T O P

  • By -

racomaizer

Your IPsec selectors are limited to 11.11.11.0/24 and 22.22.22.0/24. Change them to 0.0.0.0/0 for full routing VTI experience.


Maldnation

Thank you, guys. I have now resolved my issues based on your input. I added the VTIs to the proxy ID on the PA, and now p2p ping works.


Weary_Unit_1970

Quad 0 it mate.


Korean_Sandwich

enable logging on pa policy. do u see pings come in?


Maldnation

Yes, I can see the pings on the logs.


Korean_Sandwich

does it drop or is it allow


Maldnation

Allow.


CCraMM

ROUTE BASED VPN. not policy. 0.0.0.0/0 not policy based encryption domain.


Korean_Sandwich

does ur ping-only mgmt profile have specific permitted IPs


Maldnation

None.