<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISP ping going out via different interface in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/isp-ping-going-out-via-different-interface/m-p/527911#M788</link>
    <description>&lt;P&gt;I am facing a very strange issue. Thee are four ISP connected to PA. All are VLAN interfaces.&lt;/P&gt;
&lt;P&gt;While doing a ping to 8.8.8.8 or any public IP from the vlan interface IP it works fine except for one ISP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For one ISP if a ping a initiated from vlan.7 the traffic goes out via vlan.3. attached a screenshot.&lt;/P&gt;
&lt;P&gt;Ping is initiated from PA cli - ping source &amp;lt;int ip&amp;gt; host 8.8.8.8&lt;/P&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pingPA.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47267iA813179B25DDA6E2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="pingPA.jpg" alt="pingPA.jpg" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Any idea why ping is going via a different interface?&lt;/DIV&gt;&lt;BR /&gt;&lt;BR /&gt;Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.</description>
    <pubDate>Fri, 20 Jan 2023 06:35:57 GMT</pubDate>
    <dc:creator>ceapen01</dc:creator>
    <dc:date>2023-01-20T06:35:57Z</dc:date>
    <item>
      <title>ISP ping going out via different interface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/isp-ping-going-out-via-different-interface/m-p/527911#M788</link>
      <description>&lt;P&gt;I am facing a very strange issue. Thee are four ISP connected to PA. All are VLAN interfaces.&lt;/P&gt;
&lt;P&gt;While doing a ping to 8.8.8.8 or any public IP from the vlan interface IP it works fine except for one ISP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For one ISP if a ping a initiated from vlan.7 the traffic goes out via vlan.3. attached a screenshot.&lt;/P&gt;
&lt;P&gt;Ping is initiated from PA cli - ping source &amp;lt;int ip&amp;gt; host 8.8.8.8&lt;/P&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pingPA.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47267iA813179B25DDA6E2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="pingPA.jpg" alt="pingPA.jpg" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Any idea why ping is going via a different interface?&lt;/DIV&gt;&lt;BR /&gt;&lt;BR /&gt;Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.</description>
      <pubDate>Fri, 20 Jan 2023 06:35:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/isp-ping-going-out-via-different-interface/m-p/527911#M788</guid>
      <dc:creator>ceapen01</dc:creator>
      <dc:date>2023-01-20T06:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ping going out via different interface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/isp-ping-going-out-via-different-interface/m-p/528045#M794</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/177752"&gt;@ceapen01&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi, check if you have&lt;BR /&gt;ECMP that could be balancing the traffic.&lt;/P&gt;
&lt;P&gt;Or check if you have any PBF policy that is forcing that traffic flow through that other interface.&lt;/P&gt;
&lt;P&gt;Check that by any chance at virtualrouter level is not set an explicit route against that destination.&lt;/P&gt;
&lt;P&gt;Another thing the PBF will not manipulate the traffic coming from the FW, that is to say in this case the IP source of vlan 7 that you mention, it will always use the route with the best metric (the one with the lowest metric).&lt;/P&gt;
&lt;P&gt;Check if the same thing happens with an end equipment, an endpoint of vlan 7 and you will get better conclusions of the behavior.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 05:21:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/isp-ping-going-out-via-different-interface/m-p/528045#M794</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2023-01-21T05:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ping going out via different interface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/isp-ping-going-out-via-different-interface/m-p/528057#M795</link>
      <description>&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;ECMP that could be balancing the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;gt;&amp;gt;&lt;EM&gt;I didn't understand this point&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Or check if you have any PBF policy that is forcing that traffic flow through that other interface.&lt;BR /&gt;&amp;nbsp; &amp;gt;&amp;gt;&lt;EM&gt;No PBF&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Check that by any chance at virtualrouter level is not set an explicit route against that destination.&lt;BR /&gt;&amp;nbsp; &amp;gt;&amp;gt;&lt;EM&gt;As there are four ISP, four default routes exist with different metric&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Another thing the PBF will not manipulate the traffic coming from the FW, that is to say in this case the IP source of vlan 7 that you mention, it will always use the route with the best metric (the one with the lowest metric).&lt;/P&gt;
&lt;P&gt;Check if the same thing happens with an end equipment, an endpoint of vlan 7 and you will get better conclusions of the behavior.&lt;BR /&gt;&amp;nbsp; &amp;gt;&amp;gt;&lt;EM&gt;endpoint of vlan 7 gets internet and ping. No issues.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 10:45:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/isp-ping-going-out-via-different-interface/m-p/528057#M795</guid>
      <dc:creator>ceapen01</dc:creator>
      <dc:date>2023-01-21T10:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ping going out via different interface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/isp-ping-going-out-via-different-interface/m-p/528063#M796</link>
      <description>&lt;P&gt;As already mentioned PBF will not be applied to traffic sourcing from firewall itself.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you ping from public IP to next hop then you can expect traffic to go out from same interface (because it stays inside same subnet).&lt;/P&gt;
&lt;P&gt;If you ping from public IP to IP on the internet then you must have static route configured towards that public IP.&lt;/P&gt;
&lt;P&gt;Otherwise Palo will look at static routes.&lt;/P&gt;
&lt;P&gt;If multiple 0.0.0.0/0 routes have same metric (ECMP is enabled) then source interface is chosen based on ECMP settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So Palo will not care that you ping from specific vlan IP. Path is chosen based on virtual router configuration.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 17:08:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/isp-ping-going-out-via-different-interface/m-p/528063#M796</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-21T17:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ping going out via different interface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/isp-ping-going-out-via-different-interface/m-p/528079#M797</link>
      <description>&lt;P&gt;there are different static routes to 0.0.0.0 with different metrics. I can see ping to 8.8.8.8 from vlan 7 is now taking the interface with lowest metric (vlan3).&lt;/P&gt;
&lt;P&gt;Is there any method such that ping to 8.8.8.8 from vlan 7 interface wd only egress through vlan 7 only.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;**furthermore i can this is only happening with vlan 7. If ping from vlan 4 or 5, traffic egress via that interface only.&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jan 2023 09:00:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/isp-ping-going-out-via-different-interface/m-p/528079#M797</guid>
      <dc:creator>ceapen01</dc:creator>
      <dc:date>2023-01-22T09:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ping going out via different interface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/isp-ping-going-out-via-different-interface/m-p/528086#M798</link>
      <description>&lt;P&gt;No.&lt;/P&gt;
&lt;P&gt;Traffic always uses interface with that has lowest metric route.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need more specific static route towards 8.8.8.8 to send traffic towards 8.8.8.8 out from vlan 7 (if vlan 7 don't have lowest metric) for traffic sourcing from the firewall.&lt;/P&gt;
&lt;P&gt;For traffic passing firewall (sourced from workstations/servers) you can use either static route or PBF (PBF is checked first and if no PBF then virtual router is checked for routing decision).&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jan 2023 16:06:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/isp-ping-going-out-via-different-interface/m-p/528086#M798</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-22T16:06:44Z</dc:date>
    </item>
  </channel>
</rss>

