<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I need routing between two internal networks in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/i-need-routing-between-two-internal-networks/m-p/525045#M702</link>
    <description>&lt;P&gt;Hi Mr. Young you are right it is the firewall settings at 192.168.20.31 . Thank you so much I've been stuck with this problem for 3 days and now I can get on with my work!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 24 Dec 2022 12:53:26 GMT</pubDate>
    <dc:creator>ArtemTokarenko</dc:creator>
    <dc:date>2022-12-24T12:53:26Z</dc:date>
    <item>
      <title>I need routing between two internal networks</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/i-need-routing-between-two-internal-networks/m-p/525041#M700</link>
      <description>&lt;P&gt;Hi !&lt;/P&gt;
&lt;PRE class="tw-data-text tw-text-large tw-ta" dir="ltr" data-placeholder="Перевод"&gt;&lt;SPAN class="Y2IQFc"&gt;I have a problem with setting up a static route between two internal networks.

There is a networks &lt;BR /&gt;192.168.10.0/24
192.168.20.0/24
192.168.30.0/24
I want to ping between
PC1 192.168.10.30/24
PC2 192.168.20.31/24

I can't figure out what I'm doing wrong&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;PRE id="tw-target-text" class="tw-data-text tw-text-large tw-ta" dir="ltr" data-placeholder="Перевод"&gt;&lt;SPAN class="Y2IQFc"&gt;Considering that machines from the inside have access to the Internet&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;PRE id="tw-target-text" class="tw-data-text tw-text-large tw-ta" dir="ltr" data-placeholder="Перевод"&gt;&lt;SPAN class="Y2IQFc"&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1PC.jpeg" style="width: 827px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46394i527F527B57C7F8FF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1PC.jpeg" alt="1PC.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2PC.jpeg" style="width: 583px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46395iAD8C7E8DA25FF7A9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2PC.jpeg" alt="2PC.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_Network_VR.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46401i23626F7D6E171C11/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_Network_VR.jpeg" alt="PA_Network_VR.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_Network_Interface.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46403iAB16054059803AE2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_Network_Interface.jpeg" alt="PA_Network_Interface.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_Metwork_InterfaceMgmt.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46404i4F94FFCABE72E8DD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_Metwork_InterfaceMgmt.jpeg" alt="PA_Metwork_InterfaceMgmt.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_Policy_NAT.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46405i1BEACAF8A5E1103F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_Policy_NAT.jpeg" alt="PA_Policy_NAT.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_Policy_Security.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46406i2D4CAF0996FE7058/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_Policy_Security.jpeg" alt="PA_Policy_Security.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 24 Dec 2022 10:08:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/i-need-routing-between-two-internal-networks/m-p/525041#M700</guid>
      <dc:creator>ArtemTokarenko</dc:creator>
      <dc:date>2022-12-24T10:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: I need routing between two internal networks</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/i-need-routing-between-two-internal-networks/m-p/525044#M701</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/253447"&gt;@ArtemTokarenko&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the detailed information and screen shots.&amp;nbsp; They are very helpful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your pings demonstrate that L2 connectivity is good.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The 1st thing you can do is delete static routes 10 and 20.&amp;nbsp; They are not needed.&amp;nbsp; If you look at More Runtime Stats to the right of your virtual router config, you will see those routes already exist as (A)ctive and (C)onnected.&amp;nbsp; Simply put, the NGFW knows how to route between connected subnets.&amp;nbsp; (You can also delete your disabled NAT rules.&amp;nbsp; They are not needed.)&lt;/LI&gt;
&lt;LI&gt;The 2nd thing you need to do is verify the traffic is going through your NGFW under Monitor &amp;gt; Logs &amp;gt; Traffic.&amp;nbsp; Once you find the traffic logs, you can examine them to see if the NGFW is forwarding the traffic correctly.&lt;/LI&gt;
&lt;LI&gt;If the NGFW is forwarding traffic correctly, then it is another issue (Windows firewall, etc.).&lt;/LI&gt;
&lt;LI&gt;If you do not see the traffic logs, you should enable logging for your default rules by highlighting each rule, selecting Override, and enabling logging.&amp;nbsp; Then traffic that hits those rules will also show in the logs.&amp;nbsp; For example, traffic dropped by the NGFW will hit the interzone-default rule.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sat, 24 Dec 2022 12:18:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/i-need-routing-between-two-internal-networks/m-p/525044#M701</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-12-24T12:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: I need routing between two internal networks</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/i-need-routing-between-two-internal-networks/m-p/525045#M702</link>
      <description>&lt;P&gt;Hi Mr. Young you are right it is the firewall settings at 192.168.20.31 . Thank you so much I've been stuck with this problem for 3 days and now I can get on with my work!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Dec 2022 12:53:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/i-need-routing-between-two-internal-networks/m-p/525045#M702</guid>
      <dc:creator>ArtemTokarenko</dc:creator>
      <dc:date>2022-12-24T12:53:26Z</dc:date>
    </item>
  </channel>
</rss>

