I cant figure it out why tunnel interface cant ping each other even site to site VPN is up and running fine. Is there anything I am missing here?? I have setup multiple site to site VPN with all other vendor and its just works fine. This is to Palo to Palo.
i did test vpn ike-sa and ipsec-sa multiple time but still no luck
Thanks in advance.
Also check the VPN flow on both sides when you do a ping to check the encap/decap counters. This will help you find out which peer to focus on.
Also setup a packet-filter and use the command "show counter global filter packet-filter yes delta yes" do this command multiple times and look for drops.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!