Disable a tunneling interface ?

Reply
Highlighted
L1 Bithead

Disable a tunneling interface ?

Hi all,

Is there a CLI command to disable (shutdown) a tunnel interface on a PAN firewall ?

Thank you

Regards


Accepted Solutions
Highlighted
L3 Networker

Re: Disable a tunneling interface ?

there is currently no command to disable a tunnel interface.

View solution in original post


All Replies
Highlighted
L3 Networker

Re: Disable a tunneling interface ?

there is currently no command to disable a tunnel interface.

View solution in original post

Highlighted
Not applicable

Re: Disable a tunneling interface ?

Is there one now :smileyhappy:

If not, I have a work-around. Will post next as attachment.

Highlighted
L6 Presenter

Re: Disable a tunneling interface ?

WTF a cliffhanger? =)

Highlighted
Not applicable

Re: Disable a tunneling interface ?

Patience, Daniel-san...

Highlighted
L5 Sessionator

Re: Disable a tunneling interface ?

Curious why you want to shutdown a tunnel interface. This is a logical interface and not really tied to a physical interface as such. What are you trying to accomplish by shutting down tunnel interface?

Having said that, you can enable tunnel monitoring as that can basically disable the tunnel interface if the VPN is down to influence routing protocols. Is that what you are trying to do?

-Richard

Highlighted
Not applicable

Re: Disable a tunneling interface ?

Many reasons, but I'll give the two, which I'm using it for right now.  First, is a VPN between client(s) and myself.  I don't want to leave it up at all times, just bring it up when needed.  This will relieve routing conflicts between overlapping schemes among different clients and myself.  Second, we moved from an old VPN between a Cisco (remote device) on one side and PA on the other to a complete Palo Alto solution.  I want to avoid any chance of traffic routing over the old VPN and the only way to ensure this is to disable it, but PA doesn't allow an admin down state like Cisco does, BTW, why is that?  SOP to leave the old infra in place until the new is proven good and stable.  If a problem arises, simply fall back to the old VPN. 

Highlighted
Not applicable

Re: Disable a tunneling interface ?

::crickets::

Highlighted
L6 Presenter

Re: Disable a tunneling interface ?

I guess you would just bitchslap me if I returned your "Patience, Daniel-san..."? ;-)

Highlighted
Not applicable

Re: Disable a tunneling interface ?

LOL!  two-shay...  Then I would say, damn you guys are slow... ha

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!