<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple External IPs to Multiple Firewalls in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ips-to-multiple-firewalls/m-p/441965#M100053</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;What do the logs on the PAN say as to why the traffic is getting blocked? Might want to put in a policy of something like this for the PAN:&lt;/P&gt;
&lt;P&gt;source zone untrust source ip&amp;nbsp;&lt;SPAN&gt;172.10.10.10/29 destination zone untrust destination ip&amp;nbsp;172.10.10.10/29 any application/any service action is allow&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Just a thought.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Oct 2021 17:49:07 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2021-10-19T17:49:07Z</dc:date>
    <item>
      <title>Multiple External IPs to Multiple Firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ips-to-multiple-firewalls/m-p/441936#M100051</link>
      <description>&lt;P&gt;I am sure this is going to be something simple, but I am admittedly stumped (not hard to do).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a block of External IP addresses assigned by our ISP , say&amp;nbsp; &amp;nbsp;172.10.10.10/29&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The gateway is 172.10.10.10 . This contains a single physical port . This is connected to a switch to allow distribution of multiple ports.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 firewalls attached.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewall one is assigned 172.10.10.11/29&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewall two is assigned 172.10.10.15/29&amp;nbsp; &amp;nbsp;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I add my new PA 850 with an external interface setting of 172.10.10.14/29, it blocks access to 172.10.10.15.&amp;nbsp; The other firewall on 172.10.10.11 is not affected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have created no static routes or NAT on the 850 at this point.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I set the external address of the 850 to 172.10.10.14/32. it still blocks 15.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I swap the IP addresses, that is, set the 850 to 172.10.10.15/29 and set Firewall2 to 172.10.10.14/29, it works.&amp;nbsp; So then all 3 firewalls are up.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could leave it at that. However a) I don't know why its blocking devices further down the IP address list and I would like to and b)&amp;nbsp; I have some public webservices pointing to the original IP address of 172.10.10.15 so would rather not change that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 16:09:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ips-to-multiple-firewalls/m-p/441936#M100051</guid>
      <dc:creator>peeryog</dc:creator>
      <dc:date>2021-10-19T16:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple External IPs to Multiple Firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ips-to-multiple-firewalls/m-p/441965#M100053</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;What do the logs on the PAN say as to why the traffic is getting blocked? Might want to put in a policy of something like this for the PAN:&lt;/P&gt;
&lt;P&gt;source zone untrust source ip&amp;nbsp;&lt;SPAN&gt;172.10.10.10/29 destination zone untrust destination ip&amp;nbsp;172.10.10.10/29 any application/any service action is allow&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Just a thought.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 17:49:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ips-to-multiple-firewalls/m-p/441965#M100053</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-10-19T17:49:07Z</dc:date>
    </item>
  </channel>
</rss>

