#M50226</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-04-07T15:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151745#M50227</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/58582"&gt;@bradk14&lt;/a&gt;&amp;nbsp;another good point. Phase 2 definitely&amp;nbsp;would not be up if proxy ID mismatch.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 15:45:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151745#M50227</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-07T15:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151749#M50228</link>
      <description>&lt;P&gt;I am not sure about the VPN product that the other end is using.&amp;nbsp; As a test, if I configured the Proxy ID, the tunnel status goes into "down" state (red).&amp;nbsp;&lt;/P&gt;&lt;P&gt;A static route existed for the remote network&lt;/P&gt;&lt;P&gt;If I do a tracert to the remote server, the tracert stops at our PA firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PA traffic monitor will show packets has send to the remote network, but no packet receives (eg: no return traffic).&lt;/P&gt;&lt;P&gt;I am wondering if the remtoe network didn't configure their route properly.&amp;nbsp; Otherwise I don't see any issue on the VPN tunnel side, it is up, just no traffic coming back.&amp;nbsp; Also the tracert result bothers me, as it shows stopped on our PA.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 16:46:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151749#M50228</guid>
      <dc:creator>UXPSystems</dc:creator>
      <dc:date>2017-04-07T16:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151759#M50230</link>
      <description>&lt;P&gt;If you don't configure ProxyID in Palo it falls back to default ProxyID &amp;nbsp;and sends over 0.0.0.0/0&lt;/P&gt;&lt;P&gt;ProxyID is needed only if you connect to device that does policy based vpn instead of route based vpn. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most likely other end does not have route back to you.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 18:22:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151759#M50230</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-04-07T18:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151775#M50233</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46153"&gt;@UXPSystems&lt;/a&gt;&amp;nbsp;as you said seems like other side having an issue to return traffic. You also can check encapsulation counters:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; show vpn flow name - check encap/decap bytes&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UU.PNG" style="width: 579px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8691i1431602075D40C78/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="UU.PNG" alt="UU.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Will give you a very good indication that the traffic is encapsulated and sent through the&amp;nbsp;tunnel.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 18:35:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151775#M50233</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-07T18:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151974#M50287</link>
      <description>&lt;P&gt;Hi all.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I ran the "show vpn flow name" command, and I can see the "&lt;SPAN&gt;encap/decap bytes" field logs data there, and no authentication errors.&amp;nbsp; The tunnel looks perfectly fine.&amp;nbsp; Pretty much stuck on this one ...&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 16:52:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151974#M50287</guid>
      <dc:creator>UXPSystems</dc:creator>
      <dc:date>2017-04-10T16:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151993#M50291</link>
      <description>&lt;P&gt;You don't&amp;nbsp;run this tunnel between Azure on PAN-OS 7.1.3 or previous versions, do&amp;nbsp;you?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BUG.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8730iC66052430195D08E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="BUG.PNG" alt="BUG.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 17:32:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/151993#M50291</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-10T17:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/152077#M50318</link>
      <description>&lt;P&gt;Hi.&amp;nbsp; Nope, not running on Azure.&amp;nbsp; It looks like the customer end is running on Juniper firewall if that helps.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 21:23:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/152077#M50318</guid>
      <dc:creator>UXPSystems</dc:creator>
      <dc:date>2017-04-10T21:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/152080#M50320</link>
      <description>&lt;P&gt;Let's ask kindly&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 21:29:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/152080#M50320</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-10T21:29:45Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/152092#M50325</link>
      <description>&lt;P&gt;Did you check the reply traffic route in the routing table of the peer (Juniper)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Take pcaps on the peer and see if it's receiving packets from PA and/or sending anything back.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 22:54:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/152092#M50325</guid>
      <dc:creator>ansharma</dc:creator>
      <dc:date>2017-04-10T22:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/152167#M50341</link>
      <description>&lt;P&gt;Hi all.&amp;nbsp; I don't have access to customer's network, thus no pcacp available from their end.&amp;nbsp; It is a pain to get a hold of their staff to investigate this issue.&amp;nbsp; They keep responding they've done the necessary configuration at their end, and from their prespective, this VPN configuration has been completed at their end.&amp;nbsp; Yet no network traffic coming from their end.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've gone over the troubleshooting step as outline here,&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I can see the "Encap Bytes" value keep increasing, while the "Decap Bytes" stays constant.&amp;nbsp; Per the explaination, that indicate network traffic is going out, but nothing returns from the target.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 13:17:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/152167#M50341</guid>
      <dc:creator>UXPSystems</dc:creator>
      <dc:date>2017-04-11T13:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/152185#M50345</link>
      <description>&lt;P&gt;I think in this&amp;nbsp;situation you and another end should go for a conference call and get all troubleshooting steps alive rather than&amp;nbsp;do a finger-pointing. Without the other end, it is going to be hard to get this resolved as you can see.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 13:59:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/152185#M50345</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-11T13:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/152292#M50371</link>
      <description>&lt;P&gt;From what you described here i would say that the issue is definitelly on the other side. If you are sending packets into tunnel, they are getting them. Now they must find out what happens with them. And i feel your pain. I've also have many occasions when i was debugging VPN on the other end as well even tho i had contract only with my customer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One (very unlikely) issue could also be SPI missmatch; exchange info about SPIs with admin on the other end and check if they match.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess on your side you have only 1 pair?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 06:23:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/152292#M50371</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-04-12T06:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN Tunnel is up, but no traffic pass through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/152832#M50502</link>
      <description>&lt;P&gt;Hi all.&amp;nbsp; After couple of email exchange with the customer, and conference calls.&amp;nbsp; It ends up their network administartor configured the VPN tunnel, yet he didn't configure the routes for this VPN connection.&amp;nbsp; That explains why the tunnel is up, but no traffic goes through.&amp;nbsp; Now they've assigned another network administrator to look into, yet he is on vacation till mid May....&amp;nbsp; Nothing can be done till mid May.&amp;nbsp; Thank you for all the feedback, much appreciated! &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2017 13:23:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-tunnel-is-up-but-no-traffic-pass-through/m-p/152832#M50502</guid>
      <dc:creator>UXPSystems</dc:creator>
      <dc:date>2017-04-17T13:23:40Z</dc:date>
    </item>
  </channel>
</rss>

