unable to reach peer end public IP via vpn tunnel

Reply
Highlighted
L3 Networker

unable to reach peer end public IP via vpn tunnel

HI Team

 

I have created S2S VPN tunnel between palo alto and cyberoam firewall.

 

Tunnel is up but the traffic is not flow.

 

Under Cyberoam firewall there is one server with public IP 144.21.X.X.

From palo alto we need to reach the peer end public IP 144.21.X.X via the vpn tunnel.

but whenever I tried to reach the peer end  public IP 144.21.X.X its going via the internet rule instead of vpn rule.

 

Our requirement is that traffic should go via the vpn tunnel to reach the IP 144.21.X.X

 

I have configured the PBF policy but its not work.. Please help on this 

 

Regards

Mohammed Asik

 

 

Highlighted
L5 Sessionator

Re: unable to reach peer end public IP via vpn tunnel

Hey,

 

This is expected.

Your PEER IP communication will happen over internet only. The proxy IDs configured will only pass through tunnel.

 

- Mayur



Mayur Sutare
Highlighted
L3 Networker

Re: unable to reach peer end public IP via vpn tunnel

HI Mayur

 

I have configured proxy ID s also. but its not working

 

regards
Mohammed Asik

Highlighted
L5 Sessionator

Re: unable to reach peer end public IP via vpn tunnel

Hi @MohammedAsik Check if routes are pointed towards proper tunnel interface. 

 

Verify traffic logs once if matching correct security policy and sending traffic to correct tunnel interface.

 

-Mayur



Mayur Sutare
Highlighted
L3 Networker

Re: unable to reach peer end public IP via vpn tunnel

Please find the below routing and security policy details

 

144.250.3.222/32   0.0.0.0   10   A S   tunnel.10

 

{
from inside;
source 172.31.62.0/24;
source-region none;
to vpn;
destination 144.250.3.222;
destination-region none;
user any;
category any;
application/service 0:any/any/any/any;
action allow;
icmp-unreachable: no
terminal yes;
}

 

Regards

Mohammed Asik

Highlighted
L5 Sessionator

Re: unable to reach peer end public IP via vpn tunnel

Hi @MohammedAsik What is 0.0.0.0 in the route? is it next hop?

 

What you found in traffic logs?? Is firewall passing it to same tunnel interface?

 

-Mayur



Mayur Sutare
Highlighted
L3 Networker

Re: unable to reach peer end public IP via vpn tunnel

Mayur

 

its a tunnel interface. thats why its showing next hop as 0.0.0.0.

 

In traffic logs its taking the internet rule and its not pass through tunnel interface. its passing through internet interface Ethernet 1/1.

 

Mohammed Asik

Highlighted
L5 Sessionator

Re: unable to reach peer end public IP via vpn tunnel

Can you please check once if tunnel interface belongs to VPN zone?

 

Mayur



Mayur Sutare
Highlighted
L3 Networker

Re: unable to reach peer end public IP via vpn tunnel

Please find the below ss  tunnel.10 interface 

 

MohammedAsik_0-1581089649123.png

 

Highlighted
L5 Sessionator

Re: unable to reach peer end public IP via vpn tunnel

Something is mis configured .  Check any pbf which is sending traffic on external interface or traffic getting NAT?

please share traffic log snap?

 

Mayur



Mayur Sutare
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!