<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing issue with Palo alto in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issue-with-palo-alto/m-p/441860#M100038</link>
    <description>&lt;P&gt;Strangly,I realized that only 1 sub if is able to ping firewall.&amp;nbsp; firewall has three sub interface under aggregate 2.&lt;/P&gt;&lt;P&gt;Aggregate 2.31, ae2.32 and ae2.33&lt;/P&gt;&lt;P&gt;I am able to ping from ae2.32 connected router to firewall, but can not ping from other 2 sub interfaces connected router to firewall.&lt;/P&gt;&lt;P&gt;Same MGMT profile is used for all interfaces and A, B,C class ip addresses included in this MGMT profile.&lt;/P&gt;&lt;P&gt;Meanwhile, both devices are visible in the ARP table.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Oct 2021 06:11:52 GMT</pubDate>
    <dc:creator>AzerTurkBank</dc:creator>
    <dc:date>2021-10-19T06:11:52Z</dc:date>
    <item>
      <title>Routing issue with Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issue-with-palo-alto/m-p/441715#M100024</link>
      <description>&lt;P&gt;Hello everyone!&lt;/P&gt;&lt;P&gt;I am experiencing an odd problem.&lt;/P&gt;&lt;P&gt;I have 3250 HA pairs. I have configured 2 aggregate(L3 trunk) interfaces and added sub interfaces to these aggregate.&lt;/P&gt;&lt;P&gt;The first problem is the firewall itself can not ping directly connected device by using "ping source x.x.x.x host y.y.y.y" command.&lt;/P&gt;&lt;P&gt;Every sub interface has management profile assigned.&lt;/P&gt;&lt;P&gt;The each aggregate interfaces has connected to 2 cisco stack switches.(switchstack1---aggregate1-aggregate2---switch-stack2)&lt;/P&gt;&lt;P&gt;I set IP addresses on both switches, however, there is not connection between two switches even though they have default route towards palo alto. I can not even ping from switch to palo alto interface.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 17:59:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issue-with-palo-alto/m-p/441715#M100024</guid>
      <dc:creator>AzerTurkBank</dc:creator>
      <dc:date>2021-10-18T17:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Routing issue with Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issue-with-palo-alto/m-p/441819#M100029</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/143296"&gt;@AzerTurkBank&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you ping from Active PA?&lt;/P&gt;
&lt;P&gt;Did this ever worked before?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is both interfaces show up on PA and Cisco?&lt;/P&gt;
&lt;P&gt;In MGMT Interface is Ping allowed ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which source IP you are using to ping Cisco Switch?&lt;/P&gt;
&lt;P&gt;You need to use PA interface IP to ping the Cisco Switch directly connected interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 01:45:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issue-with-palo-alto/m-p/441819#M100029</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2021-10-19T01:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Routing issue with Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issue-with-palo-alto/m-p/441843#M100032</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/143296"&gt;@AzerTurkBank&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;That honestly sounds like you either don't have ping enabled on the interface-management-profile&amp;nbsp;&lt;EM&gt;or&amp;nbsp;&lt;/EM&gt;you have permitted-ip setup on the profile and the IPs your attempting to ping aren't included.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 03:15:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issue-with-palo-alto/m-p/441843#M100032</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-10-19T03:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: Routing issue with Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issue-with-palo-alto/m-p/441856#M100036</link>
      <description>&lt;P&gt;Are you ping from Active PA?&lt;/P&gt;&lt;P&gt;To tell the truth, no. the first problem has fixed thanks to you.&lt;/P&gt;&lt;P&gt;Did this ever worked before?(this is new deployment)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is both interfaces show up on PA and Cisco?(Yes)&lt;/P&gt;&lt;P&gt;In MGMT Interface is Ping allowed ? Yes- it is allowed.&lt;/P&gt;&lt;P&gt;it seems switch was L2 and there was routing issue. I changed the switch to router and it responded ping packets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 05:50:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issue-with-palo-alto/m-p/441856#M100036</guid>
      <dc:creator>AzerTurkBank</dc:creator>
      <dc:date>2021-10-19T05:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Routing issue with Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issue-with-palo-alto/m-p/441858#M100037</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;IP addresses allowed in MGMT profile are 10.0.0.0/8. 172.16.0.0./12 and 192.168.0.0./16&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 06:07:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issue-with-palo-alto/m-p/441858#M100037</guid>
      <dc:creator>AzerTurkBank</dc:creator>
      <dc:date>2021-10-19T06:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: Routing issue with Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issue-with-palo-alto/m-p/441860#M100038</link>
      <description>&lt;P&gt;Strangly,I realized that only 1 sub if is able to ping firewall.&amp;nbsp; firewall has three sub interface under aggregate 2.&lt;/P&gt;&lt;P&gt;Aggregate 2.31, ae2.32 and ae2.33&lt;/P&gt;&lt;P&gt;I am able to ping from ae2.32 connected router to firewall, but can not ping from other 2 sub interfaces connected router to firewall.&lt;/P&gt;&lt;P&gt;Same MGMT profile is used for all interfaces and A, B,C class ip addresses included in this MGMT profile.&lt;/P&gt;&lt;P&gt;Meanwhile, both devices are visible in the ARP table.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 06:11:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issue-with-palo-alto/m-p/441860#M100038</guid>
      <dc:creator>AzerTurkBank</dc:creator>
      <dc:date>2021-10-19T06:11:52Z</dc:date>
    </item>
  </channel>
</rss>

