Hello Just check the Palo Alto Prisma documentation as it covers such cases: https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prepare-the-prisma-access-infrastructure/create-a-service-connection https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-for-networks/configure-prisma-access-for-networks %%%%%%%%%%%%%%%%%%% To enable tunnel monitoring for the service connection, select Tunnel Monitor . Enter a Destination IP address. Specify an IP address at your HQ or data center site to which Prisma Access can send ICMP ping requests for IPSec tunnel monitoring. Make sure that this address is reachable by ICMP from the entire Prisma Access infrastructure subnet. If you use tunnel monitoring with a peer device that uses multiple proxy IDs, specify a Proxy ID or add a New Proxy ID that allows access from the infrastructure subnet to your HQ or data center site. %%%%%%%%%%%%%%%%%%%%%%% %%%%%%%%%%%%%% You must configure a static route on your CPE to the Tunnel Monitor IP Address for tunnel monitoring to function. To find the destination IP address to use for tunnel monitoring from your data center or HQ network to Prisma Access, select Panorama Cloud Services Status Network Details , click the Service Infrastructure radio button, and find the Tunnel Monitor IP Address . %%%%%%%%%%%%%%%%%%%
... View more