- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-12-2025 01:42 AM
HI everyone, for a long time we have had a functioning VPN gateway between our on premise 3250 and and Azure VPN Gateway.
Recently, we have observed that appear to be unable to send traffic from the PA side, to Azure. Including return traffic.
Here's what I am observing. The Tunnel is up.
When I send traffic from the Azure Side, I see it appearing on the on premise Palo. So for example a ping, I see it arrive in the traffic monitor, and pass between the correct zones to the destination as allowed traffic.
However, the echo reply never gets back to Azure.
Conversely, if I send a ping from the PA, top the azure side, on the PA I see the traffic pass through the correct zones, and if I look at the egress traffic on the interface (QOS monitor) I see the ping sessions. However we never get a reply.
All traffic both inbound and outbound reports as "aging out" on the PA. I would expect the ping to age out on that anyway as per ICMP, but other types of traffic are also aging out. Such as RDP.
When I run a packet capture on destination machines on the azure side, I do not see any traffic originating from the PA side at all.
When I run a packet capture on the VPN Gateway, All i see is ESP traffic between both sides.
When I run the network monitor on the azure side to check im not blocking anything on the NSG, this verifies the matching rule, with an allow.
We are running 10.2.12-h6.
Any input from anyone who has seen a similar issue would be great!
Many thanks,
Graham.
06-12-2025 02:47 AM
Id just like to add, I have performed a packet capture on a machine inside the network, pinging from the azure side and I see the packets arrive on the machine itself. I also see the echo reply go back out. But it never arrives at the azure destination.
Thanks!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!