<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Internet -&amp;gt; PA-440 -&amp;gt; ASUS RT-AX53U AX1800. Error = Router does not get Internet access in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/internet-gt-pa-440-gt-asus-rt-ax53u-ax1800-error-router-does-not/m-p/573318#M2452</link>
    <description>&lt;P&gt;there's a good book you can read &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there's a lot of stuff you can do but let's start with the basics&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;create 2 new layer3 zones&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'd firstly set the interface 1/1 to layer 3 mode and set it as dhcp client. that should get you a public IP automatically from your ISP&lt;/P&gt;
&lt;P&gt;assign it the external zone&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_0-1705491902222.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56574i5CC05B5961A5CECF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="reaper_0-1705491902222.png" alt="reaper_0-1705491902222.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;next, set the ethernet1/2 as a layer3 interface and assign it an IP address (e.g. 192.168.50.1/24) , and enable a dhcp server on that interface, make sure you set the 192.168.50.1 IP as default route in the dhcp features&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_1-1705492035273.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56575i31910C2DD840B721/image-size/medium?v=v2&amp;amp;px=400" role="button" title="reaper_1-1705492035273.png" alt="reaper_1-1705492035273.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;now, it would be preferable if you can set your Asus in passthrough mode so it simply acts as an access point and not interfere with routing or additional NAT inside your network&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;don't forget to create a security rule that allows your new internal zone out to your new external zone (delete the rule that was already in place, fresh starts are better)&lt;/P&gt;
&lt;P&gt;make sure to add your subscription profiles!&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_2-1705492213885.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56576i8980A7CFF95BBC19/image-size/large?v=v2&amp;amp;px=999" role="button" title="reaper_2-1705492213885.png" alt="reaper_2-1705492213885.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;and lastly, create a NAT rule for your outbound traffic:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_3-1705492271967.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56577iE959FF6CFF409453/image-size/large?v=v2&amp;amp;px=999" role="button" title="reaper_3-1705492271967.png" alt="reaper_3-1705492271967.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to ensure your firewall is able to fetch updates, configure it with a DNS server in the management section, then consider setting up 'service routes'&amp;nbsp; (Device &amp;gt; setup &amp;gt; service &amp;gt; service routes) attached to your ethernet1/2 (as else the updates will be fetched via your managment interface which is currently not connected to anything)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_4-1705492548214.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56578i16511A468BA1D7C9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="reaper_4-1705492548214.png" alt="reaper_4-1705492548214.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jan 2024 11:55:59 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2024-01-17T11:55:59Z</dc:date>
    <item>
      <title>Internet -&gt; PA-440 -&gt; ASUS RT-AX53U AX1800. Error = Router does not get Internet access</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/internet-gt-pa-440-gt-asus-rt-ax53u-ax1800-error-router-does-not/m-p/573298#M2449</link>
      <description>&lt;P&gt;I have just purchased my first PaloAlto firewall. I am a sysadmin at a small office (about 20 people) and I am in the progress of setting up a new WiFi for my office.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is my equipment:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Firewall: &lt;SPAN&gt;PA-440&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Router: &lt;SPAN&gt;Asus&amp;nbsp;RT-AX53U AX1800&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;This is my current setting:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="01 PA-440 Drawing.png" style="width: 627px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56566iD004BFDE6F63AF57/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="01 PA-440 Drawing.png" alt="01 PA-440 Drawing.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have managed to connect to the PA-440 firewall by setting my network cards IP to 192.168.1.2.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What should I do in order to make my router get Internet? I have some screenshots of my setup here:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PA-440 Dashboard&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="02 PA-440 Dashboard.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56567i444D6C90587AC63F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="02 PA-440 Dashboard.png" alt="02 PA-440 Dashboard.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PA-440 Interfaces&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="03 PA-440 Interfaces.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56568i0F5494C7F4640ABD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="03 PA-440 Interfaces.png" alt="03 PA-440 Interfaces.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Asus&amp;nbsp;RT-AX53U AX1800&lt;/SPAN&gt; dashboard&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="10 Asus Dashboard.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56569iC5D3FA82C88F933A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="10 Asus Dashboard.png" alt="10 Asus Dashboard.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Asus&amp;nbsp;RT-AX53U AX1800 &lt;/SPAN&gt;LAN&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11 Asus LAN.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56570iC37B91ACBD15A96C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="11 Asus LAN.png" alt="11 Asus LAN.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Asus&amp;nbsp;RT-AX53U AX1800 &lt;/SPAN&gt;LAN&lt;/STRONG&gt; -&lt;STRONG&gt;&amp;gt; DHCP&lt;/STRONG&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="12 Asus DHCP.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56571iBA5DA3F688F02424/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="12 Asus DHCP.png" alt="12 Asus DHCP.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Asus&amp;nbsp;RT-AX53U AX1800&lt;/SPAN&gt; WAN&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="13 Asus Connection.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56572iC3F4BC0118E8F63A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="13 Asus Connection.png" alt="13 Asus Connection.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 09:00:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/internet-gt-pa-440-gt-asus-rt-ax53u-ax1800-error-router-does-not/m-p/573298#M2449</guid>
      <dc:creator>SoloSigma</dc:creator>
      <dc:date>2024-01-17T09:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: Internet -&gt; PA-440 -&gt; ASUS RT-AX53U AX1800. Error = Router does not get Internet access</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/internet-gt-pa-440-gt-asus-rt-ax53u-ax1800-error-router-does-not/m-p/573318#M2452</link>
      <description>&lt;P&gt;there's a good book you can read &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there's a lot of stuff you can do but let's start with the basics&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;create 2 new layer3 zones&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'd firstly set the interface 1/1 to layer 3 mode and set it as dhcp client. that should get you a public IP automatically from your ISP&lt;/P&gt;
&lt;P&gt;assign it the external zone&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_0-1705491902222.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56574i5CC05B5961A5CECF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="reaper_0-1705491902222.png" alt="reaper_0-1705491902222.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;next, set the ethernet1/2 as a layer3 interface and assign it an IP address (e.g. 192.168.50.1/24) , and enable a dhcp server on that interface, make sure you set the 192.168.50.1 IP as default route in the dhcp features&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_1-1705492035273.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56575i31910C2DD840B721/image-size/medium?v=v2&amp;amp;px=400" role="button" title="reaper_1-1705492035273.png" alt="reaper_1-1705492035273.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;now, it would be preferable if you can set your Asus in passthrough mode so it simply acts as an access point and not interfere with routing or additional NAT inside your network&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;don't forget to create a security rule that allows your new internal zone out to your new external zone (delete the rule that was already in place, fresh starts are better)&lt;/P&gt;
&lt;P&gt;make sure to add your subscription profiles!&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_2-1705492213885.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56576i8980A7CFF95BBC19/image-size/large?v=v2&amp;amp;px=999" role="button" title="reaper_2-1705492213885.png" alt="reaper_2-1705492213885.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;and lastly, create a NAT rule for your outbound traffic:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_3-1705492271967.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56577iE959FF6CFF409453/image-size/large?v=v2&amp;amp;px=999" role="button" title="reaper_3-1705492271967.png" alt="reaper_3-1705492271967.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to ensure your firewall is able to fetch updates, configure it with a DNS server in the management section, then consider setting up 'service routes'&amp;nbsp; (Device &amp;gt; setup &amp;gt; service &amp;gt; service routes) attached to your ethernet1/2 (as else the updates will be fetched via your managment interface which is currently not connected to anything)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_4-1705492548214.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56578i16511A468BA1D7C9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="reaper_4-1705492548214.png" alt="reaper_4-1705492548214.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 11:55:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/internet-gt-pa-440-gt-asus-rt-ax53u-ax1800-error-router-does-not/m-p/573318#M2452</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-01-17T11:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: Internet -&gt; PA-440 -&gt; ASUS RT-AX53U AX1800. Error = Router does not get Internet access</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/internet-gt-pa-440-gt-asus-rt-ax53u-ax1800-error-router-does-not/m-p/573352#M2460</link>
      <description>&lt;P&gt;Thank you for your help Reaper. Now my office have Internet via the PA-440 firewall. &lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 18:37:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/internet-gt-pa-440-gt-asus-rt-ax53u-ax1800-error-router-does-not/m-p/573352#M2460</guid>
      <dc:creator>SoloSigma</dc:creator>
      <dc:date>2024-01-17T18:37:11Z</dc:date>
    </item>
  </channel>
</rss>

