he tunnel build process is documented here. https://www.paloaltonetworks.com/resources/reference-architectures/aws In general, if it works intermittently, check your timers in your IKE and IPSec profiles. Also, ensure that only the VPN ethernet interface has the "Automatically create default route pointing to DG provided by server". If you have multiple interfaces, you may end up with 2 default routes in the VR that are competing with each other. If you have EIPs on multiple interfaces, then you give each its own virtual router with a 0.0.0.0/0 route pointing outbound. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClQRCA0
... View more