Skip to main content
Palo Alto NetworksCustomer feedback

Users discuss a common and confusing issue with Palo Alto Networks' IPsec VPNs where the tunnel shows as 'UP' but fails to pass traffic, requiring extensive troubleshooting of routing, NAT...

What happened

Users discuss a common and confusing issue with Palo Alto Networks' IPsec VPNs where the tunnel shows as 'UP' but fails to pass traffic, requiring extensive troubleshooting of routing, NAT, security policies, and proxy IDs.

Source

RedditOct 3, 2026By u/samsh92

r/paloaltonetworks

Palo Alto IPsec VPN is UP but traffic isn't passing - how do you troubleshoot it?

upvotes
6
comments
19

Post

Highlighted: the lines this signal was extracted from

One of the more confusing Palo Alto VPN issues is when the IKE SA and IPsec SA are both UP, but traffic still doesn't pass. When troubleshooting a site-to-site IPsec VPN, I usually try to avoid changing multiple settings at once and instead work through the traffic path step by step: Is the VPN peer reachable? Is IKE Phase 1 established? Is IPsec Phase 2 established? Are the IKE/IPsec proposals matching? Are Proxy IDs or traffic selectors causing an issue? Is there a route to the remote subnet? Is the security policy matching the traffic? Is NAT accidentally being applied? Are VPN traffic counters increasing? What do the traffic logs show? If needed, where should packet capture be performed? One thing that is easy to overlook is that a tunnel being UP doesn't necessarily mean the application traffic will work. The VPN can be perfectly established while routing, security policy, NAT, or the return path is still wrong. I put together a practical troubleshooting guide covering these checks along with useful Palo Alto CLI commands such as: show vpn ike-sa show vpn ipsec-sa show vpn flow test vpn ike-sa gateway <gateway> test vpn ipsec-sa tunnel <tunnel> If anyone is troubleshooting Palo Alto IPsec VPNs, I'd be interested to hear what problem you encounter most often - Phase 1, Phase 2, routing, policy, NAT, or something else. For anyone who wants the full...

Keep reading with a free account

The rest of this post, and every signal for Palo Alto Networks, is in your free account.

Also quoted as evidence

  • [comment u/jtmajorx] It’s funny how many times I’ve ran into this issue and it ended up being NAT traversal not being enabled.

  • [comment u/Any-Promotion3744] for us, it is usually static routes or proxy id problems.

Comments on the post

5 of 19 comments
  • “Do you have a route for the traffic in question pointing to the tunnel interface? What do the traffic logs details show for action and egress interface?”

    u/CaptainCaraway12 points · Oct 3, 2026View

  • “It’s funny how many times I’ve ran into this issue and it ended up being NAT traversal not being enabled.”

    u/jtmajorx5 points · Oct 3, 2026View

  • “Do we have route ? If yes, are we seeing encap decap on tunnel ? If yes, is it for our traffic ? Do we have other traffic going in as well? If yes, what does traffic logs show for our interesting traffic? - bytes sent and received, egress and ingress What’s the peer - policy or route based ? If policy based, did we configure proxy IDs ? If yes, Did we configure them on both ends and what is the st”

    u/Impossible_Coyote2383 points · Oct 3, 2026View

  • “I have encountered where one side is showing as up, while the other is down. so the traffic gets sent to the tunnel int, but dies at that point. This can be if one side has either restarted (such as during PANOS updates) or someone disabled and enabled the tunnels on one side. The new P1 negotiation requests were getting ignored because the P2 was thinking it was still up. DPD is supposed to”

    u/alphaxion1 points · Oct 3, 2026View

  • “Bouncing it works wonders. Use the test vpn command”

    u/awwephuck1 points · Oct 3, 2026View

Extracted by Autobound

From the Signal API record
Signal
Customer feedback

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/paloaltonetworks

The full record

From the Signal API record

Numbers

Mentions
16

Details

Timing
Ongoing state
Category
Usability
Link URL
/r/FirewallFlow/comments/1wwiuvx/palo_alto_ipsec_vpn_is_up_but_traffic_isnt/
Virality
Medium
Post kind
Crosspost
Prominence
Core
Company's role
Vendor

Topics and mentions

Topics

  • troubleshooting
  • networking
  • security
  • usability
  • vpn

Flair

  • Informational

Products named

  • IPsec VPN
  • PAN-OS

Extraction

Sentiment
Negative
Detected
Oct 3, 2026
signal_type
reddit-company
signal_subtype
customerFeedback

Use this data

Get every Reddit signal for Palo Alto Networks and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Palo Alto Networks this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/1e713303-f5f2-5b46-a4ac-52c87a6f2b15 returns this record as JSON. POST /v1/companies/enrich returns every signal for paloaltonetworks.com.

{
  "signal_id": "1e713303-f5f2-5b46-a4ac-52c87a6f2b15",
  "signal_type": "reddit-company",
  "signal_subtype": "customerFeedback",
  "detected_at": "2026-10-03T09:20:23+00:00",
  "company": {
    "name": "Palo Alto Networks",
    "domain": "paloaltonetworks.com"
  },
  "data": {
    "nsfw": false,
    "stage": "none",
    "awards": 0,
    "timing": "ongoing_state",
    "topics": [
      "vpn",
      "troubleshooting",
      "networking",
      "security",
      "usability"
    ],
    "post_id": "1wwiv6e",
    "summary": "Users discuss a common and confusing issue with Palo Alto Networks' IPsec VPNs where the tunnel shows as 'UP' but fails to pass traffic, requiring extensive troubleshooting of routing, NAT, security policies, and proxy IDs.",
    "category": "usability",
    "comments": [
      {
        "url": "https://www.reddit.com/r/paloaltonetworks/comments/1wwiv6e/comment/pdkvm2a/",
        "depth": 0,
        "score": 12,
        "author": "CaptainCaraway",
        "excerpt": "Do you have a route for the traffic in question pointing to the tunnel interface? What do the traffic logs details show for action and egress interface?",
        "posted_at": "2026-10-03T09:24:05.000Z",
        "author_url": "https://www.reddit.com/user/CaptainCaraway/"
      },
      {
        "url": "https://www.reddit.com/r/paloaltonetworks/comments/1wwiv6e/comment/pdl53sh/",
        "depth": 0,
        "score": 5,
        "author": "jtmajorx",
        "excerpt": "It’s funny how many times I’ve ran into this issue and it ended up being NAT traversal not being enabled.",
        "posted_at": "2026-10-03T10:41:32.000Z",
        "author_url": "https://www.reddit.com/user/jtmajorx/"
      },
      {
        "url": "https://www.reddit.com/r/paloaltonetworks/comments/1wwiv6e/comment/pdmhz4c/",
        "depth": 0,
        "score": 3,
        "author": "Impossible_Coyote238",
        "excerpt": "Do we have route ?\nIf yes, are we seeing encap decap on tunnel ?\nIf yes, is it for our traffic ? Do we have other traffic going in as well?\nIf yes, what does traffic logs show for our interesting traffic? - bytes sent and received, egress and ingress\nWhat’s the peer - policy or route based ?\nIf policy based, did we configure proxy IDs ?\nIf yes, Did we configure them on both ends and what is the st",
        "posted_at": "2026-10-03T15:15:32.000Z",
        "author_url": "https://www.reddit.com/user/Impossible_Coyote238/"
      },
      {
        "url": "https://www.reddit.com/r/paloaltonetworks/comments/1wwiv6e/comment/pdlb665/",
        "depth": 0,
        "score": 1,
        "author": "alphaxion",
        "excerpt": "I have encountered where one side is showing as up, while the other is down.\n\n so the traffic gets sent to the tunnel int, but dies at that point.\n\n This can be if one side has either restarted (such as during PANOS updates) or someone disabled and enabled the tunnels on one side. The new P1 negotiation requests were getting ignored because the P2 was thinking it was still up.\n\n DPD is supposed to",
        "posted_at": "2026-10-03T11:25:52.000Z",
        "author_url": "https://www.reddit.com/user/alphaxion/"
      },
      {
        "url": "https://www.reddit.com/r/paloaltonetworks/comments/1wwiv6e/comment/pdlc297/",
        "depth": 0,
        "score": 1,
        "author": "awwephuck",
        "excerpt": "Bouncing it works wonders. Use the test vpn command",
        "posted_at": "2026-10-03T11:32:09.000Z",
        "author_url": "https://www.reddit.com/user/awwephuck/"
      },
      {
        "url": "https://www.reddit.com/r/paloaltonetworks/comments/1wwiv6e/comment/pdljjxy/",
        "depth": 0,
        "score": 1,
        "author": "Professional_Set_351",
        "excerpt": "Have you check your security policy and routing table?",
        "posted_at": "2026-10-03T12:20:30.000Z",
        "author_url": "https://www.reddit.com/user/Professional_Set_351/"
      },
      {
        "url": "https://www.reddit.com/r/paloaltonetworks/comments/1wwiv6e/comment/pdma43t/",
        "depth": 0,
        "score": 1,
        "author": "donut_ky_808",
        "excerpt": "if phase 2 is up….its routing. (in my experience)\nbgp could bring up phase2 but not established.\n\n i’m only talking about encrypts and decrypts, not traffic policy issues.",
        "posted_at": "2026-10-03T14:39:12.000Z",
        "author_url": "https://www.reddit.com/user/donut_ky_808/"
      },
      {
        "url": "https://www.reddit.com/r/paloaltonetworks/comments/1wwiv6e/comment/pdmgtr1/",
        "depth": 0,
        "score": 1,
        "author": "WalkFirm",
        "excerpt": "As I tell all my techs, follow the packet.",
        "posted_at": "2026-10-03T15:10:18.000Z",
        "author_url": "https://www.reddit.com/user/WalkFirm/"
      }
    ],
    "evidence": [
      "[post] One of the more confusing Palo Alto VPN issues is when the IKE SA and IPsec SA are both UP, but traffic still doesn't pass.",
      "[post] One thing that is easy to overlook is that a tunnel being UP doesn't necessarily mean the application traffic will work. The VPN can be perfectly established while routing, security policy, NAT, or the return path is still wrong.",
      "[comment u/jtmajorx] It’s funny how many times I’ve ran into this issue and it ended up being NAT traversal not being enabled.",
      "[comment u/Any-Promotion3744] for us, it is usually static routes or proxy id problems."
    ],
    "link_url": "/r/FirewallFlow/comments/1wwiuvx/palo_alto_ipsec_vpn_is_up_but_traffic_isnt/",
    "virality": "medium",
    "post_date": "2026-10-03T09:20:23.000Z",
    "post_kind": "crosspost",
    "post_text": "One of the more confusing Palo Alto VPN issues is when the IKE SA and IPsec SA are both UP, but traffic still doesn't pass.\n\nWhen troubleshooting a site-to-site IPsec VPN, I usually try to avoid changing multiple settings at once and instead work through the traffic path step by step:\n\nIs the VPN peer reachable?\n\nIs IKE Phase 1 established?\n\nIs IPsec Phase 2 established?\n\nAre the IKE/IPsec proposals matching?\n\nAre Proxy IDs or traffic selectors causing an issue?\n\nIs there a route to the remote subnet?\n\nIs the security policy matching the traffic?\n\nIs NAT accidentally being applied?\n\nAre VPN traffic counters increasing?\n\nWhat do the traffic logs show?\n\nIf needed, where should packet capture be performed?\n\nOne thing that is easy to overlook is that a tunnel being UP doesn't necessarily mean the application traffic will work. The VPN can be perfectly established while routing, security policy, NAT, or the return path is still wrong.\n\nI put together a practical troubleshooting guide covering these checks along with useful Palo Alto CLI commands such as:\nshow vpn ike-sa\nshow vpn ipsec-sa\nshow vpn flow\ntest vpn ike-sa gateway <gateway>\ntest vpn ipsec-sa tunnel <tunnel>\nIf anyone is troubleshooting Palo Alto IPsec VPNs, I'd be interested to hear what problem you encounter most often - Phase 1, Phase 2, routing, policy, NAT, or something else.\n\nFor anyone who wants the full...",
    "sentiment": "negative",
    "subreddit": "paloaltonetworks",
    "post_flair": [
      "Informational"
    ],
    "post_title": "Palo Alto IPsec VPN is UP but traffic isn't passing - how do you troubleshoot it?",
    "prominence": "core",
    "source_url": "https://www.reddit.com/r/paloaltonetworks/comments/1wwiv6e/palo_alto_ipsec_vpn_is_up_but_traffic_isnt/",
    "entity_role": "vendor",
    "post_author": "samsh92",
    "upvote_ratio": 0.8,
    "mention_count": 16,
    "mention_surge": true,
    "subreddit_url": "https://www.reddit.com/r/paloaltonetworks/",
    "total_upvotes": 6,
    "comments_total": 21,
    "total_comments": 19,
    "post_author_url": "https://www.reddit.com/user/samsh92/",
    "signal_category": "feedback",
    "comments_included": 14,
    "products_mentioned": [
      "IPsec VPN",
      "PAN-OS"
    ]
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.