IPSec VPN Tunnel Palo Alto Networks Firewall to Palo Alto Networks Firewall

LateNaite
LateNaite used Ask the Experts™
on
Does anyone know why the IPSec tunnel would show one way encapsulation? This is typically a routing issue but I checked the routing table and the remote network is there and it is send to the tunnel interface.

I am attaching the screenshot.

TIA,
LN
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Blue Street TechLast Knight
Distinguished Expert 2018

Commented:
Hi LateNaite,

I don't see any screenshots. How are you determining there is one-way encapsulation?

Are there ACLs preventing the traffic on one end? Verify you are allowing traffic on the side that is not passing it.

I would put a capture on the receiving device to ensure the packets are leaving that device. Then, check the destination to ensure the packets are arriving at the destination. If so, I would check to ensure the packets are then leaving that destination. If they are, I would check that the packets are arriving back at your router.

We need to find out what is going on with the data; why its not coming back. Obviously, check your error logs for the tunnel being brought down for a specified reason.

On another related point, dial in your MTUs if you haven't already. Here is an easy guide: https://www.experts-exchange.com/articles/12615/Unstable-Slow-Performing-Networks-or-VPNs-just-go-grocery-shopping.html

let me know how it goes!
CEO and Founder
Commented:
The issue is resolved as there as a policy based forwarding configuration that matched source/destination traffic, which caused traffic to not work.
LateNaiteCEO and Founder

Author

Commented:
Resolved the issue.
Blue Street TechLast Knight
Distinguished Expert 2018

Commented:
Next time try providing some feedback... it's better for you since you are the one asking the questions! ;)

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial