<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site-to-Site VPN private subnets cannot ping eachother through the tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-private-subnets-cannot-ping-eachother-through/m-p/410952#M92672</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Also make sure your policies are set log log at session end. Make sure there are policies to allow the traffic to traverse the zones if you configured them.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Thu, 03 Jun 2021 16:51:55 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2021-06-03T16:51:55Z</dc:date>
    <item>
      <title>Site-to-Site VPN private subnets cannot ping eachother through the tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-private-subnets-cannot-ping-eachother-through/m-p/410859#M92656</link>
      <description>&lt;P&gt;I am new to learning Palo Alto Firewalls.&amp;nbsp; I have a couple of PA-8.0.0 virtual machine instances setup on my desktop with internet access through my home network on a Windows 10 host machine, for learning purposes.&amp;nbsp; I configured site-to-site vpn and can get the tunnel up, both phase1 and phase2.&amp;nbsp; The firewalls can ping eachother’s external IP addresses but their respective internal private hosts cannot ping eachother through the tunnel.&amp;nbsp; The configuration seems fine and nothing in the system logs indicate any drops or disconnection.&amp;nbsp; Am I missing a security policy or what else needs doing?&amp;nbsp; I have security policies configured on each firewall to allow traffic out to the external untrust zone.&amp;nbsp; Any assistance will be appreciated.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 12:47:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-private-subnets-cannot-ping-eachother-through/m-p/410859#M92656</guid>
      <dc:creator>Palobeacon</dc:creator>
      <dc:date>2021-06-03T12:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN private subnets cannot ping eachother through the tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-private-subnets-cannot-ping-eachother-through/m-p/410933#M92668</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/180339"&gt;@Palobeacon&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Did you setup static routes so that the firewall knows how to route the traffic through the IPSec tunnel? Do you have a security rulebase entry allowing traffic to actually process across the IPSec tunnel zone that you added?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you haven't already, override your interzone-default security entry to log denied traffic so you can see if it's a security entry that is missing or not.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 15:41:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-private-subnets-cannot-ping-eachother-through/m-p/410933#M92668</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-06-03T15:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN private subnets cannot ping eachother through the tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-private-subnets-cannot-ping-eachother-through/m-p/410952#M92672</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Also make sure your policies are set log log at session end. Make sure there are policies to allow the traffic to traverse the zones if you configured them.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 16:51:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-private-subnets-cannot-ping-eachother-through/m-p/410952#M92672</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-06-03T16:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN private subnets cannot ping eachother through the tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-private-subnets-cannot-ping-eachother-through/m-p/410988#M92676</link>
      <description>Thanks for your assistance. There's been some progress. I do have static routes setup for both firewalls. I also have security rules setup. I checked the settings based on your suggestions and adjusted the rule for outbound traffic from site 2. I also configured proxy-id for both firewalls just in case (it does say it is not needed if they are both PA firewalls).&lt;BR /&gt;&lt;BR /&gt;So now site 2 internal hosts can ping through the tunnel to site 1 internal hosts but for some reason, site 1 hosts cannot ping to site 2 host. The configurations are the same.&lt;BR /&gt;</description>
      <pubDate>Thu, 03 Jun 2021 18:54:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-private-subnets-cannot-ping-eachother-through/m-p/410988#M92676</guid>
      <dc:creator>Palobeacon</dc:creator>
      <dc:date>2021-06-03T18:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN private subnets cannot ping eachother through the tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-private-subnets-cannot-ping-eachother-through/m-p/410991#M92677</link>
      <description>I think site 2 firewall may be missing a security policy. The internal hosts are able to ping site 1 internal hosts. However, I have now noticed that site 2 internal hosts cannot reach the webserver in the DMZ zone of site 1 even though it is accessible by hosts from other locations. I do have a security policy on the site 1 firewall that allows access to the server from the outside.&lt;BR /&gt;&lt;BR /&gt;Thanks for your assistance.&lt;BR /&gt;</description>
      <pubDate>Thu, 03 Jun 2021 19:06:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-private-subnets-cannot-ping-eachother-through/m-p/410991#M92677</guid>
      <dc:creator>Palobeacon</dc:creator>
      <dc:date>2021-06-03T19:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN private subnets cannot ping eachother through the tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-private-subnets-cannot-ping-eachother-through/m-p/411465#M92735</link>
      <description>&lt;P&gt;Thanks all, for your assistance.&amp;nbsp; I adjusted the security policy to allow traffic to pass through the tunnel.&amp;nbsp; Both sites can communicate through the tunnel now.&amp;nbsp; Everything is working fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you all&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jun 2021 23:18:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-private-subnets-cannot-ping-eachother-through/m-p/411465#M92735</guid>
      <dc:creator>Palobeacon</dc:creator>
      <dc:date>2021-06-06T23:18:42Z</dc:date>
    </item>
  </channel>
</rss>

