<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Class C addresses PA setup in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-class-c-addresses-pa-setup/m-p/421386#M1534</link>
    <description>&lt;P&gt;Thank you for your reply. Yes, the ISP is forwarding to that Vlan. I have a PC that is in the subnet (107) outside the firewall that I can ping. However, I cannot ping the address assigned to the PA interface. That's what is confusing. The PA doesn't show the ping in a capture either.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Jul 2021 16:45:55 GMT</pubDate>
    <dc:creator>HamptonSaussy</dc:creator>
    <dc:date>2021-07-22T16:45:55Z</dc:date>
    <item>
      <title>Multiple Class C addresses PA setup</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-class-c-addresses-pa-setup/m-p/421107#M1530</link>
      <description>&lt;P&gt;I’m configuring a PA3220 for three external class C addresses we own (192.168.10.0/24, 192.168.11.0/24, and 192.168.14.0/24). We have two ISP Internet connections on two different campuses. We are using trunking to carry the different VLANs, so the outside networks are on the same physical interface. The inside network is on another physical interface. We have static routes setup for the two class C – 192.168.10.0 and 192.168.11.0. I tried to setup a static route for the other network, but that doesn’t work. See diagram.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am able to get two of the class C addresses working correctly; however, I cannot get a ping response back from the third class C address (192.168.14.0/24) assigned to the PA from outside. I do get a response from a PC on the same network. I have a PC &amp;nbsp;(192.168.14.250) in the third class C subnet that does respond to ping, so I know that the router is working correctly. I’m not sure if this is a routing issue with the PA or something else. Please let me know if I need to provide additional information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Firewall Network.jpg" style="width: 869px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35165i2FCB6B34F5205936/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Firewall Network.jpg" alt="Firewall Network.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2021 16:52:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-class-c-addresses-pa-setup/m-p/421107#M1530</guid>
      <dc:creator>HamptonSaussy</dc:creator>
      <dc:date>2021-07-21T16:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Class C addresses PA setup</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-class-c-addresses-pa-setup/m-p/421192#M1531</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179399"&gt;@HamptonSaussy&lt;/a&gt;&amp;nbsp;Is the vlan 107 allowed by your ISP s they might need to allow it on their devices for the vlan to work. You can also create vlan interface on switch in both campuses which will bypass the PA and then you can be sure it s not the firewall.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jul 2021 05:26:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-class-c-addresses-pa-setup/m-p/421192#M1531</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2021-07-22T05:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Class C addresses PA setup</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-class-c-addresses-pa-setup/m-p/421386#M1534</link>
      <description>&lt;P&gt;Thank you for your reply. Yes, the ISP is forwarding to that Vlan. I have a PC that is in the subnet (107) outside the firewall that I can ping. However, I cannot ping the address assigned to the PA interface. That's what is confusing. The PA doesn't show the ping in a capture either.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jul 2021 16:45:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-class-c-addresses-pa-setup/m-p/421386#M1534</guid>
      <dc:creator>HamptonSaussy</dc:creator>
      <dc:date>2021-07-22T16:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Class C addresses PA setup</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-class-c-addresses-pa-setup/m-p/421584#M1546</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179399"&gt;@HamptonSaussy&lt;/a&gt;&amp;nbsp;Have another look if you have allowed the vlan on the trunk connecting to PA. You can also create and assign an IP from the subnet on the switch which trunks to PA, you rule out the ISP and focus locally first. You should be able ping from PA interface as source to the switch interface vlan 197 IP. Also when doing a ping to PA don't forget what and which IPs you allow in attached interface management profile.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 06:02:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-class-c-addresses-pa-setup/m-p/421584#M1546</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2021-07-23T06:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Class C addresses PA setup</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-class-c-addresses-pa-setup/m-p/421687#M1549</link>
      <description>&lt;P&gt;The router is handling the trunk port and has a .1 address and the PA has a .2 address. From a PC with a .250 address, I can ping both .1 and .2 addresses. However, from outside that network, I can only ping the .1 address and the .250 address. The PA routing table has the 107 subnet pointing to the .1 address. The PA default route is pointing to vlan102. So, I believe the PA is handling the trunking. I'm thinking I may need PBF for this network.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 15:30:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-class-c-addresses-pa-setup/m-p/421687#M1549</guid>
      <dc:creator>HamptonSaussy</dc:creator>
      <dc:date>2021-07-23T15:30:56Z</dc:date>
    </item>
  </channel>
</rss>

