OK I see but in my case, when I use ethx as tunnel interface with 3 tunnels it doesn’t work, it works only with only one remote network of the 3.
In Palo Alto side, I don’t need to setup multiple tunnels as I just have to reach one remote network, right?
On Palo Alto side, you do need 3 identical tunnels, with only local/remote prefixes reversed.
To succesfully negotiate this tunnel policy settings should match on both sides (encryption, hash lifetime (not so) and remote/local subnet)
OK I did find how to add this in Palo side and tested and for some reason one subnet doesn’t work.
By the way, I found this configuration process which use VTI instead of ETH for Palo and it works like that so I’ll keep as it.
Thanks anyway for your help