<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Azure No Arp in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259103#M575</link>
    <description>&lt;P&gt;You have hit all of the usual culprits.&amp;nbsp; Time to get a TAC case open.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Apr 2019 15:53:54 GMT</pubDate>
    <dc:creator>jmeurer</dc:creator>
    <dc:date>2019-04-29T15:53:54Z</dc:date>
    <item>
      <title>Azure No Arp</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259088#M570</link>
      <description>&lt;P&gt;Hey All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm coming across a weird issue here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have two subents in Azure. Let's call them Subnet1 and Subnet2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Subnet1 has a UDR to point traffic to the internal interface of the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This works, we see the traffic come into the firewall. We don't see any return traffic from the server in subnet 2. There is a static route pointing to the azure fabric .1 address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I do a flow basic, the firewall is unable to send the traffic to the gateway (azure .1 address) because there is no ARP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Route found, interface ethernet1/2, zone 2, nexthop 10.38.225.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Resolve ARP for IP 10.38.225.1 on interface ethernet1/2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;ARP pending&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Packet dropped, no ARP&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;HELP!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 15:20:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259088#M570</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-04-29T15:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Azure No Arp</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259098#M571</link>
      <description>&lt;P&gt;Do you have a corresponding route in subnet 2 pointing to the firewall for subnet 1?&amp;nbsp; If you do not, azure will assymetrically return the traffic directly to the server rather than return routing through the firewall due to the VNET route.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 15:27:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259098#M571</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2019-04-29T15:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: Azure No Arp</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259099#M572</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70475"&gt;@jmeurer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your input. Yes the UDR for subent 2 is there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any other ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 15:31:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259099#M572</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-04-29T15:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: Azure No Arp</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259100#M573</link>
      <description>&lt;P&gt;I assume the firewall has corresponding routes for both subnets pointing to the first IP of the internal subnet the firewall is attached two.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, check to ensure the interface has IP Forwarding enabled on the azure side.&amp;nbsp; If you do need to change this setting.&amp;nbsp; Reboot the firewall.&amp;nbsp; I have seen it not apply until after reboot.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-network-interface#enable-or-disable-ip-forwarding" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-network-interface#enable-or-disable-ip-forwarding&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From there, double check your NSGs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since this intrazone traffic, it should be allowed, but you may not be logging it due to the inherent rule.&amp;nbsp; Override logging on intrazone, it may give you some further information in the Monitor.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 15:40:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259100#M573</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2019-04-29T15:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: Azure No Arp</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259102#M574</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70475"&gt;@jmeurer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewall routes exist and are correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IP forwarding enabled on all interfaces. I've also rebooted the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nSGs are all allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've done logging on the policies but just show "bytes received: 0"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried with a NAT rule to source NAT and not, makes no difference.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 15:49:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259102#M574</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-04-29T15:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: Azure No Arp</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259103#M575</link>
      <description>&lt;P&gt;You have hit all of the usual culprits.&amp;nbsp; Time to get a TAC case open.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 15:53:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259103#M575</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2019-04-29T15:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: Azure No Arp</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259117#M576</link>
      <description>&lt;P&gt;Is Subnet 2 a gateway subnet?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 16:36:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259117#M576</guid>
      <dc:creator>dmaynard</dc:creator>
      <dc:date>2019-04-29T16:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Azure No Arp</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259235#M577</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27135"&gt;@dmaynard&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nope! It's not a gateway subnet.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 07:53:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259235#M577</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-04-30T07:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Azure No Arp</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259272#M578</link>
      <description>&lt;P&gt;Found out the issue.. the static routes on the firewall were pointing to each .1 address of the subnet rather than the .1 address of the address range assigned to the VNET&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 13:56:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/259272#M578</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-04-30T13:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Azure No Arp</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/315463#M776</link>
      <description>&lt;P&gt;Can you elaborate little bit ?&amp;nbsp; you are saying you pointed static route on Palo Alto to VNET&amp;nbsp; .1 IP ? and not first IP in subnet of interface of firewall for example eth2 ?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 14:12:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/315463#M776</guid>
      <dc:creator>fatboy1607</dc:creator>
      <dc:date>2020-03-10T14:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: Azure No Arp</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/336481#M864</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had the same problem and managed to get it sorted. I orignally was this accepted answer but didnt really understand it.&lt;/P&gt;&lt;P&gt;Take a look at my post and it might clear things up.&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/azure-palo-alto-arp-not-found/m-p/336411/thread-id/84754/highlight/false#M84756" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/azure-palo-alto-arp-not-found/m-p/336411/thread-id/84754/highlight/false#M84756&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 16:39:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-no-arp/m-p/336481#M864</guid>
      <dc:creator>ashleyk</dc:creator>
      <dc:date>2020-07-02T16:39:08Z</dc:date>
    </item>
  </channel>
</rss>

