- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-17-2026 06:18 AM
issue:
1 server behind PA being accessed through 2 different tunnels
tunnel 1 = working
tunnel 2 = incoming traffic working, the return traffic is being grabbed by interzone-default = deny, and on the PA seen as a new session being initiated, for which there is ofc no security rule in place to allow
anyone with an idea why the return traffic on tunnel 2 isnt being matched correctly on the PA and sent back through the correct tunnel?
04-17-2026 06:03 PM
Hi @S.Dollerup ,
Does the 6-tuple key of the return traffic match the initial traffic? https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVECA0
The security-zone is the destination zone of the initial traffic.
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

