VPN Tunnel Monitoring between two Palo Alto devices

Reply
Highlighted
L0 Member

VPN Tunnel Monitoring between two Palo Alto devices

Hello,

 

From what I understand, when creating a tunnel monitor between two PA devices it's best to assign IP addresses on the same segment to the tunnel interface on each side.  The monitor is then setup with the remote destination on each side.

 

Example:

FW-A-Tunnel.1 (10.10.10.1/30)  <--->  FW-B-Tunnel.1 (10.10.10.2/30)

 

FW-A will monitor 10.10.10.2

FW-B will monitor 10.10.10.1

 

On the firewall this creates what appears to be a directly connected network on the tunnel interfaces, and no additional configuration or routing is required.  I have set it up this way and it works, but I just want to make sure I'm understanding it correctly, and doing it properly.  There isn't much documentation on the IP configuration, but it seems like an arbitrary private address on the same network on both sides is the solution.

 

Thanks. 

Highlighted
Cyber Elite

Hello,

Sounds like you have it correct :).

 

Cheers!

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!