Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site2Site ipsec stablished between UTM 9 and Palo Alto firewall, I can't ping nor access remote hosts

Hi guys!

I have configured a site 2 site IPSec VPN with a partner, the tunnel is established and the tunnel status shows all green.

Now I am trying to ping some of the remote hosts and I get no reply.

I added the log traffic for the auto created firewall rules and I can see the ICMP request in the real-time log as allowed

I wonder what would be another way to troubleshoot and see if the packages are leaving my firewall?

Another interesting thing, my internal interface is 10.0.0.0 /8 and my internal hosts are in the same ip pool and subnet, in order to establish the tunnel, palo alto had to setup the hosts internal and remote hosts as  /32

Not sure if that could be a problem or not.

Anyways, I just want to find a way to see the traffic leaving my UTM , I know that the firewall rules are not blocking it.

any advise in how to troubleshoot further is welcome.

Thanks

Gaston



This thread was automatically locked due to age.
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?