IPSEC s2s VPN between VM-50 and PA-3220

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

IPSEC s2s VPN between VM-50 and PA-3220

L2 Linker

We've done plenty of s2s IPSEC VPN tunnels between our DC firewalls and branch offices. I have a new branch office which we are configuring the same way as the others, yet the IPSEC VPN is not operating as expected. The tunnel is showing as up and the IKE Phase 1 & 2 are successful. However, on both firewalls, when I go into Tunnel Info all I'm showing is packets & bytes being encapsulated with the number incrementing but the decap column stays at 0.

 

Has anyone experienced this issue and what have you done to resolve? I've confirmed my configuration looks good, I've rebooted the ESXi host, and rebooted the firewall.

3 REPLIES 3

L2 Linker

Hi Mate, 

you would need to check the filtered global counters.. Good article on same below 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClUyCAK

MTU, replay attack issue or possible environmental issue with the esxi host or networking i suspect. 

 

regards

Rob 

Thanks for that article. I did forget to mention that I tried enabled replay protection on both ends and also disabling replay protection on both ends with no success and still getting the  flow_tunnel_decap_err.

 

I have a case open with TAC on this and will probably wait for them to decrypt the IKE & ESP traffic.

L2 Linker

To add more info:

  • Outside interface is receiving DHCP from a CradlePoint on a Verizon cellular connection
  • ESXi version is 6.7
  • PAN OS version is 10.1.4
  • 1701 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!