Unable to establish tunnel during Service Connection configuration (Details Added with Screenshot)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Unable to establish tunnel during Service Connection configuration (Details Added with Screenshot)

L0 Member

Dear Community Expert Team,

 

This my first post in Community.

 

I really enjoy the Palo Alto Prisma Access SASE.

 

Find the below details:

 

Before I am going to production configuration I plan to test in my LAB environment for multiple of POC.

Requirement: Service Connection configuration

Setup:

  1. Palo Alto NGFW hosted in GCP (Google Cloud Platform)
  2. Strata Cloud Manager (Prisma Access)
  3. The internet facing interface is private IP address (10.233.2.x) and that IP address NAT on the GCP.

LAB IP Address Details:

Palo Alto FW (Hosted in GCP) interface details:

Ethernet1/1 : 10.233.2.x/24

Ethernet1/2 : 10.235.2.6/24

Service Connection in Prisma Access Strata cloud manager Configuration details:

I

n General section:

Select - From Preferred Region

Prisma Access Location: India North PA-G

Data Traffic Source NAT: Not Enabled

Infrastructure Traffic Source NAT: Not Enabled

In Primary Tunnel:

Branch Device Type: Palo Alto Networks NGFW

 

NOTE: As by default when I select Palo Alto Networks NGFW then its automatically select the below Profile:

 

PaloAlto-Networks-IPSec-Crypto:

chinmayanaik_0-1768299362753.png

chinmayanaik_1-1768299362754.png

PaloAlto-Networks-IKE-Crypto

 

chinmayanaik_2-1768299362758.png

chinmayanaik_3-1768299362759.png

IKE Local Identification :  None

IKE Peer Identification: IP Address >> 35.246.250.xxx

KE Passive Mode: Unchecked

Authentication: Pre-Shared Key

IKE Gateway: Branch Device Public IP Address >> Static IP >> 35.246.250.xxx

Proxy ID: Not configured

Turn on Tunnel Monitoring: Unchecked

In Routing Section:

Static Routing >> 10.35.2.0/24 (This is the Palo Alto NGFW behind Network which going to my private resources for mobile users)

 

After configuration I get the Service FQDN and Service IP Address (130.41.114.xxx)

chinmayanaik_4-1768299362761.png

Now PUSH also done and getting below:

Config show : In Sync

chinmayanaik_5-1768299362767.png

Now in Palo Alto NGFW hosted in GCP:

 

IKE Crypto parameters is same as Prisma Access configured side.

IPSec crypto parameters also same as Prisma Access configured side.

Version: IKE v2 mode

In IKE Gateway >>  Local IP Address: Ethernet1/1 : 10.233.2.x

In IKE Gateway >>  Authentication: Pre-Shared Key

In IKE Gateway >> Local Identification:  35.246.250.xxx (Public IP address)

In IKE Gateway >> Peer Identification:  130.41.114.xxx (Prism Access Public IP address)

In IKE Gateway >> Advanced Options >> Enable NAT Traversal

 

chinmayanaik_6-1768299362774.png

Zone created as below :

 

chinmayanaik_7-1768299362783.png

Logical Router configure as below:

chinmayanaik_8-1768299362787.png

 

QUESTION-1:

I am unable to find the Destination IP address from Prisma Access Strata Cloud Manager.

chinmayanaik_9-1768299362793.png

QUESTION-2:

Below is the Tunnel Down Status in NGFW (Hosted in GCP):

chinmayanaik_10-1768299362800.png

QUESTION - 3:

Also, I am unable to find the Prisma Access Infrastructure Subnet.

 

Please guide me after review my configuration details and let me known if need any additional details to established IPSec Tunnel.

 

Thank You in Advanced

@chinmaya.naik 

 

0 REPLIES 0
  • 64 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!