11-12-2020 10:26 AM - edited 11-12-2020 10:28 AM
From what I understand, when creating a tunnel monitor between two PA devices it's best to assign IP addresses on the same segment to the tunnel interface on each side. The monitor is then setup with the remote destination on each side.
FW-A-Tunnel.1 (10.10.10.1/30) <---> FW-B-Tunnel.1 (10.10.10.2/30)
FW-A will monitor 10.10.10.2
FW-B will monitor 10.10.10.1
On the firewall this creates what appears to be a directly connected network on the tunnel interfaces, and no additional configuration or routing is required. I have set it up this way and it works, but I just want to make sure I'm understanding it correctly, and doing it properly. There isn't much documentation on the IP configuration, but it seems like an arbitrary private address on the same network on both sides is the solution.
11-12-2020 02:35 PM
Sounds like you have it correct :).
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!