Issues with VPN to AWS

cancel
Showing results for 
Search instead for 
Did you mean: 

Issues with VPN to AWS

L4 Transporter

Hi

 

I appreciate this is an odd one but I have a little bit of an issue with my home setup, I have a pa-220 behind a sky router, the issue is that if I am coming from the inside network i.e mgmt interface that traverses the inside zone to make it out then I can ping anything I want, however if I am trying to source the ping from the external interface then it fails, this is causing the issue above where I cannot get a vpn up between me and aws as there is never a reply received.

 

Any help would be greatly appreciated.

PCCSA PCNSA PCNSE PCSAE
1 ACCEPTED SOLUTION

Accepted Solutions

Cyber Elite
Cyber Elite

Hello there

 

I have a PA220 and pings do work for me.  You would need to confirm you have a rule that allows ping FROM the outside interface as shown in my screenshot below:

 

SteveCantwell_0-1629822838306.png

 

You should look in your traffic logs and see your pings failing, due to hitting a rule.

If you do not see your traffic, then perhaps you are not logging your traffic on the Intrazone rule at the bottom of your configuration.

 

What other questions can we answer for you?

Help the community: Like helpful comments and mark solutions

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

Hello there

 

I have a PA220 and pings do work for me.  You would need to confirm you have a rule that allows ping FROM the outside interface as shown in my screenshot below:

 

SteveCantwell_0-1629822838306.png

 

You should look in your traffic logs and see your pings failing, due to hitting a rule.

If you do not see your traffic, then perhaps you are not logging your traffic on the Intrazone rule at the bottom of your configuration.

 

What other questions can we answer for you?

Help the community: Like helpful comments and mark solutions

L4 Transporter

Hi @SteveCantwell 

 

The problem, unfortunately seems to go much deeper than I feared, there is an issue where traffic originating from the external interface of the firewall cannot it seems make it to the Gateway, although traffic from the inside zone can, I am talking it through with TAC as well as the upstream provider as this did work previously.

 

Thank you for your reply though and you are, of course, right that I should check there for the logs and make sure the traffic is allowed.

PCCSA PCNSA PCNSE PCSAE
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!