r/paloaltonetworks
Palo Alto IPsec VPN is UP but traffic isn't passing - how do you troubleshoot it?
- upvotes
- 6
- comments
- 19
Post
Highlighted: the lines this signal was extracted from
One of the more confusing Palo Alto VPN issues is when the IKE SA and IPsec SA are both UP, but traffic still doesn't pass. When troubleshooting a site-to-site IPsec VPN, I usually try to avoid changing multiple settings at once and instead work through the traffic path step by step: Is the VPN peer reachable? Is IKE Phase 1 established? Is IPsec Phase 2 established? Are the IKE/IPsec proposals matching? Are Proxy IDs or traffic selectors causing an issue? Is there a route to the remote subnet? Is the security policy matching the traffic? Is NAT accidentally being applied? Are VPN traffic counters increasing? What do the traffic logs show? If needed, where should packet capture be performed? One thing that is easy to overlook is that a tunnel being UP doesn't necessarily mean the application traffic will work. The VPN can be perfectly established while routing, security policy, NAT, or the return path is still wrong. I put together a practical troubleshooting guide covering these checks along with useful Palo Alto CLI commands such as: show vpn ike-sa show vpn ipsec-sa show vpn flow test vpn ike-sa gateway <gateway> test vpn ipsec-sa tunnel <tunnel> If anyone is troubleshooting Palo Alto IPsec VPNs, I'd be interested to hear what problem you encounter most often - Phase 1, Phase 2, routing, policy, NAT, or something else. For anyone who wants the full...
Keep reading with a free account
The rest of this post, and every signal for Palo Alto Networks, is in your free account.
Also quoted as evidence
[comment u/jtmajorx] It’s funny how many times I’ve ran into this issue and it ended up being NAT traversal not being enabled.
[comment u/Any-Promotion3744] for us, it is usually static routes or proxy id problems.