Hi there,
I cant figure it out why tunnel interface cant ping each other even site to site VPN is up and running fine. Is there anything I am missing here?? I have setup multiple site to site VPN with all other vendor and its just works fine. This is to Palo to Palo.
i did test vpn ike-sa and ipsec-sa multiple time but still no luck
Thanks in advance.
Pratik
Just something to verify quick, do you actually have a managmenet profile assigned to the tunnel interface that allows ping?
Also check the VPN flow on both sides when you do a ping to check the encap/decap counters. This will help you find out which peer to focus on.
Also setup a packet-filter and use the command "show counter global filter packet-filter yes delta yes" do this command multiple times and look for drops.
@mrajdevwe found the issue. The packet is no decapping on other side but we don't know how to fix that also Support team is also working on it. we tried every possibility but no luck. have you ever experience this issue before?? do you know the fix for this ??
Thanks in advance.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!