IPsec VPN tunnel cant ping eachother

Reply
Highlighted
L2 Linker

IPsec VPN tunnel cant ping eachother

Hi there,

 

I cant figure it out why tunnel interface cant ping each other even site to site VPN is up and running fine. Is there anything I am missing here?? I have setup multiple site to site VPN with all other vendor and its just works fine. This is to Palo to Palo.

i did test vpn ike-sa and ipsec-sa multiple time but still no luck

 

Thanks in advance.

Pratik

Highlighted
Cyber Elite

Re: IPsec VPN tunnel cant ping eachother

@pkathiria,

Just something to verify quick, do you actually have a managmenet profile assigned to the tunnel interface that allows ping? 

Highlighted
L4 Transporter

Re: IPsec VPN tunnel cant ping eachother

Also check the VPN flow on both sides when you do a ping to check the encap/decap counters. This will help you find out which peer to focus on.

 

Also setup a packet-filter and use the command "show counter global filter packet-filter yes delta yes" do this command multiple times and look for drops. 

 
Hope the above helps. 
 
Thanks
Highlighted
L2 Linker

Re: IPsec VPN tunnel cant ping eachother

@mrajdevwe found the issue. The packet is no decapping on other side but we don't know how to fix that also Support team is also working on it. we tried every possibility but no luck. have you ever experience this issue before?? do you know the fix for this ??

 

Thanks in advance.

 

Highlighted
L0 Member

Re: IPsec VPN tunnel cant ping eachother

Spoiler
Hello @pkathiria ,

Do you have resolution to this. I have similar issue. BUT through IPSEC I can ping printers and some servers. I cannot ping workstations.

I know this little old but any help will be highly appreciated.
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!