IPSEC to Azure establish but cannot use traceroute

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

IPSEC to Azure establish but cannot use traceroute

L3 Networker

Hi All

 

We have PA 410 and has established an ipsec tunnel to Azure.
We testing from PA-410 to cloud that ping, SSH, and traceroute are working normally.
However, when testing from cloud to PA-410, ping and SSH work as expected, but traceroute does not function.


 A packet capture was performed and it was observed that the traffic UDP was dropped by the firewall. However, a security policy allowing the traffic has already been configured.

We dont use Zone protection profile and i saw the Azure cloud limitation for traceroute. 

 

any suggestion or advise?

 

thank you

4 REPLIES 4

Cyber Elite

Packet capture was taken on Palo and you see it being dropped?

Do you have IP configured on tunnel interface that is used for tunnel towards Azure?

Do you have interface mgmt profile attached to tunnel interface permitting ping?

Principal Architect @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Packet capture was taken on Palo and you see it being dropped?

Yes, UDP packet 

Fariq_Zaidi_0-1776131699745.png

 

 

Do you have IP configured on tunnel interface that is used for tunnel towards Azure? NO

Do you have interface mgmt profile attached to tunnel interface permitting ping? NO

Fariq_Zaidi_1-1776131734954.png

 

 

Cyber Elite

You need to have IP on Palo tunnel interface if you want to see every hop on the way in your traceroute.

Principal Architect @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Cyber Elite

Drops are expected.

If you add destination into packet capture filter and then run command "show counter global filter delta yes packet-filter yes" then you see packets dropped with reason "Packets dropped: IP TTL reaches zero"

Principal Architect @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 1026 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!