Hello, We were also running into same issue, with NO tunnel monitors. Every 3 seconds or 5 seconds our SPI will change, or reset to different; indicating that new 'interesting traffic' has been selected. It was very weird behavior, certain hosts could ping fine but others wouldn't, tunnel kept resetting every 3-5 seconds. The remote end/peer was Fortinet firewall. Turns out, our peer was doing 'strict phase 2 IP selection' in Route-Based Tunnel. In other words, in palo alto, even in route-based tunnel, we had to define proxy ID, and everything started to come normal!!!!!
... View more