Situation: The client has some servers on AWS which connecting to the LAN over site to site VPN. Today, two of servers on AWS can’t access one of LAN servers.
Troubleshooting: 1. Ping LAN server IP doesn’t work.
2. Paloalto firewall Monitor shows sending is fine. However, Packet received is 0.

3. AWS support confirm they don’t block access the LAN.
4. Finally, we find the server has a security software that blocks the AWS servers. Unblocking fixes the problem.