IPSEC tunnel is up but can not ping through

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

IPSEC tunnel is up but can not ping through

Cyber Elite
Cyber Elite

 

I have IPSEc ikev1 tunnel with vendor.

Phase 1 and 2 are up and green.

 

From PA   from my Lan interface when I ping remote lan subnet ping does not work.

I see no return traffic from vendor to PA.

 

IS this normal behaviour to have Phase 1 and 2 up but routing does nor work both way?

MP

Help the community: Like helpful comments and mark solutions.
1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

 phases 1 and 2 are simply the connection, routing is still needed on both ends before packets can pass through

 

have both sides set a static route to the remote network into the tunnel

does the remote end rely on ProxyIDs to properly route packets into the tunnel

have security policies been configured to allow both ends to communicate through the tunnel

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

 phases 1 and 2 are simply the connection, routing is still needed on both ends before packets can pass through

 

have both sides set a static route to the remote network into the tunnel

does the remote end rely on ProxyIDs to properly route packets into the tunnel

have security policies been configured to allow both ends to communicate through the tunnel

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Vendor Device interface - ping was disabled 

all good now.

MP

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 10675 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!