<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NGFW routing internet traffic help in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416672#M11</link>
    <description>&lt;P&gt;I am setting up a very simple PA200 implementation and all I need at this stage is to be able to contact the Palo update server to update the PanOS.&amp;nbsp; I have the FW plugged in directly from ethernet1/1 to the modem (subnet 192.168.0.1).&amp;nbsp; The gateway is pingable.&amp;nbsp; My machine is connected to the the management interface (172.16.30.35).&amp;nbsp; I have&amp;nbsp; virtual router configured to send all traffic (0.0.0.0/0) out of ethernet1/1.&amp;nbsp; I have an any/any security policy set.&amp;nbsp; I have a NAT rule (I suspect this is the problem) configured to translate the networks to each other (at least that's my intention).&amp;nbsp; I know the issue is something simple but I can't get past it. Any help would be appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_1-1625177055815.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34697iFF556C60E11DA16A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_1-1625177055815.png" alt="ebryan_1-1625177055815.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_0-1625176896772.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34696i18DF3C6D03A5E164/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_0-1625176896772.png" alt="ebryan_0-1625176896772.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Oct 2021 01:22:40 GMT</pubDate>
    <dc:creator>ebryan</dc:creator>
    <dc:date>2021-10-27T01:22:40Z</dc:date>
    <item>
      <title>NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416672#M11</link>
      <description>&lt;P&gt;I am setting up a very simple PA200 implementation and all I need at this stage is to be able to contact the Palo update server to update the PanOS.&amp;nbsp; I have the FW plugged in directly from ethernet1/1 to the modem (subnet 192.168.0.1).&amp;nbsp; The gateway is pingable.&amp;nbsp; My machine is connected to the the management interface (172.16.30.35).&amp;nbsp; I have&amp;nbsp; virtual router configured to send all traffic (0.0.0.0/0) out of ethernet1/1.&amp;nbsp; I have an any/any security policy set.&amp;nbsp; I have a NAT rule (I suspect this is the problem) configured to translate the networks to each other (at least that's my intention).&amp;nbsp; I know the issue is something simple but I can't get past it. Any help would be appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_1-1625177055815.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34697iFF556C60E11DA16A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_1-1625177055815.png" alt="ebryan_1-1625177055815.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_0-1625176896772.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34696i18DF3C6D03A5E164/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_0-1625176896772.png" alt="ebryan_0-1625176896772.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 01:22:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416672#M11</guid>
      <dc:creator>ebryan</dc:creator>
      <dc:date>2021-10-27T01:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416725#M12</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179774"&gt;@ebryan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Is your intention to make the PA-200 sit at the edge of your home network? Assuming that this is the case, your NAT statement as presently configured doesn't really make much sense unless you have a route on your modem/router (assuming you aren't talking about an actual straight modem) combo unit pointing back to your firewall. Otherwise you wouldn't have a return route pointing the traffic back to your firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Generally for a home setup your NAT statement would simply have your source-translation setup like so:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Translation Type&lt;/STRONG&gt;&lt;STRONG&gt;:&lt;/STRONG&gt; Dynamic IP And Port&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Address Type:&amp;nbsp;&lt;/STRONG&gt;Interface Address&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Interface:&lt;/STRONG&gt; ethernet1/1&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IP&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;address:&amp;nbsp;&lt;/STRONG&gt;None (Assuming DHCP assignment, otherwise you can select the static address from the drop down)&lt;/P&gt;&lt;P&gt;What this will do is simply NAT all of the traffic through the address assigned to your ethernet1/1 address and out through the modem. This then allows your modem to know where it has to return the traffic without any additional route configuration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 03:09:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416725#M12</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-07-02T03:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416772#M13</link>
      <description>&lt;P&gt;also...&amp;nbsp; &amp;nbsp;have you really put your external interface into the trust zone?&amp;nbsp; if not then perhaps the NAT destination should be "untrust"&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 07:35:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416772#M13</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-07-02T07:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416797#M14</link>
      <description>&lt;P&gt;Thanks for your help. I have updated the NAT statement as such.&amp;nbsp; I'm still not getting internet connectivity, though.&amp;nbsp; What other information do you need for us to continue troubleshooting?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_0-1625222066474.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34718i8E1358EAB1F36896/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_0-1625222066474.png" alt="ebryan_0-1625222066474.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for pointing that out.&amp;nbsp; I have made that correction as well.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 10:36:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416797#M14</guid>
      <dc:creator>ebryan</dc:creator>
      <dc:date>2021-07-02T10:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416850#M15</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;can you share me route table output.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can use below steps to get it.&lt;/P&gt;&lt;P&gt;&amp;gt;network &amp;gt; virtual Routers&amp;gt;&amp;lt;vr-name&amp;gt; &amp;gt;more runtime stats&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And also try to test ( internet, security policy, ping etc) from below step.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;device &amp;gt; Troubleshooting &amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Suresh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 14:35:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416850#M15</guid>
      <dc:creator>SureshReddyM</dc:creator>
      <dc:date>2021-07-02T14:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416870#M16</link>
      <description>&lt;P&gt;This is my NAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2947E06C-E26A-4736-B657-89C41011C4F1.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34721i21D96C6BCA19FD8C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2947E06C-E26A-4736-B657-89C41011C4F1.jpeg" alt="2947E06C-E26A-4736-B657-89C41011C4F1.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If still not working then try changing the service route for updates to ethernet1/1... &amp;nbsp; if that works then perhaps an issue before it hits the NAT policy...&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 15:45:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416870#M16</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-07-02T15:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416922#M17</link>
      <description>&lt;P&gt;If NAT and MGT addresses are correctly populated and ruled out, could it be more basic?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you able to verify that you've given the MGT server a reachable DNS server?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screen Shot 2021-07-02 at 12.12.17 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34731i1830E49BE00BB7F6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-07-02 at 12.12.17 PM.png" alt="Screen Shot 2021-07-02 at 12.12.17 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 19:13:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416922#M17</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2021-07-02T19:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416951#M18</link>
      <description>&lt;P&gt;Hi. Here is the route table.&amp;nbsp; 192.168.0.43 is the DHCP address of the FW.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_0-1625263635129.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34733i7C85DB6B77E8167F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_0-1625263635129.png" alt="ebryan_0-1625263635129.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_1-1625263679968.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34734i42EB15BB7C98B3CB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_1-1625263679968.png" alt="ebryan_1-1625263679968.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My device is at PanOS 8.1.6 so it doesn't have the troubleshooting tools mentioned above.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 22:09:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416951#M18</guid>
      <dc:creator>ebryan</dc:creator>
      <dc:date>2021-07-02T22:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416954#M19</link>
      <description>&lt;P&gt;No, MGT cannot reach a DNS server.&amp;nbsp; I have manually set it to 8.8.8.8 and 9.9.9.9.&amp;nbsp; DNS is pingable from ethernet1/1 but not from MGT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_3-1625263926254.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34736i8954ABAB17D39317/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_3-1625263926254.png" alt="ebryan_3-1625263926254.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_0-1625264704546.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34737i93D1DEBC79F14F82/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_0-1625264704546.png" alt="ebryan_0-1625264704546.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 22:25:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416954#M19</guid>
      <dc:creator>ebryan</dc:creator>
      <dc:date>2021-07-02T22:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416960#M20</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Is the trusted interface on the firewall 172.16.30.1/24 and is it also a member of the same virtual router as ethernet1/1.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 07:49:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416960#M20</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-07-03T07:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416961#M21</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hang on a mo..... &amp;nbsp; &amp;nbsp;you said at the first post... “&lt;/SPAN&gt;&lt;SPAN&gt;My machine is connected to the the management interface (172.16.30.35)”. &amp;nbsp;If this is the case then how is the management interface going to see the palo trusted interface? Or perhaps i have misread.... &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 08:06:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416961#M21</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-07-03T08:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416973#M22</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;Thanks again for your help.&amp;nbsp; Yes, 172.16.30.1/24 is on the trusted interface of the firewall and a member of the same virtual router.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_0-1625324096146.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34740iF1D83542624ACD9C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_0-1625324096146.png" alt="ebryan_0-1625324096146.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_1-1625324456377.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34741iE936C6D933C28E20/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_1-1625324456377.png" alt="ebryan_1-1625324456377.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe that's my problem; the management interface cannot see the trusted interface.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 15:01:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416973#M22</guid>
      <dc:creator>ebryan</dc:creator>
      <dc:date>2021-07-03T15:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416991#M24</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179774"&gt;@ebryan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So currently probably the firewall or at least the default-vr has internet access but not your management interface as this one is conected to your computer. The route table of the management plane is completely separated from other dataplane configurations (all the actual firewallinterfaces). In a default configuration the firewall tries to reach everything from the management interface which means the firewalls tries to download updates for example over your computer. I see now two possiblities&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;You connect the firewalls managementinterface to eth1/2. This should enable internet access for the firewall but in your current configuration you then don't have a connection to the firewall.&lt;/LI&gt;&lt;LI&gt;You configure serviceroutes on the firewall. Under Device &amp;gt; Setup &amp;gt; Services &amp;gt; Service Features &amp;gt; Service Route Configuration you can specify another interface than the managementport as source for specific services like dns, paloalto updates. When you change this the firewall should be able to reach the dns servers and download the updates&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20210703-182039_Chrome.jpg" style="width: 1440px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34744i075949E7C244764D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot_20210703-182039_Chrome.jpg" alt="Screenshot_20210703-182039_Chrome.jpg" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;In your situation I propose to use possibility 2 and change the sourceinterface for the services that require internet access. If you do this, then a firewallpolicy is required to allow that traffic but as you already have an any-any-allow rule this shouldn't be a problem.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 16:25:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416991#M24</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-07-03T16:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416995#M25</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp; has your best solution here... &amp;nbsp;but if you have a spare switch/hub then just connect ethernet1/2, management interface.. and your laptop into it... &amp;nbsp;Boom!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 17:05:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/416995#M25</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-07-03T17:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/417001#M26</link>
      <description>&lt;P&gt;Thanks for your help.&amp;nbsp; I've added loopback.1 (192.168.0.1/32) to the desired service route but I'm still unable to access the updates server.&amp;nbsp; I tried the other method as well without success.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_0-1625335279997.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34748i092C5FC700ED0A97/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_0-1625335279997.png" alt="ebryan_0-1625335279997.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_1-1625335398832.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34749iCEF855D899E6E11A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_1-1625335398832.png" alt="ebryan_1-1625335398832.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 18:03:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/417001#M26</guid>
      <dc:creator>ebryan</dc:creator>
      <dc:date>2021-07-03T18:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/417002#M27</link>
      <description>&lt;P&gt;Ok, then ...&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;What zone did you assign to loopback.1?&lt;/LI&gt;&lt;LI&gt;Did you ad the loopback interface to the same virtual router as ethernet1/1 (your "external" interface)?&lt;/LI&gt;&lt;LI&gt;Did you check the trafficlogs for connections from 192.168.0.1 towards the configured dns servers on port 53?&lt;/LI&gt;&lt;LI&gt;Did you commit the configuration prior to checking for new updates?&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Sat, 03 Jul 2021 18:47:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/417002#M27</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-07-03T18:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/417014#M28</link>
      <description>&lt;P&gt;... or configure the interface eth1/2 as layer2 and also another port to the same layer 2 vlan and there is no need for a switch/hub &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 19:43:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/417014#M28</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-07-03T19:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/417016#M29</link>
      <description>&lt;P&gt;loopback.1 is in the untrust zone&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_2-1625341567333.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34753iA5CFC21192585331/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_2-1625341567333.png" alt="ebryan_2-1625341567333.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The loopback and interface 1/1 are both on the same virtual router&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_1-1625341304526.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34752iC9D1FD676C3222D6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_1-1625341304526.png" alt="ebryan_1-1625341304526.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see log entries from 192.168.0.1 to the configured DNS servers&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_0-1625341262644.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34751i66D3745747ABF3D5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_0-1625341262644.png" alt="ebryan_0-1625341262644.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I committed the changes prior to testing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 19:46:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/417016#M29</guid>
      <dc:creator>ebryan</dc:creator>
      <dc:date>2021-07-03T19:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/417017#M30</link>
      <description>&lt;P&gt;In these sessions in the trafficlog, is NAT applied there?&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 19:50:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/417017#M30</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-07-03T19:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW routing internet traffic help</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/417019#M31</link>
      <description>&lt;P&gt;Yes. This is the NAT policy:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ebryan_0-1625342065038.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34754i1B412B57DEA53A2D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ebryan_0-1625342065038.png" alt="ebryan_0-1625342065038.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 19:54:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-routing-internet-traffic-help/m-p/417019#M31</guid>
      <dc:creator>ebryan</dc:creator>
      <dc:date>2021-07-03T19:54:30Z</dc:date>
    </item>
  </channel>
</rss>

