<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC VPN - Cannot ping across the tunnel. Both Ph1 and Ph2 tunnels are in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-cannot-ping-across-the-tunnel-both-ph1-and-ph2-tunnels/m-p/355958#M87597</link>
    <description>&lt;P&gt;Hi BPry - Yes I have static routing configured as well as management profile assigned on our side. I am not sure what Vendor side is configured with but they are saying it looks all good on their side.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Oct 2020 01:32:05 GMT</pubDate>
    <dc:creator>Rutvij</dc:creator>
    <dc:date>2020-10-13T01:32:05Z</dc:date>
    <item>
      <title>IPSEC VPN - Cannot ping across the tunnel. Both Ph1 and Ph2 tunnels are up.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-cannot-ping-across-the-tunnel-both-ph1-and-ph2-tunnels/m-p/355922#M87589</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have set up an IPSec VPN tunnel which seem to be up, however, i cannot ping from my local LAN IP on tunnel interface to the other side LAN interface of the tunnel. NOTE - Other end of the tunnel is terminated on ISP network where we are using their MPLS network to connect our global sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My side palo alto firewall has tunnel.11 interface with 10.10.8.17/30 ip address and the other end at ISP has been configured with 10.10.8.18/30&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;rutvijb@pa-fw(active)&amp;gt; ping source 10.10.8.17 count 5 host 10.10.8.18&lt;BR /&gt;PING 10.10.8.18 (10.10.8.18) from 10.10.8.17 : 56(84) bytes of data.&lt;/P&gt;&lt;P&gt;--- 10.10.8.18 ping statistics ---&lt;BR /&gt;5 packets transmitted, 0 received, 100% packet loss, time 4010ms&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 23:10:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-cannot-ping-across-the-tunnel-both-ph1-and-ph2-tunnels/m-p/355922#M87589</guid>
      <dc:creator>Rutvij</dc:creator>
      <dc:date>2020-10-12T23:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN - Cannot ping across the tunnel. Both Ph1 and Ph2 tunnels are</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-cannot-ping-across-the-tunnel-both-ph1-and-ph2-tunnels/m-p/355952#M87592</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149722"&gt;@Rutvij&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Do you have a route configured for the traffic? Do you have an interface management profile assigned to the interface on each device that actually allows ICMP/Ping?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 00:26:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-cannot-ping-across-the-tunnel-both-ph1-and-ph2-tunnels/m-p/355952#M87592</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-10-13T00:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN - Cannot ping across the tunnel. Both Ph1 and Ph2 tunnels are</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-cannot-ping-across-the-tunnel-both-ph1-and-ph2-tunnels/m-p/355958#M87597</link>
      <description>&lt;P&gt;Hi BPry - Yes I have static routing configured as well as management profile assigned on our side. I am not sure what Vendor side is configured with but they are saying it looks all good on their side.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 01:32:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-cannot-ping-across-the-tunnel-both-ph1-and-ph2-tunnels/m-p/355958#M87597</guid>
      <dc:creator>Rutvij</dc:creator>
      <dc:date>2020-10-13T01:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN - Cannot ping across the tunnel. Both Ph1 and Ph2 tunnels are</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-cannot-ping-across-the-tunnel-both-ph1-and-ph2-tunnels/m-p/355959#M87598</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149722"&gt;@Rutvij&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;So I hate to blame it on the other side, but this configuration is relatively straight forward. Configure the IP address on the tunnel interface, configure the routing, verify that the security rulebase is properly permitting the traffic, and lastly verify that the tunnel interface accepts ping from the IP address that you are testing from.&lt;/P&gt;
&lt;P&gt;I would just verify with the folks running the other device that they've actually verified the security rulebase on their end is allowing the traffic, that the interface-management-profile actually allows ping, and that they haven't configured permitted IPs on that interface-management-profile.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As long as that all looks good on both sides, this really should "just work" from a configuration standpoint.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 02:07:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-cannot-ping-across-the-tunnel-both-ph1-and-ph2-tunnels/m-p/355959#M87598</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-10-13T02:07:02Z</dc:date>
    </item>
  </channel>
</rss>

