Issues with VPN to AWS

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Issues with VPN to AWS

L4 Transporter

Hi

 

I appreciate this is an odd one but I have a little bit of an issue with my home setup, I have a pa-220 behind a sky router, the issue is that if I am coming from the inside network i.e mgmt interface that traverses the inside zone to make it out then I can ping anything I want, however if I am trying to source the ping from the external interface then it fails, this is causing the issue above where I cannot get a vpn up between me and aws as there is never a reply received.

 

Any help would be greatly appreciated.

PCCSA PCNSA PCNSE PCSAE
Mode44 LTD Palo Alto Consultants
1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hello there

 

I have a PA220 and pings do work for me.  You would need to confirm you have a rule that allows ping FROM the outside interface as shown in my screenshot below:

 

SteveCantwell_0-1629822838306.png

 

You should look in your traffic logs and see your pings failing, due to hitting a rule.

If you do not see your traffic, then perhaps you are not logging your traffic on the Intrazone rule at the bottom of your configuration.

 

What other questions can we answer for you?

Please help out other users and “Accept as Solution” if a post helps solve your problem !

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

Hello there

 

I have a PA220 and pings do work for me.  You would need to confirm you have a rule that allows ping FROM the outside interface as shown in my screenshot below:

 

SteveCantwell_0-1629822838306.png

 

You should look in your traffic logs and see your pings failing, due to hitting a rule.

If you do not see your traffic, then perhaps you are not logging your traffic on the Intrazone rule at the bottom of your configuration.

 

What other questions can we answer for you?

Please help out other users and “Accept as Solution” if a post helps solve your problem !

L4 Transporter

Hi @S.Cantwell 

 

The problem, unfortunately seems to go much deeper than I feared, there is an issue where traffic originating from the external interface of the firewall cannot it seems make it to the Gateway, although traffic from the inside zone can, I am talking it through with TAC as well as the upstream provider as this did work previously.

 

Thank you for your reply though and you are, of course, right that I should check there for the logs and make sure the traffic is allowed.

PCCSA PCNSA PCNSE PCSAE
Mode44 LTD Palo Alto Consultants
  • 1 accepted solution
  • 2602 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!