

If a clean-up rule is configured, the policy is configured usually from the external zone to the external zone. Usually this policy is not required if there is no clean-up rule configured on the box.

To rule out ISP-related issues, try pinging the peer IP from the PA external interface.It is divided into two parts, one for each Phase of an IPSec VPN. This document is intended to help troubleshoot IPSec VPN connectivity issues.
