<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Ping Public IP on PA500 Interface from same PA Untrust Interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-ping-public-ip-on-pa500-interface-from-same-pa-untrust/m-p/13655#M10023</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I appreciate the help everybody. Thanks Steven your explanation and example, it helped me understand the problem and fix it. I am now able to ping the PA public IP address from inside the untrust Guest Wifi network as well as still get out to the internet. In the end I created two NATs. 1 for outbound traffic and one for traffic to the PA public IP address (Uturn NAT &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;). Just as a reference for others who may wander upon this discussion I've added a screen shot of my configs. The parts I blacked out are the places I added the public IP address of the untrust interface for my internet connection (the public IP I am attempting to ping).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2012-12-12 at 9.32.14 AM.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4903_Screen Shot 2012-12-12 at 9.32.14 AM.png" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Dec 2012 16:39:42 GMT</pubDate>
    <dc:creator>mario11584</dc:creator>
    <dc:date>2012-12-12T16:39:42Z</dc:date>
    <item>
      <title>How to Ping Public IP on PA500 Interface from same PA Untrust Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-ping-public-ip-on-pa500-interface-from-same-pa-untrust/m-p/13651#M10019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Currently we have a Guest Wireless network setup behind our PA. We'd like to use this network as a test network as well, for certain projects we are working on, to act as if it was outside the network. I have done this in the past with other vendor firewalls but I have not been successful in making this happen on a Palo Alto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now, when I connect to this network I am unable to ping the public IP address of the PA firewall. Management is configured to allow ping on that interface. NAT rules and policy based forwarding look okay too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas on how to troubleshoot this or fix the issue would be greatly appreciated. I am new to Palo Alto so go easy on me &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2012 16:15:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-ping-public-ip-on-pa500-interface-from-same-pa-untrust/m-p/13651#M10019</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2012-12-11T16:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to Ping Public IP on PA500 Interface from same PA Untrust Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-ping-public-ip-on-pa500-interface-from-same-pa-untrust/m-p/13652#M10020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dave&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just took a stab at this, and get something to work, so you may want to adjust as it fits your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a TRUST and UNTRUST Zone (as you may have also).&lt;/P&gt;&lt;P&gt;My TrustZone is my internal network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My NAT rule was TrustL3 to UntrustL3, (DestIP of PublicFW_IP) (Translation of:&amp;nbsp; Orignal Zone, Orignal Zone, NAT of Src and Dest = NONE)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So when my PC in my trusted network, pings the untrusted public IP of my FW, it does not NAT.&lt;/P&gt;&lt;P&gt;This worked for me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, I am not sure if your wireless network is in the SAME Untrust Zone as your Public IP.&lt;/P&gt;&lt;P&gt;To match my setup, maybe your Wireless Nework could be DMZZone (or similar)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then when you ping from your DMZZone to your UntrustL3Zone (with DestIP of your PublicIP) do not NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Play around, but I think this is very close to what you need to do.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 02:50:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-ping-public-ip-on-pa500-interface-from-same-pa-untrust/m-p/13652#M10020</guid>
      <dc:creator>scantwell</dc:creator>
      <dc:date>2012-12-12T02:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to Ping Public IP on PA500 Interface from same PA Untrust Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-ping-public-ip-on-pa500-interface-from-same-pa-untrust/m-p/13653#M10021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To make ping work you will probably need to create a mgmt-profile (only containing ping) which you attach to untrust and then a security rule which will allow the U-turn NAT to ping this interface from the other zone.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 13:30:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-ping-public-ip-on-pa500-interface-from-same-pa-untrust/m-p/13653#M10021</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-12-12T13:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to Ping Public IP on PA500 Interface from same PA Untrust Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-ping-public-ip-on-pa500-interface-from-same-pa-untrust/m-p/13654#M10022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mike, how about a good description of what UTurn NAT is, how it is used, etc.&amp;nbsp; Some ppl may not understand.&amp;nbsp; Just a thought.&amp;nbsp; :smileysilly: &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 13:38:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-ping-public-ip-on-pa500-interface-from-same-pa-untrust/m-p/13654#M10022</guid>
      <dc:creator>scantwell</dc:creator>
      <dc:date>2012-12-12T13:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to Ping Public IP on PA500 Interface from same PA Untrust Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-ping-public-ip-on-pa500-interface-from-same-pa-untrust/m-p/13655#M10023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I appreciate the help everybody. Thanks Steven your explanation and example, it helped me understand the problem and fix it. I am now able to ping the PA public IP address from inside the untrust Guest Wifi network as well as still get out to the internet. In the end I created two NATs. 1 for outbound traffic and one for traffic to the PA public IP address (Uturn NAT &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;). Just as a reference for others who may wander upon this discussion I've added a screen shot of my configs. The parts I blacked out are the places I added the public IP address of the untrust interface for my internet connection (the public IP I am attempting to ping).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2012-12-12 at 9.32.14 AM.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4903_Screen Shot 2012-12-12 at 9.32.14 AM.png" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 16:39:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-ping-public-ip-on-pa500-interface-from-same-pa-untrust/m-p/13655#M10023</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2012-12-12T16:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to Ping Public IP on PA500 Interface from same PA Untrust Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-ping-public-ip-on-pa500-interface-from-same-pa-untrust/m-p/13656#M10024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess this doc would answer all your NAT related questions &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="1517" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 20:29:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-ping-public-ip-on-pa500-interface-from-same-pa-untrust/m-p/13656#M10024</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-12-12T20:29:23Z</dc:date>
    </item>
  </channel>
</rss>

