I recently faced an issue with Site to Site VPN connectivity between the two Palo Alto Firewalls. They were behind the NAT Device or Internet Router. The WAN interface is configured with the Private IP address.
The Site 2 Site VPN tunnel was not forming at all between the two Palo Alto Firewalls, It formed only when I added the following settings below for Local Identification and Peer Identification with the Public IP address:
Best Regards,
Kareem