IPsec VPN tunnel cant ping eachother

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

IPsec VPN tunnel cant ping eachother

L2 Linker

Hi there,

 

I cant figure it out why tunnel interface cant ping each other even site to site VPN is up and running fine. Is there anything I am missing here?? I have setup multiple site to site VPN with all other vendor and its just works fine. This is to Palo to Palo.

i did test vpn ike-sa and ipsec-sa multiple time but still no luck

 

Thanks in advance.

Pratik

4 REPLIES 4

Cyber Elite
Cyber Elite

@pkathiria,

Just something to verify quick, do you actually have a managmenet profile assigned to the tunnel interface that allows ping? 

L4 Transporter

Also check the VPN flow on both sides when you do a ping to check the encap/decap counters. This will help you find out which peer to focus on.

 

Also setup a packet-filter and use the command "show counter global filter packet-filter yes delta yes" do this command multiple times and look for drops. 

 
Hope the above helps. 
 
Thanks

@mrajdevwe found the issue. The packet is no decapping on other side but we don't know how to fix that also Support team is also working on it. we tried every possibility but no luck. have you ever experience this issue before?? do you know the fix for this ??

 

Thanks in advance.

 

Spoiler
Hello @pkathiria ,

Do you have resolution to this. I have similar issue. BUT through IPSEC I can ping printers and some servers. I cannot ping workstations.

I know this little old but any help will be highly appreciated.
  • 6928 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!