<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo VM300 Azure routing issues? in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-vm300-azure-routing-issues/m-p/230896#M421</link>
    <description>&lt;P&gt;We are a small company right now and don't have a full time Network Engineer/Admin/etc. so there's 2 of us that are trying to make all of this work with a consultant. The consultant built 2 VRs as I assume for some sort of extra security but I don't understand what they really do. I assume they are similar to say a SonicWall's route section; just done in something called Virtual routers but I can't be sure (the different lingo Palo uses is confusing to me as well but that's no biggie).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the Trust VR settings:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="trustVR.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16646iCE8063E893B75CA9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="trustVR.PNG" alt="trustVR.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This looks like it shunts all internet traffic over to the Untrust interface VR to handle, and then shunts all inter-subnet traffic to the gateway that the Trust interface is attached to. I would assume that gateway would know where the other subnets are once traffic hits that but it looks like we're missing something somewhere as traffic just dies at some point..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe we are missing routes? I understand Palo can do all this with 1 interface as we've been thinking about dropping extra NICs on the VM into each subnet to see if that helps but would hate to do that since it's not what Palo docs say for this type of setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Fri, 14 Sep 2018 17:56:57 GMT</pubDate>
    <dc:creator>BeyondPalo</dc:creator>
    <dc:date>2018-09-14T17:56:57Z</dc:date>
    <item>
      <title>Palo VM300 Azure routing issues?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-vm300-azure-routing-issues/m-p/230878#M419</link>
      <description>&lt;P&gt;Working with a Palo VM300 series in Azure and have some issues that I just can't figure out...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the VM inside of a 10.x.x.x/16 subnet. 1 subnet (10.x.x.x/24) carved for each of the interfaces (trusted, un, mngmt) and 4 more subnets for various other VMs and such. We have UDRs setup for all 3 interfaces as well as a UDR setup for the other subnets. The plan is to push all traffic in, out, and between subnets through this single Palo unit.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have 2 virtual routers built out; 1 for trusted, and 1 for untrusted interface. Trusted VR receives traffic internal and pushes internet traffic to the Untrust VR, and all traffic meant for subnet cross traffic is supposed to be forwarded to the Trust interface gateway and then should get to the correct subnet (barring any rules).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What we see is when trying a ping; the icmp is allowed through the rules, but then ages out so no reply back from the second VM. I believe there's an issue in these VRs but I can't seem to track it down. I've seen a lot of docs showing that Palo can be run in 1 vnet/multiple subnets with 1 interface but not really sure how this works. My only other FW experience is SonicWall so 1 port 1 zone makes sense but the 1 port many zones sure doesn't.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone know what to look for in either the Palo or Azure? I'm really not even sure the Azure UDRs are correct but everything I've read points to them being right (Palo documentation and online forums) so really I'm kinda at a brick wall on where to go next. Hopefully all of this makes sense as this is my first rodeo working with Palo and Azure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 16:50:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-vm300-azure-routing-issues/m-p/230878#M419</guid>
      <dc:creator>BeyondPalo</dc:creator>
      <dc:date>2018-09-14T16:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: Palo VM300 Azure routing issues?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-vm300-azure-routing-issues/m-p/230894#M420</link>
      <description>&lt;P&gt;Question 1. Is there a particular reason that you are using two separate VRs?&lt;/P&gt;
&lt;P&gt;If not I am not a fan for unecessary complexity but if you have a valid reason then please feel free.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you use a VR you have to be sure to route traffic between VR's correctly by using the "Next VR" setting etc or you could have a black hole.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 17:45:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-vm300-azure-routing-issues/m-p/230894#M420</guid>
      <dc:creator>jperry1</dc:creator>
      <dc:date>2018-09-14T17:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: Palo VM300 Azure routing issues?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-vm300-azure-routing-issues/m-p/230896#M421</link>
      <description>&lt;P&gt;We are a small company right now and don't have a full time Network Engineer/Admin/etc. so there's 2 of us that are trying to make all of this work with a consultant. The consultant built 2 VRs as I assume for some sort of extra security but I don't understand what they really do. I assume they are similar to say a SonicWall's route section; just done in something called Virtual routers but I can't be sure (the different lingo Palo uses is confusing to me as well but that's no biggie).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the Trust VR settings:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="trustVR.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16646iCE8063E893B75CA9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="trustVR.PNG" alt="trustVR.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This looks like it shunts all internet traffic over to the Untrust interface VR to handle, and then shunts all inter-subnet traffic to the gateway that the Trust interface is attached to. I would assume that gateway would know where the other subnets are once traffic hits that but it looks like we're missing something somewhere as traffic just dies at some point..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe we are missing routes? I understand Palo can do all this with 1 interface as we've been thinking about dropping extra NICs on the VM into each subnet to see if that helps but would hate to do that since it's not what Palo docs say for this type of setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 17:56:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-vm300-azure-routing-issues/m-p/230896#M421</guid>
      <dc:creator>BeyondPalo</dc:creator>
      <dc:date>2018-09-14T17:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Palo VM300 Azure routing issues?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-vm300-azure-routing-issues/m-p/230897#M422</link>
      <description>&lt;P&gt;Are you using Azure load balancers in this scenario?&lt;/P&gt;
&lt;P&gt;Also if you can go to your CLI and run the command&lt;/P&gt;
&lt;P&gt;&amp;gt;show routing route&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Paste the output&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 18:50:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-vm300-azure-routing-issues/m-p/230897#M422</guid>
      <dc:creator>jperry1</dc:creator>
      <dc:date>2018-09-14T18:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Palo VM300 Azure routing issues?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-vm300-azure-routing-issues/m-p/230903#M423</link>
      <description>&lt;P&gt;We are not using any load balancers right now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After running the command provided here's what I see:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="routepalo.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16650i63F2D9BAC983397E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="routepalo.PNG" alt="routepalo.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 19:04:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-vm300-azure-routing-issues/m-p/230903#M423</guid>
      <dc:creator>BeyondPalo</dc:creator>
      <dc:date>2018-09-14T19:04:07Z</dc:date>
    </item>
    <item>
      <title>Re: Palo VM300 Azure routing issues?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-vm300-azure-routing-issues/m-p/230918#M424</link>
      <description>&lt;P&gt;Your untrust VR needs to have routes for "NextVR" in order to understand how to get back to the 10.x.x.x networks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 20:10:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-vm300-azure-routing-issues/m-p/230918#M424</guid>
      <dc:creator>jperry1</dc:creator>
      <dc:date>2018-09-14T20:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: Palo VM300 Azure routing issues?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-vm300-azure-routing-issues/m-p/231242#M425</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I second&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/2533"&gt;@jperry1&lt;/a&gt;&amp;nbsp;recommendation of a single VR, unless there is an absolutle compelling reason to use multiple. Especially for a small shop such as yours. The simpler it is setup the easier it will be on you to manage it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 15:51:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-vm300-azure-routing-issues/m-p/231242#M425</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-09-18T15:51:31Z</dc:date>
    </item>
  </channel>
</rss>

