<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: unable to reach peer end public IP via vpn tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310037#M80311</link>
    <description>&lt;P&gt;Can you please check once if tunnel interface belongs to VPN zone?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
    <pubDate>Fri, 07 Feb 2020 14:47:47 GMT</pubDate>
    <dc:creator>SutareMayur</dc:creator>
    <dc:date>2020-02-07T14:47:47Z</dc:date>
    <item>
      <title>unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/309982#M80296</link>
      <description>&lt;P&gt;HI Team&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have created S2S VPN tunnel between palo alto and cyberoam firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tunnel is up but the traffic is not flow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under Cyberoam firewall there is one server with public IP 144.21.X.X.&lt;/P&gt;&lt;P&gt;From palo alto we need to reach the peer end public IP 144.21.X.X via the vpn tunnel.&lt;/P&gt;&lt;P&gt;but whenever I tried to reach the peer end&amp;nbsp; public IP 144.21.X.X its going via the internet rule instead of vpn rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our requirement is that traffic should go via the vpn tunnel to reach the IP 144.21.X.X&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured the PBF policy but its not work.. Please help on this&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mohammed Asik&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 09:14:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/309982#M80296</guid>
      <dc:creator>MohammedAsik</dc:creator>
      <dc:date>2020-02-07T09:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/309986#M80297</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is expected.&lt;/P&gt;&lt;P&gt;Your PEER IP communication will happen over internet only. The proxy IDs configured will only pass through tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Mayur&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 09:43:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/309986#M80297</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-07T09:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310008#M80304</link>
      <description>&lt;P&gt;HI Mayur&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured proxy ID s also. but its not working&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;BR /&gt;Mohammed Asik&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 12:05:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310008#M80304</guid>
      <dc:creator>MohammedAsik</dc:creator>
      <dc:date>2020-02-07T12:05:37Z</dc:date>
    </item>
    <item>
      <title>Re: unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310011#M80305</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/106720"&gt;@MohammedAsik&lt;/a&gt;&amp;nbsp;Check if routes are pointed towards proper tunnel interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Verify traffic logs once if matching correct security policy and sending traffic to correct tunnel interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Mayur&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 12:28:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310011#M80305</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-07T12:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310025#M80307</link>
      <description>&lt;P&gt;Please find the below routing and security policy details&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;144.250.3.222/32&amp;nbsp; &amp;nbsp;0.0.0.0&amp;nbsp; &amp;nbsp;10&amp;nbsp; &amp;nbsp;A S&amp;nbsp; &amp;nbsp;tunnel.10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;{&lt;BR /&gt;from inside;&lt;BR /&gt;source 172.31.62.0/24;&lt;BR /&gt;source-region none;&lt;BR /&gt;to vpn;&lt;BR /&gt;destination 144.250.3.222;&lt;BR /&gt;destination-region none;&lt;BR /&gt;user any;&lt;BR /&gt;category any;&lt;BR /&gt;application/service 0:any/any/any/any;&lt;BR /&gt;action allow;&lt;BR /&gt;icmp-unreachable: no&lt;BR /&gt;terminal yes;&lt;BR /&gt;}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mohammed Asik&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 13:25:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310025#M80307</guid>
      <dc:creator>MohammedAsik</dc:creator>
      <dc:date>2020-02-07T13:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310029#M80308</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/106720"&gt;@MohammedAsik&lt;/a&gt;&amp;nbsp;What is 0.0.0.0 in the route? is it next hop?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What you found in traffic logs?? Is firewall passing it to same tunnel interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Mayur&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 13:56:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310029#M80308</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-07T13:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310031#M80309</link>
      <description>&lt;P&gt;Mayur&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;its a tunnel interface. thats why its showing next hop as 0.0.0.0.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In traffic logs its taking the internet rule and its not pass through tunnel interface. its passing through internet interface Ethernet 1/1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mohammed Asik&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 14:25:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310031#M80309</guid>
      <dc:creator>MohammedAsik</dc:creator>
      <dc:date>2020-02-07T14:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310037#M80311</link>
      <description>&lt;P&gt;Can you please check once if tunnel interface belongs to VPN zone?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 14:47:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310037#M80311</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-07T14:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310043#M80312</link>
      <description>&lt;P&gt;Please find the below ss&amp;nbsp; tunnel.10 interface&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MohammedAsik_0-1581089649123.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23868iECCF7AEFC6FBCC13/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MohammedAsik_0-1581089649123.png" alt="MohammedAsik_0-1581089649123.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 15:34:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310043#M80312</guid>
      <dc:creator>MohammedAsik</dc:creator>
      <dc:date>2020-02-07T15:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310077#M80318</link>
      <description>&lt;P&gt;Something is mis configured .&amp;nbsp; Check&lt;SPAN&gt;&amp;nbsp;any pbf which is sending traffic on external interface or traffic getting NAT?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;please share traffic log snap?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 23:16:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310077#M80318</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-07T23:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310115#M80330</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Mohammed,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you checked your NAT rules?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since&amp;nbsp;&lt;SPAN&gt;144.21.X.X is a public IP, you might be hitting a NAT rule for the Internet depending on which zone your tunnel interface is located.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I see that your Tunnel interface is part of the VPN zone. Is the source traffic is coming from the Inside zone? If so, do you have a security rule on your FW allowing communication between the Inside and VPN zone?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 21:54:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310115#M80330</guid>
      <dc:creator>svelez</dc:creator>
      <dc:date>2020-02-07T21:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310129#M80332</link>
      <description>&lt;P&gt;Hi Svelez&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes I have security rule to allow from inside to vpn zone. Please find the below security rule and static route for respective tunnel traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;144.250.3.222/32&amp;nbsp; &amp;nbsp;0.0.0.0&amp;nbsp; &amp;nbsp;10&amp;nbsp; &amp;nbsp;A S&amp;nbsp; &amp;nbsp;tunnel.10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;{&lt;BR /&gt;from inside;&lt;BR /&gt;source 172.31.62.0/24;&lt;BR /&gt;source-region none;&lt;BR /&gt;to vpn;&lt;BR /&gt;destination 144.250.3.222;&lt;BR /&gt;destination-region none;&lt;BR /&gt;user any;&lt;BR /&gt;category any;&lt;BR /&gt;application/service 0:any/any/any/any;&lt;BR /&gt;action allow;&lt;BR /&gt;icmp-unreachable: no&lt;BR /&gt;terminal yes;&lt;BR /&gt;}&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Feb 2020 06:09:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310129#M80332</guid>
      <dc:creator>MohammedAsik</dc:creator>
      <dc:date>2020-02-08T06:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310350#M80353</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/106720"&gt;@MohammedAsik&lt;/a&gt;&amp;nbsp; hey, are you still facing issues?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Mayur&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 08:03:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310350#M80353</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-10T08:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310559#M80414</link>
      <description>&lt;P&gt;Hi Mayur&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, still I am facing this issue&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 08:35:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310559#M80414</guid>
      <dc:creator>MohammedAsik</dc:creator>
      <dc:date>2020-02-11T08:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310693#M80449</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/106720"&gt;@MohammedAsik&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We can check it once over zoom or webex if you want.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Mayur&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 02:59:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310693#M80449</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-12T02:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310728#M80461</link>
      <description>&lt;P&gt;Hi Mayur&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issue got resolved after added the IP on tunnel interface.and PBF policy.I followed the below KB article.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIeCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIeCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Mohammed Asik&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 08:26:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310728#M80461</guid>
      <dc:creator>MohammedAsik</dc:creator>
      <dc:date>2020-02-12T08:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: unable to reach peer end public IP via vpn tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310740#M80464</link>
      <description>&lt;P&gt;That's great !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 09:11:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-peer-end-public-ip-via-vpn-tunnel/m-p/310740#M80464</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-12T09:11:30Z</dc:date>
    </item>
  </channel>
</rss>

