<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Strange issue- VM-Series Ext interface with Elastic IP in AWS not reachable.  (outside test PC reachable) in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/strange-issue-vm-series-ext-interface-with-elastic-ip-in-aws-not/m-p/399581#M1173</link>
    <description>&lt;P&gt;I am trying to POC a scenario for my customer in AWS with dual Palo Alto in HA within same availability zone. (We need to build a site to Site VPN tunnel from on-Premises to AWS Palo behind IGW)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing a strange issue. I an not able to reach the outside Elastic IP address of Palo.(I am able to reach the public IP on Management interface).&amp;nbsp;The ENI's are moving to the secondary on failover.&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I have deployed Palo Alto Primary FW and Secondary FW.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;All Security Groups are configured to permit all traffic. No NALC’s configured.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Main VPC is 10.180.0.0/16&lt;/LI&gt;&lt;LI&gt;There are 4 Subnets: Public 10.180.100.0/24, Management 10.180.110.0/24, Private 10.180.120.0/24 and HA 10.180.130.0/24&lt;/LI&gt;&lt;LI&gt;There are 2 route tables - Public and Private&lt;/LI&gt;&lt;LI&gt;3&amp;nbsp; subnets (Public, Management and HA) are associated with Public Route Table and Private subnet is associated with Private RT.&lt;/LI&gt;&lt;LI&gt;Internet Gateway is attached to VPC.&amp;nbsp;Default route is configured in Public RT pointing to IGW. Communication from Public RT is up as the Test PC and Palo Management interface is able to reach internet.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Palo Alto is configured with Static IP and static default route pointing to the first IP of Public subnet (10.180.100.1)&lt;/LI&gt;&lt;LI&gt;Palo Configured with Security policy to permit all traffic.&lt;/LI&gt;&lt;LI&gt;Palo management profile permits ping, ssh, https&lt;/LI&gt;&lt;LI&gt;Elastic Public IP is attached to the&lt;SPAN&gt;&amp;nbsp;Public and Management ENI’s. Palo Primary have 4 ENI's - Management (elastic IP), Public (elastic IP), HA and Private.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Source/destination check is disabled on all ENI's&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;HA configured and is syncing the configs with peer. Data plane Interface is moving to the Secondary Palo on failover.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Management IP is reachable, test PC in public subnet is reachable, but Palo’s public IP is not. I re-created this lab at least 10 times now. The interesting thing is that, I was able to reach the external public IP of Palo yesterday but is not working after another rebuild.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Am I missing something here? Can any one help me resolve this issue?.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Palo_Lab.PNG" style="width: 577px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32009iC7676326DBE41943/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Palo_Lab.PNG" alt="Palo_Lab.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 17 Apr 2021 04:31:31 GMT</pubDate>
    <dc:creator>harishsidhartha</dc:creator>
    <dc:date>2021-04-17T04:31:31Z</dc:date>
    <item>
      <title>Strange issue- VM-Series Ext interface with Elastic IP in AWS not reachable.  (outside test PC reachable)</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/strange-issue-vm-series-ext-interface-with-elastic-ip-in-aws-not/m-p/399581#M1173</link>
      <description>&lt;P&gt;I am trying to POC a scenario for my customer in AWS with dual Palo Alto in HA within same availability zone. (We need to build a site to Site VPN tunnel from on-Premises to AWS Palo behind IGW)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing a strange issue. I an not able to reach the outside Elastic IP address of Palo.(I am able to reach the public IP on Management interface).&amp;nbsp;The ENI's are moving to the secondary on failover.&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I have deployed Palo Alto Primary FW and Secondary FW.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;All Security Groups are configured to permit all traffic. No NALC’s configured.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Main VPC is 10.180.0.0/16&lt;/LI&gt;&lt;LI&gt;There are 4 Subnets: Public 10.180.100.0/24, Management 10.180.110.0/24, Private 10.180.120.0/24 and HA 10.180.130.0/24&lt;/LI&gt;&lt;LI&gt;There are 2 route tables - Public and Private&lt;/LI&gt;&lt;LI&gt;3&amp;nbsp; subnets (Public, Management and HA) are associated with Public Route Table and Private subnet is associated with Private RT.&lt;/LI&gt;&lt;LI&gt;Internet Gateway is attached to VPC.&amp;nbsp;Default route is configured in Public RT pointing to IGW. Communication from Public RT is up as the Test PC and Palo Management interface is able to reach internet.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Palo Alto is configured with Static IP and static default route pointing to the first IP of Public subnet (10.180.100.1)&lt;/LI&gt;&lt;LI&gt;Palo Configured with Security policy to permit all traffic.&lt;/LI&gt;&lt;LI&gt;Palo management profile permits ping, ssh, https&lt;/LI&gt;&lt;LI&gt;Elastic Public IP is attached to the&lt;SPAN&gt;&amp;nbsp;Public and Management ENI’s. Palo Primary have 4 ENI's - Management (elastic IP), Public (elastic IP), HA and Private.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Source/destination check is disabled on all ENI's&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;HA configured and is syncing the configs with peer. Data plane Interface is moving to the Secondary Palo on failover.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Management IP is reachable, test PC in public subnet is reachable, but Palo’s public IP is not. I re-created this lab at least 10 times now. The interesting thing is that, I was able to reach the external public IP of Palo yesterday but is not working after another rebuild.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Am I missing something here? Can any one help me resolve this issue?.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Palo_Lab.PNG" style="width: 577px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32009iC7676326DBE41943/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Palo_Lab.PNG" alt="Palo_Lab.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Apr 2021 04:31:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/strange-issue-vm-series-ext-interface-with-elastic-ip-in-aws-not/m-p/399581#M1173</guid>
      <dc:creator>harishsidhartha</dc:creator>
      <dc:date>2021-04-17T04:31:31Z</dc:date>
    </item>
  </channel>
</rss>

