GRE Tunnel interface status in passive firewalls

GRE Tunnel interface status in passive firewalls

319
Created On 02/20/26 07:33 AM - Last Modified 07/23/26 21:13 PM


Question


What should be the status of GRE tunnel interface in passive firewalls?

 



Environment


• GRE Tunnels
• HA pair



Answer


The GRE tunnels should appear as down on a passive firewall. Passive firewalls do not serve traffic and therefore do not send GRE keep-alive packets.

However, Keep-Alive processing still runs on passive devices, so some passive firewalls that
happen to receive Keep-Alive responses (due to network topology or timing) update their internal state to UP, while others stay DOWN. It is a race/timing condition that depends on whether that specific passive firewall happened to process a keepalive response or not. 

 

 

 



Additional Information


https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-networking-admin/gre-tunnels/gre-tunnel-overview

https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-web-interface-help/network/network-gre-tunnels/gre-tunnels

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wkp1CAA



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000sYKNKA2&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail