IPSEC site-to-site; passing ICMP only.. no other protocol (TCP/UDP)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

IPSEC site-to-site; passing ICMP only.. no other protocol (TCP/UDP)

L3 Networker

I have an IPSEC-to-SITE.

IKE Phase 1 and Phase 2 are good/live.

Tunnel interface in right zone.  Routes fines.

Policy defined (app: any, service: any).

I can see the policy being hit when I generate icmp/pings.  And can get to the proxy id's/subnets on other side.

I can't get anything other than ICMP through though.. No other TCP/UDP layer traffic.. no logs generated from the same policy (which should be evoked because of the source/destination condition match's that work for ICMP) that should get hit... very strange... ?

20 REPLIES 20

Can you please post the magnified traffic log output from the successful ping requests.

Untitled.png

How to you forward the traffic with a static route or PBF? Traceroute output

Static. default vr. to tunnel interface.

 

 

 

From the 192.168.75.15 host (near end) below.Untitled.png

 

 

So a little recap: you can ping the host on the other side but you are not able to transfer tcp traffic over the tunnel, right? And the paloalto firewall is on your own side where you start the ping/tcp sessions? And in addition you don't see any traffic logs for tcp traffic?

Did you try a flow basic to do a low level check whats happening on your side or if the traffic even arrives at your firewall?
https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Flow-Basic/ta-p/72556

... < embarassed > Intermediate firewall along the wire .. downstream .. before the PAN..

Tunnel and forwarding is fine.

But hey ! Great troubleshooting exercise we all went through.. 😕 Thanks everybody ❤️

  • 10738 Views
  • 20 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!