<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Tunnel Monitoring between two Palo Alto devices in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-monitoring-between-two-palo-alto-devices/m-p/362883#M88299</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Sounds like you have it correct :).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;</description>
    <pubDate>Thu, 12 Nov 2020 22:35:39 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2020-11-12T22:35:39Z</dc:date>
    <item>
      <title>VPN Tunnel Monitoring between two Palo Alto devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-monitoring-between-two-palo-alto-devices/m-p/362746#M88297</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From what I understand, when creating a tunnel monitor between two PA devices it's best to assign IP addresses on the same segment to the tunnel interface on each side.&amp;nbsp; The monitor is then setup with the remote destination on each side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;FW-A-Tunnel.1 (10.10.10.1/30)&amp;nbsp; &amp;lt;---&amp;gt;&amp;nbsp; FW-B-Tunnel.1 (10.10.10.2/30)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW-A will monitor 10.10.10.2&lt;/P&gt;&lt;P&gt;FW-B will monitor 10.10.10.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the firewall this creates what appears to be a directly connected network on the tunnel interfaces, and no additional configuration or routing is required.&amp;nbsp; I have set it up this way and it works, but I just want to make sure I'm understanding it correctly, and doing it properly.&amp;nbsp; There isn't much documentation on the IP configuration, but it seems like an arbitrary private address on the same network on both sides is the solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 18:28:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-monitoring-between-two-palo-alto-devices/m-p/362746#M88297</guid>
      <dc:creator>NobleNOC</dc:creator>
      <dc:date>2020-11-12T18:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Tunnel Monitoring between two Palo Alto devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-monitoring-between-two-palo-alto-devices/m-p/362883#M88299</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Sounds like you have it correct :).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 22:35:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-monitoring-between-two-palo-alto-devices/m-p/362883#M88299</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-11-12T22:35:39Z</dc:date>
    </item>
  </channel>
</rss>

