PBF Monitor with tunnel Interface

Showing results for 
Show  only  | Search instead for 
Did you mean: 

PBF Monitor with tunnel Interface

L0 Member


I want to use PBF with IPSEC tunnel to handle failover.

I have 2 tunnels with the same proxy id, so I need to route a network between one tunnel, and if this tunnel is down I need to automatically route to the second tunnel.

But how to use monitoring in the PBF rule with a tunnel interface?

I think I have to configure a IP on the tunnel interface, but in which network ?

Can you help?

Thank you,


L4 Transporter

Hello Martin,

You can the tunnel interface with any IP address as long as the IPSEC Peer is configured with the appropiate proxy ID/route.

For example, you can set the tunnel interface to - this would require the peer to have or configured as the remote(PaloAlto) proxy ID.

Also, when configuring a IP address to 'monitor' you will want to set a IP address in the peer's proxy ID so the traffic will get pushed through the tunnel.

- Stefan

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!