Hi @mrclueless , Based on the log below, it appears that UDP traffic which maintains the ipsec tunnel is missing keepalives which is causing the tunnel to drop. (T8656) 04/01/20 13:56:18:441 Info ( 921): --Too many outstanding keepalive and no response from GP gateway, disconnect tunnel There could be an underlying network issue but you can use the following workaround to resolve the issue temporarily. If the issue needs further investigation, please open a support ticket with Palo Alto TAC. - Uncheck "Enable IPSEC" option so that GP connection uses SSL instead of IPSEC. Please remember that this will slow down the throughput of the GP connection. Please refer to the following document as well. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PPgZCAW
... View more