S2S between PA3250 and Azure VPN Gateway -1 way traffic

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

S2S between PA3250 and Azure VPN Gateway -1 way traffic

L2 Linker

HI everyone, for a long time we have had a functioning VPN gateway between our on premise 3250 and and Azure VPN Gateway.

Recently, we have observed that appear to be unable to send traffic from the PA side, to Azure. Including return traffic.

 

Here's what I am observing.  The Tunnel is up.

When I send traffic from the Azure Side, I see it appearing on the on premise Palo. So for example a ping, I see it arrive in the traffic monitor, and pass between the correct zones to the destination as allowed traffic.  

However, the echo reply never gets back to Azure.

 

Conversely, if I send a ping from the PA, top the azure side, on the PA I see the traffic pass through the correct zones, and if I look at the egress traffic on the interface (QOS monitor) I see the ping sessions.  However we never get a reply.

All traffic both inbound and outbound reports as "aging out" on the PA.  I would expect the ping to age out on that anyway as per ICMP, but other types of traffic are also aging out. Such as RDP.

 

When I run a packet capture on destination machines on the azure side, I do not see any traffic originating from the PA side at all.

 

When I run a packet capture on the VPN Gateway, All i see is ESP traffic between both sides.

 

When I run the network monitor on the azure side to check im not blocking anything on the NSG, this verifies the matching rule, with an allow.

We are running 10.2.12-h6.

 

Any input from anyone who has seen a similar issue would be great!

 

Many thanks,

Graham.

 

 

 

1 REPLY 1

L2 Linker

Id just like to add, I have performed a packet capture on a machine inside the network, pinging from the azure side and I see the packets arrive on the machine itself.  I also see the echo reply go back out.  But it never arrives at the azure destination.

 

Thanks!

  • 269 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!