<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN up but traffic not matching outbound policy, inbound policy is work in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-up-but-traffic-not-matching-outbound-policy-inbound-policy/m-p/339626#M85281</link>
    <description>&lt;P&gt;I know this, what I was asking is why.&amp;nbsp; Either way one my direct reports figured it out and it had to do with PBR and ISP failover.&amp;nbsp; Once he added the VPN-S2S zone and the remote CIDR to that policy traffic started to flow.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jul 2020 15:37:58 GMT</pubDate>
    <dc:creator>drewdown</dc:creator>
    <dc:date>2020-07-20T15:37:58Z</dc:date>
    <item>
      <title>VPN up but traffic not matching outbound policy, inbound policy is working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-up-but-traffic-not-matching-outbound-policy-inbound-policy/m-p/339242#M85217</link>
      <description>&lt;P&gt;Recent new VPN tunnel is up with Azure.&amp;nbsp; I can see traffic matching zone VPN-S2S &amp;gt; trust but anything from trust &amp;gt; VPN-S2S zone is not matching that specific policy.&amp;nbsp; The oubound traffic is matching the blanket outbound policy and I can't figure out why.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone help me figure out what the deal is?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drewdown_0-1595002943103.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26883i3609FF452FA4DBF5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="drewdown_0-1595002943103.png" alt="drewdown_0-1595002943103.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 16:22:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-up-but-traffic-not-matching-outbound-policy-inbound-policy/m-p/339242#M85217</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2020-07-17T16:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN up but traffic not matching outbound policy, inbound policy is work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-up-but-traffic-not-matching-outbound-policy-inbound-policy/m-p/339245#M85218</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it looks to be matching the right policy from CLI but the GUI shows the wrong one when filtering by the destination IP within Azure.&amp;nbsp; More importantly its not encrypting any packets towards AZURE and I can't figure that out.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;admin@fw3-3020(active)&amp;gt; show vpn flow tunnel-id 2 | match bytes
        encap bytes:            0
        decap bytes:            95848&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;admin@fw3-3020(active)&amp;gt; test security-policy-match source 10.100.1.2 destination 10.113.129.4 protocol 80

"Allow-Azure-Ok; index: 2" {
from trust;
source 10.100.0.0/16;

source-region none;
to VPN-S2S;
destination 10.113.128.0/20;
destination-region none;
user any;
category any;
application/service 0:any/any/any/app-default;
action allow;
icmp-unreachable: no
terminal yes;
}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drewdown_0-1595003365743.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26884i3A369DEDC5D65CE2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="drewdown_0-1595003365743.png" alt="drewdown_0-1595003365743.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 18:26:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-up-but-traffic-not-matching-outbound-policy-inbound-policy/m-p/339245#M85218</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2020-07-17T18:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN up but traffic not matching outbound policy, inbound policy is work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-up-but-traffic-not-matching-outbound-policy-inbound-policy/m-p/339299#M85222</link>
      <description>&lt;P&gt;More details...I can ping the AZURE instance from the PAN but not from anything behind the PAN on the LAN:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;admin@fw3-3020(active)&amp;gt; ping source 10.100.2.5 host 10.113.129.4
PING 10.113.129.4 (10.113.129.4) from 10.195.2.5 : 56(84) bytes of data.
64 bytes from 10.113.129.4: icmp_seq=1 ttl=128 time=11.8 ms
64 bytes from 10.113.129.4: icmp_seq=2 ttl=128 time=11.1 ms
64 bytes from 10.113.129.4: icmp_seq=3 ttl=128 time=11.4 ms
64 bytes from 10.113.129.4: icmp_seq=4 ttl=128 time=11.3 ms&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 17 Jul 2020 19:37:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-up-but-traffic-not-matching-outbound-policy-inbound-policy/m-p/339299#M85222</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2020-07-17T19:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: VPN up but traffic not matching outbound policy, inbound policy is work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-up-but-traffic-not-matching-outbound-policy-inbound-policy/m-p/339363#M85230</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34542"&gt;@drewdown&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The logs that you provided are showing that the traffic isn't taking the proper route from the look of things. The traffic log you provided shows that the traffic is attempting to route through your untrust interface.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2020 04:14:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-up-but-traffic-not-matching-outbound-policy-inbound-policy/m-p/339363#M85230</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-18T04:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN up but traffic not matching outbound policy, inbound policy is work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-up-but-traffic-not-matching-outbound-policy-inbound-policy/m-p/339626#M85281</link>
      <description>&lt;P&gt;I know this, what I was asking is why.&amp;nbsp; Either way one my direct reports figured it out and it had to do with PBR and ISP failover.&amp;nbsp; Once he added the VPN-S2S zone and the remote CIDR to that policy traffic started to flow.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 15:37:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-up-but-traffic-not-matching-outbound-policy-inbound-policy/m-p/339626#M85281</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2020-07-20T15:37:58Z</dc:date>
    </item>
  </channel>
</rss>

