Several subnetworks through the tunnel between Palo Alto and Mikrotik

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Several subnetworks through the tunnel between Palo Alto and Mikrotik

L1 Bithead

Site 2 site allows only two networks to be pulled inside the tunnel (one of them behind the mikrotik and the other one behind the palo alto).I’ve tried different settings and it doesn't help.
Has anyone had experience building a tunnel between them based on GRE tunnel over IPsec?
Several subnetworks need to be passed through the tunnel.


Cyber Elite
Cyber Elite

is GRE a requirement?


a regular IPSec tunnel will allow as many subnets as you need, adding GRE will create some limitations because of GRE

Tom Piens
PANgurus - SASE and Strata specialist; (co)managed services, VAR and consultancy

I have configured s2s between mikrotik and palo alto.
Local networks go between them. I need to add other networks through this tunnel.
On the Palo Alto, I added another network on the tunnel to the proxy id.
In mikrotik, the accept rule from the LAN(Firewall - NAT) to the network behind the tunnel.
But there is no ping.
Only two networks can be specified in the IPSEC settings.
It does not work to create another policy, as the keys begin to break.
Also, there is no separate interface on Mikrotik (like with GRE).
When adding routes, I indicate the local interface.


Do either of the firewall logs show where the pings are failing? It could be a policy rule that is preventing the traffic?



In monitoring (traffic) PA there are no records from the network (from source and dest)
ssh PA utility: ping source host (no response)Документ123.jpg

Mikrotik terminal: ping source (no response)
ip - firewall -connection (no response)

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!