I am facing a strange issue with IPSec tunnels built on Palo Alto firewalls.
1. On both ends we have Palo Alto firewalls(various models PA-220, PA440, PA-3220, PA-VM(AWS))
2. Public IP addresses of both ends are always reachable.
3. Tunnel lights always look GREEN.
4. Routing also is in place, either with Static or OSPF routes.
Once tunnel is brought up with 'test vpn' command on CLI, connectivity gets established. However, after few minutes(5 to 10), connectivity automatically breaks and tunnel lights on firewalls on both ends are GREEN.
- With various PAN-OS 10.x.x, no help.
- With various hardware and VM, no help.
- By changing routing protocols, no help.
- With and without assigning IP address to tunnel interfaces, but no help.
Please let me know if you have seen this issue or any guidance would be helpful.
... View more