IPSec Tunnel is up but not passing traffic (On-Prem to Azure Palo Alto VM)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

IPSec Tunnel is up but not passing traffic (On-Prem to Azure Palo Alto VM)

L1 Bithead

CMoore927039_1-1743429050105.png

Hi guys.

GOAL:
I have an office in India with several users. They need to access a server in Azure that sits behind Virtual PA using Global Protect.


I have successfully setup an IPSec Tunnel between my On-prem PA and an Azure PA, however, I am not passing any traffic in either direction.
I suspect I might be over simplifying this deployment. I chose the "2-Arm" PA deployment in Azure. This gave me 3 Interfaces for which I had to define 3 subnets as shown in the image above.
This is a new concept for me. I am used to a single Internal subnet NAT'd out to a Public IP.

I feel like I am missing components for this deployment and that a "Single-Arm" Azure VM deployment is probably what I need.

 

 

Regardless, if anyone has some input they can provide, please let me know, I would greatly appreciate it.

 

Thanks!

 

 

 

 

 

 

2 REPLIES 2

L0 Member

Do you have any security policy in place to allow traffic from IPSEC tunnel to on-prem zone and vice versa?

L1 Bithead

As I am new to Palo Atlo's in Azure, it is important to note that the "outside" Interface is not assigned a Public IP address in the IKE Gateway settings as shown below. Since Azure associates a Public IP to your (non-routable) IP address, but routable in Azure if that makes sense, it it left blank. Typically you would have a Public IP assigned directly to your "outside" interface. After setting the interface to "None" as shown below, traffic started flowing.

CMoore927039_0-1744037770244.png

 

  • 301 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!