An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
Hello @Abrar Adil S
The key clue here is the Traffic Selector Mismatch metric. A traffic-selector mismatch causes connectivity failures when the local/remote addresses don't match the selectors negotiated between the VPN peers.
Regarding your questions:
1. Does saving the Local Network Gateway reapply/reconcile the connection?
Modifying a Local Network Gateway that already has a connection may cause tunnel disconnects and downtime. Therefore, connectivity returning after changing/saving the address space could be because the VPN configuration is reapplied. However, I cannot find Microsoft documentation confirming that every LNG address-space save forces a specific IKE/IPsec SA renegotiation or explaining this exact recovery behavior.
2. Why is only 172.19.0.0/16 affected?
That actually makes a complete tunnel outage less likely. A traffic-selector mismatch can affect traffic whose source/destination addresses don't match the negotiated selectors. Other prefixes can therefore continue working while traffic associated with a problematic selector is dropped.
Adding 172.19.20.0/22 should not normally be required for Azure routing if 172.19.0.0/16 already represents the on-premises network correctly. The fact that adding the more-specific prefix temporarily restores connectivity suggests the next investigation should focus on the negotiated Phase 2/Quick Mode traffic selectors, rather than treating the /22 as the permanent fix.
I recommend capturing the failure before modifying the LNG again and comparing:
- Azure VPN Gateway traffic-selector/drop metrics
- IKE diagnostic logs
- the negotiated Phase 2 selectors on the Palo Alto
- an Azure VPN Gateway packet capture filtered to the affected 172.19.20.0/22 traffic
Microsoft supports VPN Gateway packet capture to isolate whether traffic is being lost on the Azure side, the customer side, or between them.
Given the observed Traffic Selector Mismatch events, focus on establishing exactly which selector is negotiated during the failure versus after the LNG save.
References:
Troubleshoot S2S VPN error codes
Modify Local Network Gateway settings
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.