Tunnel interface show "Red"

Announcements

Changes to the LIVEcommunity experience are coming soon... Here's what you need to know.

Reply
Joshan_Lakhani
L4 Transporter

Tunnel interface show "Red"

Hi,

As iam facing the issue with  Passive firewall as interface status show "Red"

 

Moreover Tunnel monitoring is already disable still it's show red. As on the active firewall the it's show green,

Can you please advise.

Joshan_Lakhani_0-1616928688768.png

 

NikolayDimitrov
L4 Transporter

You have a real impact and this is not a cosmetic issue(you may check the CLI to see if the tunnel is really down).Have you checked the system logs in the GUI for this tunnel? When investigate the VPN issue by macking the firewall a responder is there something interesting in the System logs?

 

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMZCA0

 

 

 

Also check this:

 

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC

Joshan_Lakhani
L4 Transporter

@NikolayDimitrov 

 

Hi this issue is with passive firewall on active firewall tunnel interface is working fine. Furthermore, i have check on passive firewall phase2 is up and phase 1 is down and it's expected behavior but my question is why interface status shows red infect tunnel monitoring is already disable.

 

Please advise.

Joshan_Lakhani_0-1616935804399.png

 

NikolayDimitrov
L4 Transporter

Is the physical interface related to the tunnel down from the network tab? As the passive firewall could be in shutdown mode?

 

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcACAS

Joshan_Lakhani
L4 Transporter

@NikolayDimitrov 

 

It's virtual interface. For physical interface is where it's shutdown or auto mode is not impacts on IPSec interface.

As all the other IPsec tunnel interface status shows green but only one tunnel is having the issue,

 

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!