<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VM Series and Azure Stack Hub - Routing problem? in VM-Series in the Private Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/vm-series-and-azure-stack-hub-routing-problem/m-p/485495#M32</link>
    <description>&lt;P&gt;All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having a frustrating time with VM-Series integration inside an Azure Stack Hub (2108, Disconnected) - Setup is as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;Installed from 8.1 marketplace image using basic 3 NIC template - then upgraded (in many stages) to 10.2.1.&lt;/P&gt;&lt;P&gt;&amp;gt;Single firewall is positioned in hub VNet, with bidirectional VNet peering to the hosting VNets. No load balancer.&lt;/P&gt;&lt;P&gt;&amp;gt;The firewall has static routes in place (in a single virtual router) to the 'router' address of each subnet on the hosting VNets. (i.e network addr +1)&lt;/P&gt;&lt;P&gt;&amp;gt;A routing table is in place for all subnets required, pointing them to the trusted interface IP.&lt;/P&gt;&lt;P&gt;&amp;gt;No NSGs are in place on the hosting VNets.&lt;/P&gt;&lt;P&gt;&amp;gt;An intra-zone rule is in place to allow all traffic&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Testing reveals that:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;The firewall can ping all the hosts in the hosting VNets through the trusted interface.&lt;/P&gt;&lt;P&gt;&amp;gt;Prior to enabling the route table in Azure, hosts pinging the trusted firewall interface do not get a reply, but are shown in the traffic log.&lt;/P&gt;&lt;P&gt;&amp;gt;After enabling the full redirection via the trusted firewall interface, attempts to contact hosts on other VNets or subnets in the system fail, but the traffic is seen (as allowed) in the firewall log. Nothing gets through or re-routed though - I have tried with and without a noNAT to make sure that wasn't the issue.&lt;/P&gt;&lt;P&gt;&amp;gt;A packet capture reveals the firewall sending ARPs for the address of the subnet router addresses - but cannot see if it gets a reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what do we think is happening here? It's like the firewall isn't able to reach the router address in the subnet, even though I can see that it can.&lt;/P&gt;&lt;P&gt;Have I missed something? Asymmetric routing perhaps?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 May 2022 19:30:58 GMT</pubDate>
    <dc:creator>Rob_Stevens</dc:creator>
    <dc:date>2022-05-06T19:30:58Z</dc:date>
    <item>
      <title>VM Series and Azure Stack Hub - Routing problem?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/vm-series-and-azure-stack-hub-routing-problem/m-p/485495#M32</link>
      <description>&lt;P&gt;All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having a frustrating time with VM-Series integration inside an Azure Stack Hub (2108, Disconnected) - Setup is as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;Installed from 8.1 marketplace image using basic 3 NIC template - then upgraded (in many stages) to 10.2.1.&lt;/P&gt;&lt;P&gt;&amp;gt;Single firewall is positioned in hub VNet, with bidirectional VNet peering to the hosting VNets. No load balancer.&lt;/P&gt;&lt;P&gt;&amp;gt;The firewall has static routes in place (in a single virtual router) to the 'router' address of each subnet on the hosting VNets. (i.e network addr +1)&lt;/P&gt;&lt;P&gt;&amp;gt;A routing table is in place for all subnets required, pointing them to the trusted interface IP.&lt;/P&gt;&lt;P&gt;&amp;gt;No NSGs are in place on the hosting VNets.&lt;/P&gt;&lt;P&gt;&amp;gt;An intra-zone rule is in place to allow all traffic&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Testing reveals that:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;The firewall can ping all the hosts in the hosting VNets through the trusted interface.&lt;/P&gt;&lt;P&gt;&amp;gt;Prior to enabling the route table in Azure, hosts pinging the trusted firewall interface do not get a reply, but are shown in the traffic log.&lt;/P&gt;&lt;P&gt;&amp;gt;After enabling the full redirection via the trusted firewall interface, attempts to contact hosts on other VNets or subnets in the system fail, but the traffic is seen (as allowed) in the firewall log. Nothing gets through or re-routed though - I have tried with and without a noNAT to make sure that wasn't the issue.&lt;/P&gt;&lt;P&gt;&amp;gt;A packet capture reveals the firewall sending ARPs for the address of the subnet router addresses - but cannot see if it gets a reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what do we think is happening here? It's like the firewall isn't able to reach the router address in the subnet, even though I can see that it can.&lt;/P&gt;&lt;P&gt;Have I missed something? Asymmetric routing perhaps?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 19:30:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/vm-series-and-azure-stack-hub-routing-problem/m-p/485495#M32</guid>
      <dc:creator>Rob_Stevens</dc:creator>
      <dc:date>2022-05-06T19:30:58Z</dc:date>
    </item>
  </channel>
</rss>

