<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tunnel Monitoring Setup issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/429631#M94925</link>
    <description>&lt;P&gt;Hey, you need to configure IP address on your tunnel interface which will act as a source while pinging destination server. Now you can take any free IP from your LAN side to configure IP address on tunnel interface.&lt;/P&gt;&lt;P&gt;NOTE- As you are doing source NAT while sending traffic over tunnel, make sure traffic going from tunnel interface IP should also NATed to desired IP in order to work it.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Aug 2021 06:11:05 GMT</pubDate>
    <dc:creator>SutareMayur</dc:creator>
    <dc:date>2021-08-27T06:11:05Z</dc:date>
    <item>
      <title>Tunnel Monitoring Setup issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/429616#M94922</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to enable Tunnel Monitoring for S2S VPN between PA and Cisco ISR Router.&lt;/P&gt;&lt;P&gt;Since, we need to hide our local network behind one IP address given by client (172.x.x.x/32) so we have used that IP address as loopback interface.&lt;/P&gt;&lt;P&gt;There are 2 Tunnels to reach client's remote network and we are using Static route (Primary tunnel with Metric 9 and Secondary Tunnel with metric 10) for this.&lt;/P&gt;&lt;P&gt;Tunnel.1 and Tunnel.2 are configured with VR-&amp;gt;Default and Security Zone-&amp;gt;VPN without any IP address.&lt;/P&gt;&lt;P&gt;Proxy ID is configured with local address using the masked IP address (172.x.x.x/32) and customer LAN IP as remote address.&lt;/P&gt;&lt;P&gt;NAT is in place using SNAT like below.&lt;/P&gt;&lt;P&gt;Original Packet:&lt;/P&gt;&lt;P&gt;Source Zone-&amp;gt;Trust, Destination Zone-&amp;gt;VPN, Source Address-&amp;gt;our local network, Destination Address-&amp;gt;Customer LAN IP/remote address.&lt;/P&gt;&lt;P&gt;Translated Packet:&lt;/P&gt;&lt;P&gt;Translation Type: DIPP, Interface Address-&amp;gt;Loopback Interface, IP Address-&amp;gt;172.x.x.x/32&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure what IP address to use as Destination IP in Tunnel monitoring. I understand that this IP will be the one that PAN will ping to verify that tunnel is up. I tried using remote proxyID (customer LAN IP), loopback IP, our local network IP but this causes ping dropouts/request timed out. I tried enabling Tunnel Monitoring in both the Tunnels as well as only one of them (Primary/Secondary).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help/suggestion please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 04:12:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/429616#M94922</guid>
      <dc:creator>Connected123</dc:creator>
      <dc:date>2021-08-27T04:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel Monitoring Setup issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/429619#M94923</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/187164"&gt;@Connected123&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here you need to use destination end Server IP address to ping from your side while monitoring. If destination side IP is not responding, you need to verify if destination side has allowed ping traffic via tunnel and/or destination server itself responds to ping.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 04:16:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/429619#M94923</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-08-27T04:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel Monitoring Setup issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/429626#M94924</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes ping is allowed from Destination side as continuous ping from our local network to client Server IP is successful.&lt;/P&gt;&lt;P&gt;I tried using this Server IP in Tunnel monitoring but got this error message below.&lt;/P&gt;&lt;P&gt;This is simply because there is no IP address configured for the tunnel.1 and tunnel.2 Interfaces.&lt;/P&gt;&lt;P&gt;Only Loopback Interface has IP address as stated in my original post.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Error.PNG" style="width: 595px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35905i19CBB28D4C4C2A19/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Error.PNG" alt="Error.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I am not sure what other IP I can use in tunnel monitoring. Any idea?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 05:11:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/429626#M94924</guid>
      <dc:creator>Connected123</dc:creator>
      <dc:date>2021-08-27T05:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel Monitoring Setup issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/429631#M94925</link>
      <description>&lt;P&gt;Hey, you need to configure IP address on your tunnel interface which will act as a source while pinging destination server. Now you can take any free IP from your LAN side to configure IP address on tunnel interface.&lt;/P&gt;&lt;P&gt;NOTE- As you are doing source NAT while sending traffic over tunnel, make sure traffic going from tunnel interface IP should also NATed to desired IP in order to work it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 06:11:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/429631#M94925</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-08-27T06:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel Monitoring Setup issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/429636#M94926</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your suggestion.&lt;/P&gt;&lt;P&gt;I have given dummy IPs to the two tunnel interfaces from our Local IPs (10.x.x.x/24) and made sure they are not referenced anywhere in the network.&lt;/P&gt;&lt;P&gt;Also, created NAT rule below as you mentioned. This has resulted in intermittent Ping request timed out and Tunnel Interface Status of one of the tunnels go down/red.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NATrule.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35906i48BB4579B7C0B6FC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NATrule.jpg" alt="NATrule.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 06:50:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/429636#M94926</guid>
      <dc:creator>Connected123</dc:creator>
      <dc:date>2021-08-27T06:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel Monitoring Setup issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/429742#M94937</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Make sure you have routing configured in your virtual router for the traffic to send down the VPN tunnel. i.e. 'Dest Server IP' interface would be the tunnel and next hop none:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1630084484460.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35918i53527CB08A869C93/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1630084484460.png" alt="OtakarKlier_0-1630084484460.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also make sure there are security policies to allow the traffic.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 17:15:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/429742#M94937</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-08-27T17:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel Monitoring Setup issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/429817#M94946</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;Yes both (VR Static route and Policy) are in place as you have mentioned. That is why ping is working but issue is as soon as Tunnel monitoring is enabled (configured as per the previous discussions here) ping drops out intermittently and Tunnel Interface status becomes Red.&lt;/P&gt;&lt;P&gt;Please help!&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 22:35:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/429817#M94946</guid>
      <dc:creator>Connected123</dc:creator>
      <dc:date>2021-08-27T22:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel Monitoring Setup issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/430973#M95052</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I realized that IP addresses need to be added to the Tunnel Interfaces at both ends. Adding dummy IPs only to PA tunnel interfaces do not help with Tunnel monitoring. However, the issue is client end will NOT assign any IP address to the tunnel interfaces of their Cisco router.&lt;/P&gt;&lt;P&gt;In that case, I only have PBF option left to be configured. Is this right?&lt;/P&gt;&lt;P&gt;I tried Path Monitoring but even that requires to create a static route for each tunnel, with a next-hop of the other end of the tunnel subnet. The only accessible addresses via the VPN are 146.x.x.x/24. And this range is not assigned to any addresses on their router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 05:28:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/430973#M95052</guid>
      <dc:creator>Connected123</dc:creator>
      <dc:date>2021-09-02T05:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel Monitoring Setup issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/431094#M95060</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/187164"&gt;@Connected123&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don’t think if tunnel interface IP should have at both ends. If you’re trying to initiate tunnel monitoring using any of the possibilities like &lt;EM&gt;tunnel monitoring profile&lt;/EM&gt; &lt;STRONG&gt;or&lt;/STRONG&gt; &lt;EM&gt;path monitoring on static route,&lt;/EM&gt; you can setup it by configuring IP address on your side tunnel interface. And you need to setup monitoring where Palo Alto will check reachability to the destination end server. During this, your side Palo Alto will use tunnel interface IP as source while monitoring destination server’s reachability.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;NOTE- In case you need monitoring from both ends to each other, In that case you would need IP address on both sides tunnel interfaces. Also if you are looking to monitor tunnel interface IP configured on peer end, in that case also you would need IP on tunnel interface at peer side. I guess above said scenario (in first para) should work for you because not necessarily every peer end will be always acting a route based VPN, it can be Policy based as well depending on the peer end vendor. Palo Alto always act as Route Based VPN.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 13:44:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/431094#M95060</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-09-02T13:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel Monitoring Setup issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/431282#M95071</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much for your response.&lt;/P&gt;&lt;P&gt;Yes you are right, I don't need monitoring from both ends to each other.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I did now is removed the loopback interface as previously configured and added the natt'ed IP address to tunnel.1.&lt;/P&gt;&lt;P&gt;I then selected a random IP address from the NATTed IP range (even though we are given only 172.x.x.x/32) and assigned it to tunnel.2.&lt;/P&gt;&lt;P&gt;I have only enabled Tunnel Monitor on tunnel.1 for the primary tunnel and can see monitor pkts sent increasing.&lt;/P&gt;&lt;P&gt;&amp;gt; show vpn flow tunnel-id 1 | match monitor&lt;BR /&gt;monitor: on&lt;BR /&gt;monitor status: up&lt;BR /&gt;monitor dest: 1.x.x.x&lt;BR /&gt;monitor interval: 3 seconds&lt;BR /&gt;monitor threshold: 5 probe losses&lt;BR /&gt;monitor bitmap: 11111&lt;BR /&gt;monitor packets sent: 23411&lt;BR /&gt;monitor packets recv: 23365&lt;BR /&gt;monitor packets seen: 0&lt;BR /&gt;monitor packets reply:0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do I enable tunnel monitoring for tunnel.2 (secondary tunnel) as well?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 02:50:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/431282#M95071</guid>
      <dc:creator>Connected123</dc:creator>
      <dc:date>2021-09-03T02:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel Monitoring Setup issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/431927#M95151</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/187164"&gt;@Connected123&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having monitoring enabled on the Primary interface only should fulfilled your use case. This is because secondary tunnel routes will always have higher metric and so will be in standby state. Now once Primary tunnel monitoring fails, in that case only traffic will use secondary tunnel. Also it will again failback to Primary once Primary tunnel monitoring is restored. So as per my understanding, having monitoring enabled on primary tunnel should be enough.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Sep 2021 05:49:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/431927#M95151</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-09-06T05:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel Monitoring Setup issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/431940#M95155</link>
      <description>&lt;P&gt;Thank you so much&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;for all your responses.&lt;/P&gt;&lt;P&gt;You helped me a lot from the beginning to the end of S2S setup.&lt;/P&gt;&lt;P&gt;Really appreciate for taking your time out and answering my questions.&lt;/P&gt;&lt;P&gt;Closing off this thread now.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Sep 2021 07:15:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitoring-setup-issue/m-p/431940#M95155</guid>
      <dc:creator>Connected123</dc:creator>
      <dc:date>2021-09-06T07:15:17Z</dc:date>
    </item>
  </channel>
</rss>

