I have a site to site VPN tunnel between PA-820 and Cisco ASA. The tunnel comes up successfully for both Phase 1 & 2. However, no traffic seems to be flowing between the endpoints.
Both the PA and ASA are behind a NAT device, I tried to enable NAT-T with no luck. Disabling it instead brings up the tunnel.
Running "show vpn flow tunnel-id x | match endap" I can see some encaps, but the decaps are 0. On the ASA side both encaps and decaps are 0.
Although I configured the static route on the virtual router pointing to the right tunnel interface, but it seems as the PA does not send the VPN traffic to the destination.
One thing worth mentioning is that the private IP of the outside interface of the ASA has same subnet ID as the one I have between the PA and the local default gateway.
Any suggestion is appreciated.