<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to make Router BGP ping into IP inside Palo Alto in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-make-router-bgp-ping-into-ip-inside-palo-alto/m-p/1251290#M6808</link>
    <description>&lt;P&gt;I'm sorry, it just the error from switch core image on STL-CORE-01. I'm using different image cisco and success to ping ptp ip paloalto from Router BGP. Thank you&lt;/P&gt;</description>
    <pubDate>Tue, 31 Mar 2026 10:41:03 GMT</pubDate>
    <dc:creator>Mikhailzd</dc:creator>
    <dc:date>2026-03-31T10:41:03Z</dc:date>
    <item>
      <title>How to make Router BGP ping into IP inside Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-make-router-bgp-ping-into-ip-inside-palo-alto/m-p/1251215#M6806</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mikhailzd_0-1774930708413.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71075iABB071F313963E56/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Mikhailzd_0-1774930708413.png" alt="Mikhailzd_0-1774930708413.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good Afternoon guys, how i could reach network 10.100.111.0/24 inside Palo Alto from Router BGP? i have success to get routing table of 10.100.111.0/24 from Router BGP, but unfortunately i can't ping into gateway of 10.100.111.252/24. How to solve this? Thank you&lt;BR /&gt;&lt;BR /&gt;This is route inside Router BGP :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mikhailzd_1-1774930782934.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71076i2A8364947DA7CB79/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Mikhailzd_1-1774930782934.png" alt="Mikhailzd_1-1774930782934.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And this is Configuration Inside STL-CORE-01 :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;STL-CORE-01#show running-config&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 3705 bytes&lt;BR /&gt;!&lt;BR /&gt;! Last configuration change at 04:18:40 UTC Tue Mar 31 2026&lt;BR /&gt;!&lt;BR /&gt;version 15.2&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;no service password-encryption&lt;BR /&gt;service compress-config&lt;BR /&gt;!&lt;BR /&gt;hostname STL-CORE-01&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;no aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip cef&lt;BR /&gt;no ipv6 cef&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;spanning-tree mode rapid-pvst&lt;BR /&gt;spanning-tree extend system-id&lt;BR /&gt;!&lt;BR /&gt;vlan internal allocation policy ascending&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;media-type rj45&lt;BR /&gt;negotiation auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;media-type rj45&lt;BR /&gt;negotiation auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/3&lt;BR /&gt;media-type rj45&lt;BR /&gt;negotiation auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt;no switchport&lt;BR /&gt;no ip address&lt;BR /&gt;duplex full&lt;BR /&gt;no negotiation auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0.39&lt;BR /&gt;encapsulation dot1Q 39&lt;BR /&gt;ip address 10.200.200.137 255.255.255.248&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0&lt;BR /&gt;switchport trunk allowed vlan 44&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;media-type rj45&lt;BR /&gt;negotiation auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/1&lt;BR /&gt;media-type rj45&lt;BR /&gt;negotiation auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/2&lt;BR /&gt;media-type rj45&lt;BR /&gt;negotiation auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;media-type rj45&lt;BR /&gt;negotiation auto&lt;BR /&gt;!&lt;BR /&gt;interface Vlan44&lt;BR /&gt;ip address 10.200.200.193 255.255.255.248&lt;BR /&gt;!&lt;BR /&gt;router bgp 65549&lt;BR /&gt;bgp router-id 10.200.200.137&lt;BR /&gt;bgp log-neighbor-changes&lt;BR /&gt;redistribute connected route-map STATIC-TO-BGP&lt;BR /&gt;redistribute static&lt;BR /&gt;neighbor 10.200.200.140 remote-as 65550&lt;BR /&gt;!&lt;BR /&gt;ip forward-protocol nd&lt;BR /&gt;!&lt;BR /&gt;no ip http server&lt;BR /&gt;no ip http secure-server&lt;BR /&gt;!&lt;BR /&gt;ip route 10.32.4.0 255.255.255.0 10.200.200.194&lt;BR /&gt;ip route 10.100.111.0 255.255.255.0 10.200.200.194&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip prefix-list STATIC-TO-BGP seq 1 permit 10.200.200.192/29&lt;BR /&gt;!&lt;BR /&gt;route-map STATIC-TO-BGP permit 10&lt;BR /&gt;match ip address prefix-list STATIC-TO-BGP&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;control-plane&lt;BR /&gt;!&lt;BR /&gt;banner exec ^C&lt;BR /&gt;**************************************************************************&lt;BR /&gt;* IOSv is strictly limited to use for evaluation, demonstration and IOS *&lt;BR /&gt;* education. IOSv is provided as-is and is not supported by Cisco's *&lt;BR /&gt;* Technical Advisory Center. Any use or disclosure, in whole or in part, *&lt;BR /&gt;* of the IOSv Software or Documentation to any third party for any *&lt;BR /&gt;* purposes is expressly prohibited except as otherwise authorized by *&lt;BR /&gt;* Cisco in writing. *&lt;BR /&gt;**************************************************************************^C&lt;BR /&gt;banner incoming ^C&lt;BR /&gt;**************************************************************************&lt;BR /&gt;* IOSv is strictly limited to use for evaluation, demonstration and IOS *&lt;BR /&gt;* education. IOSv is provided as-is and is not supported by Cisco's *&lt;BR /&gt;* Technical Advisory Center. Any use or disclosure, in whole or in part, *&lt;BR /&gt;* of the IOSv Software or Documentation to any third party for any *&lt;BR /&gt;* purposes is expressly prohibited except as otherwise authorized by *&lt;BR /&gt;* Cisco in writing. *&lt;BR /&gt;**************************************************************************^C&lt;BR /&gt;banner login ^C&lt;BR /&gt;**************************************************************************&lt;BR /&gt;* IOSv is strictly limited to use for evaluation, demonstration and IOS *&lt;BR /&gt;* education. IOSv is provided as-is and is not supported by Cisco's *&lt;BR /&gt;* Technical Advisory Center. Any use or disclosure, in whole or in part, *&lt;BR /&gt;* of the IOSv Software or Documentation to any third party for any *&lt;BR /&gt;* purposes is expressly prohibited except as otherwise authorized by *&lt;BR /&gt;* Cisco in writing. *&lt;BR /&gt;**************************************************************************^C&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;line aux 0&lt;BR /&gt;line vty 0 4&lt;BR /&gt;login&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And this is the IP &amp;amp; Security inside PALOALTO :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mikhailzd_2-1774930921598.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71077i8548B7D2AED12608/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Mikhailzd_2-1774930921598.png" alt="Mikhailzd_2-1774930921598.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mikhailzd_3-1774930940370.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71078i1D057673E466B0FE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Mikhailzd_3-1774930940370.png" alt="Mikhailzd_3-1774930940370.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 04:22:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-make-router-bgp-ping-into-ip-inside-palo-alto/m-p/1251215#M6806</guid>
      <dc:creator>Mikhailzd</dc:creator>
      <dc:date>2026-03-31T04:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to make Router BGP ping into IP inside Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-make-router-bgp-ping-into-ip-inside-palo-alto/m-p/1251231#M6807</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/324305"&gt;@Mikhailzd&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does management profile on Palo Alto's L3 interface allow ping? Here is a reference:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMmCAK" target="_self"&gt;How to Allow Ping and ICMP on Layer 3 Interface of Your Palo Alto Networks Device&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does Palo Alto has a route back to the switch?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 05:28:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-make-router-bgp-ping-into-ip-inside-palo-alto/m-p/1251231#M6807</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2026-03-31T05:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to make Router BGP ping into IP inside Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-make-router-bgp-ping-into-ip-inside-palo-alto/m-p/1251290#M6808</link>
      <description>&lt;P&gt;I'm sorry, it just the error from switch core image on STL-CORE-01. I'm using different image cisco and success to ping ptp ip paloalto from Router BGP. Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 10:41:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-make-router-bgp-ping-into-ip-inside-palo-alto/m-p/1251290#M6808</guid>
      <dc:creator>Mikhailzd</dc:creator>
      <dc:date>2026-03-31T10:41:03Z</dc:date>
    </item>
  </channel>
</rss>

