<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VMs cannot access the Internet in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vms-cannot-access-the-internet/m-p/426903#M1300</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131231"&gt;@dmifsud&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Does the firewall transmit the request &amp;gt;YES&lt;BR /&gt;2) Does the firewall receive the response from 8.8.8.8&amp;gt;NO&lt;/P&gt;&lt;P&gt;3) If it does, does it transmit this to the client&amp;gt;There is nothing in between FW and VM&lt;/P&gt;&lt;P&gt;4) No drop seen in global counter. I have turned off DPDK setting.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;gt; show counter global filter packet-filter yes delta yes&lt;/P&gt;&lt;P&gt;Global counters:&lt;BR /&gt;Elapsed time since last sampling: 7.5 seconds&lt;/P&gt;&lt;P&gt;name value rate severity category aspect description&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;pkt_sent 1 0 info packet pktproc Packets transmitted&lt;BR /&gt;session_allocated 3 0 info session resource Sessions allocated&lt;BR /&gt;session_installed 3 0 info session resource Sessions installed&lt;BR /&gt;flow_ip_cksm_sw_validation 3 0 info flow pktproc Packets for which IP checksum validation was done in software&lt;BR /&gt;appid_ident_by_icmp 3 0 info appid pktproc Application identified by icmp type&lt;BR /&gt;nat_dynamic_port_xlat 3 0 info nat resource The total number of dynamic_ip_port NAT translate called&lt;BR /&gt;dfa_sw 3 0 info dfa pktproc The total number of dfa match using software&lt;BR /&gt;ctd_pscan_sw 3 0 info ctd pktproc The total usage of software for pscan&lt;BR /&gt;ctd_process 3 0 info ctd pktproc session processed by ctd&lt;BR /&gt;ctd_pkt_slowpath 3 0 info ctd pktproc Packets processed by slowpath&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5) NAT seems fine as configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Waiting for your response.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Aug 2021 08:20:56 GMT</pubDate>
    <dc:creator>Connected123</dc:creator>
    <dc:date>2021-08-23T08:20:56Z</dc:date>
    <item>
      <title>VMs cannot access the Internet</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vms-cannot-access-the-internet/m-p/426824#M1298</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope I get some direction/solution here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;VM (10.9.8.4) can ping trusted interface (10.8.130.4) of PA but with packet loss!!! However, tracert 8.8.8.8 does not show the trusted interface as next hop....request timed out. Cannot go to the Internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All NSG set to allowed. PA has the most basic config at this stage with Allow All Policy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tried to bypass asymmetric routing. Show counter global filter did not show any drop packets.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would appreciate if anyone can help in solving this puzzle.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 08:22:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vms-cannot-access-the-internet/m-p/426824#M1298</guid>
      <dc:creator>Connected123</dc:creator>
      <dc:date>2021-08-23T08:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: VMs cannot access the Internet</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vms-cannot-access-the-internet/m-p/426867#M1299</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Personally I would set up a packet capture at the receive, transmit and drop stages, then check:&lt;/P&gt;&lt;P&gt;1) Does the firewall transmit the request (assuming yes)&lt;BR /&gt;2) Does the firewall receive the response from 8.8.8.8&lt;/P&gt;&lt;P&gt;3) If it does, does it transmit this to the client&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can check the drop capture for any drops, although if the counters are clean you shouldn't be seeing anything there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, open the detailed log view (that magnifying glass at the left-most side of the traffic log) to check NAT was performed and if the NAT IP/interface make sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- DM&lt;/P&gt;</description>
      <pubDate>Sat, 14 Aug 2021 15:49:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vms-cannot-access-the-internet/m-p/426867#M1299</guid>
      <dc:creator>dmifsud</dc:creator>
      <dc:date>2021-08-14T15:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: VMs cannot access the Internet</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vms-cannot-access-the-internet/m-p/426903#M1300</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131231"&gt;@dmifsud&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Does the firewall transmit the request &amp;gt;YES&lt;BR /&gt;2) Does the firewall receive the response from 8.8.8.8&amp;gt;NO&lt;/P&gt;&lt;P&gt;3) If it does, does it transmit this to the client&amp;gt;There is nothing in between FW and VM&lt;/P&gt;&lt;P&gt;4) No drop seen in global counter. I have turned off DPDK setting.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;gt; show counter global filter packet-filter yes delta yes&lt;/P&gt;&lt;P&gt;Global counters:&lt;BR /&gt;Elapsed time since last sampling: 7.5 seconds&lt;/P&gt;&lt;P&gt;name value rate severity category aspect description&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;pkt_sent 1 0 info packet pktproc Packets transmitted&lt;BR /&gt;session_allocated 3 0 info session resource Sessions allocated&lt;BR /&gt;session_installed 3 0 info session resource Sessions installed&lt;BR /&gt;flow_ip_cksm_sw_validation 3 0 info flow pktproc Packets for which IP checksum validation was done in software&lt;BR /&gt;appid_ident_by_icmp 3 0 info appid pktproc Application identified by icmp type&lt;BR /&gt;nat_dynamic_port_xlat 3 0 info nat resource The total number of dynamic_ip_port NAT translate called&lt;BR /&gt;dfa_sw 3 0 info dfa pktproc The total number of dfa match using software&lt;BR /&gt;ctd_pscan_sw 3 0 info ctd pktproc The total usage of software for pscan&lt;BR /&gt;ctd_process 3 0 info ctd pktproc session processed by ctd&lt;BR /&gt;ctd_pkt_slowpath 3 0 info ctd pktproc Packets processed by slowpath&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5) NAT seems fine as configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Waiting for your response.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 08:20:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vms-cannot-access-the-internet/m-p/426903#M1300</guid>
      <dc:creator>Connected123</dc:creator>
      <dc:date>2021-08-23T08:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: VMs cannot access the Internet</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vms-cannot-access-the-internet/m-p/426937#M1301</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131231"&gt;@dmifsud&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am checking on the Azure side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just wanted to ask if you have come across this issue below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) tracert is failing. It should show the trusted interface of PA as next hop&lt;/P&gt;&lt;P&gt;&amp;gt;tracert 8.8.8.8&lt;/P&gt;&lt;P&gt;Tracing route to dns.google [8.8.8.8]&lt;BR /&gt;over a maximum of 30 hops:&lt;/P&gt;&lt;P&gt;1 * * * Request timed out.&lt;BR /&gt;2 * * * Request timed out.&lt;BR /&gt;3 * * * Request timed out.&lt;BR /&gt;4 * * * Request timed out.&lt;BR /&gt;5 * * * Request timed out.&lt;BR /&gt;6 * * * Request timed out.&lt;BR /&gt;7 * * * Request timed out.&lt;BR /&gt;8 * * * Request timed out.&lt;BR /&gt;&lt;BR /&gt;2) Same route settings is used for Hub machines and they can access the Internet. Effective routes in Azure is showing the correct path.&lt;BR /&gt;The only difference is Spoke VM is on the other side of VNET peering.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 01:31:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vms-cannot-access-the-internet/m-p/426937#M1301</guid>
      <dc:creator>Connected123</dc:creator>
      <dc:date>2021-08-16T01:31:31Z</dc:date>
    </item>
  </channel>
</rss>

