- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-31-2019 10:53 AM
Hi there,
I cant figure it out why tunnel interface cant ping each other even site to site VPN is up and running fine. Is there anything I am missing here?? I have setup multiple site to site VPN with all other vendor and its just works fine. This is to Palo to Palo.
i did test vpn ike-sa and ipsec-sa multiple time but still no luck
Thanks in advance.
Pratik
10-31-2019 02:44 PM
Just something to verify quick, do you actually have a managmenet profile assigned to the tunnel interface that allows ping?
10-31-2019 02:50 PM
Also check the VPN flow on both sides when you do a ping to check the encap/decap counters. This will help you find out which peer to focus on.
Also setup a packet-filter and use the command "show counter global filter packet-filter yes delta yes" do this command multiple times and look for drops.
11-01-2019 11:29 AM
@mrajdevwe found the issue. The packet is no decapping on other side but we don't know how to fix that also Support team is also working on it. we tried every possibility but no luck. have you ever experience this issue before?? do you know the fix for this ??
Thanks in advance.
03-19-2020 12:57 AM
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!