Ping Failed (aged out)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Ping Failed (aged out)

L0 Member

Hello friends,

 

I configured site-to-site vpn between two firewalls and the ping from network behind firewall (internal network) to other internal network is failed (timeout) while the traffic shows allowed in the firewall logs. The Tunnel is Up and Green status. The configuration is the same on both firewalls and straightforward.

Policy allows all applications

No NAT

Static route between both sites and Peers are pingable

Static route for the internal networks using the Tunnel interface

The Tunnel interface does not have ip address

Dedicate Zone for the S2SVPN

 

I'm not sure if this is a Routing or Policy issue, but current setting is allowing everything. Please advise if you have seen this scenario before. 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

did you also set a route for the remote network to egress into the tunnel interface on both sides:

 

reaper_0-1714467041615.png

 

are you seein gthe ping arrive on the remote side? if you do, look at the session details if the next hop interface is the correct one etc

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

did you also set a route for the remote network to egress into the tunnel interface on both sides:

 

reaper_0-1714467041615.png

 

are you seein gthe ping arrive on the remote side? if you do, look at the session details if the next hop interface is the correct one etc

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L0 Member

@reaper  Thank you for your response. There was a network issue and firewall configuration was fine. 

  • 1 accepted solution
  • 432 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!