Hello, From what I understand, when creating a tunnel monitor between two PA devices it's best to assign IP addresses on the same segment to the tunnel interface on each side. The monitor is then setup with the remote destination on each side. Example: FW-A-Tunnel.1 (10.10.10.1/30) <---> FW-B-Tunnel.1 (10.10.10.2/30) FW-A will monitor 10.10.10.2 FW-B will monitor 10.10.10.1 On the firewall this creates what appears to be a directly connected network on the tunnel interfaces, and no additional configuration or routing is required. I have set it up this way and it works, but I just want to make sure I'm understanding it correctly, and doing it properly. There isn't much documentation on the IP configuration, but it seems like an arbitrary private address on the same network on both sides is the solution. Thanks.
... View more