<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot ping inside interface from Windows PC with inside interface set as GW in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585901#M3115</link>
    <description>&lt;P&gt;Switch in-between is fine, just depends how everything is configured, is your switch just operating as a layer 2 switch or is the clients default gateway on the switch? Are you seeing the clients traffic appear in the traffic logs of the firewall or no?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would also recommend checking the global counters on the firewall, as if the traffic is hitting the firewall and then failing, there is a good chance these counters will provide a direction on where to look. KB article on this:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS" target="_blank"&gt;How to check global counters for a specific source and destinat... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 06 May 2024 19:21:30 GMT</pubDate>
    <dc:creator>Claw4609</dc:creator>
    <dc:date>2024-05-06T19:21:30Z</dc:date>
    <item>
      <title>Cannot ping inside interface from Windows PC with inside interface set as GW</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585891#M3112</link>
      <description>&lt;P&gt;I'm going a little bit crazy. I have a super simple setup, I have a Windows PC @&amp;nbsp;10.0.0.10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My PA 440 has 10.0.0.11 as its MGT Interface and all communications between the Windows PC and the management interface work fine. I have an inside interface set as eth 1/8 Layer 3 with an IP of 10.0.0.1 and its assigned to the inside zone. Eth 1/8 is also layer 3 and assigned to the outside zone. I created an interface management profile that allows Ping, ssh, http, and response pages and explicitly allows the 10.0.0.0/24 network. However, no matter what I do, I cannot ping from my PC to the actual data interface of the firewall. Its also not able to get out to the internet even though the outside interface is able to communicate with the internet. I have a security rule that allows inside to outside for any source and destination. What am I missing here??&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 18:09:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585891#M3112</guid>
      <dc:creator>donovanrodriguez1997</dc:creator>
      <dc:date>2024-05-06T18:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping inside interface from Windows PC with inside interface set as GW</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585899#M3113</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you see the attempted traffic in the firewalls traffic logs? If not, something to check would be the subnet mask of the client itself and make sure is 255.255.255.0 in your case. Secondly for the internet piece, is there a firewall rule allowing this traffic? Do you see this traffic in the firewall? If you see the traffic and its allowed, either your routing or your NAT rule may need to be whats looked at&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 19:10:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585899#M3113</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-05-06T19:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping inside interface from Windows PC with inside interface set as GW</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585900#M3114</link>
      <description>&lt;P&gt;The subnet mask is correct at 255.255.255.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My nat policy converts from inside -&amp;gt; outside using the ip address of the outside interface connecting to my ISP. Would having a C9200 Cisco switch in between the Firewall and the PC make any difference? The virtual router I have configured is assigned to my two interfaces and it just has one static route for 0.0.0.0/0 going out the outside interface with the next hop of the gateway for the network.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 19:14:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585900#M3114</guid>
      <dc:creator>donovanrodriguez1997</dc:creator>
      <dc:date>2024-05-06T19:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping inside interface from Windows PC with inside interface set as GW</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585901#M3115</link>
      <description>&lt;P&gt;Switch in-between is fine, just depends how everything is configured, is your switch just operating as a layer 2 switch or is the clients default gateway on the switch? Are you seeing the clients traffic appear in the traffic logs of the firewall or no?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would also recommend checking the global counters on the firewall, as if the traffic is hitting the firewall and then failing, there is a good chance these counters will provide a direction on where to look. KB article on this:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS" target="_blank"&gt;How to check global counters for a specific source and destinat... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 19:21:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585901#M3115</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-05-06T19:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping inside interface from Windows PC with inside interface set as GW</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585902#M3116</link>
      <description>&lt;P&gt;So I see the attempted pings from my PC to the firewall. The action is set to allow, but I'm still not getting anything back on my PC and I'm still not able to touch the internet, but my firewall is able to download updates...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 19:27:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585902#M3116</guid>
      <dc:creator>donovanrodriguez1997</dc:creator>
      <dc:date>2024-05-06T19:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping inside interface from Windows PC with inside interface set as GW</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585903#M3117</link>
      <description>&lt;P&gt;It the traffic is hitting the firewall I would refer to that KB article and check the counters if they can provide more information where to look.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 19:30:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585903#M3117</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-05-06T19:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping inside interface from Windows PC with inside interface set as GW</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585907#M3118</link>
      <description>&lt;P&gt;Here's what I get from that counter filter. I have a ping going to the gateway address running while I did the filter:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59538i607B21A1F5A50AF3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Image.jpg" alt="Image.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 19:41:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585907#M3118</guid>
      <dc:creator>donovanrodriguez1997</dc:creator>
      <dc:date>2024-05-06T19:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping inside interface from Windows PC with inside interface set as GW</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585908#M3119</link>
      <description>&lt;P&gt;Doesn't really seem to tell me that its dropping any packets or anything. I'm so confused...&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 19:42:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585908#M3119</guid>
      <dc:creator>donovanrodriguez1997</dc:creator>
      <dc:date>2024-05-06T19:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping inside interface from Windows PC with inside interface set as GW</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585909#M3120</link>
      <description>&lt;P&gt;On the firewall if you do "show routing route" do you see&amp;nbsp;&lt;SPAN&gt;10.0.0.0/24&amp;nbsp;as a directly connected route? Can you ping the machine sourcing from the firewall? ping source&amp;nbsp;10.0.0.1 host 10.0.0.10&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 19:45:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585909#M3120</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-05-06T19:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping inside interface from Windows PC with inside interface set as GW</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585917#M3121</link>
      <description>&lt;P&gt;It didn't exactly solve the issue but you helped me get there haha. I feel a bit stupid but I guess the syntax for applying the ip address is 10.0.0.1/24, I just had 10.0.0.1... gotta drink the humble tea every once n a while. Thanks a bunch dude.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 20:24:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-ping-inside-interface-from-windows-pc-with-inside/m-p/585917#M3121</guid>
      <dc:creator>donovanrodriguez1997</dc:creator>
      <dc:date>2024-05-06T20:24:37Z</dc:date>
    </item>
  </channel>
</rss>

