- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-15-2024 04:44 AM
Hi,
I have created a site to site tunnel, both devices are Paloalto firewall; One Firewall is PA 820 and another one is PA 410
All the configuration is okay but tunnel is down.
We are ping public IP of PA 410 from PA 820, But Not able to ping public IP of PA 820 from PA 410 as ICMP is blocked for PA 820 Public IP.
Please suggest any solution.
05-15-2024 05:33 AM
Does "test vpn ipsec-sa tunnel <name>" from firewall cli bring up the tunnel?
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC
05-15-2024 05:40 AM
Already tried this command but still tunnel down.
05-15-2024 05:50 AM
Logs on initiator side show only if it times out.
You need to check logs on destination side as only destination shows details if there is config mismatch.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!