<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: A connection issue between PA and SW in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454279#M101450</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203590"&gt;@DavidyPalo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could you click on green gear icon and press override?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1639974024459.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38228i499F83F5724F6125/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PavelK_0-1639974024459.png" alt="PavelK_0-1639974024459.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;then you will be able to edit and commit the change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
    <pubDate>Mon, 20 Dec 2021 04:21:09 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2021-12-20T04:21:09Z</dc:date>
    <item>
      <title>A connection issue between PA and SW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454233#M101442</link>
      <description>&lt;P&gt;Hi, PA port e1/2 is connected to switch port f1/5(L3). Both devices can see each other's ip and mac address. The Virtual router and Security zone and Magagement profile Ping are configured. but both devices cannot ping each other. Did I miss some step? Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Dec 2021 17:31:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454233#M101442</guid>
      <dc:creator>DavidyPalo</dc:creator>
      <dc:date>2021-12-19T17:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: A connection issue between PA and SW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454256#M101444</link>
      <description>&lt;P&gt;Thank you for post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203590"&gt;@DavidyPalo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By default Firewall is using management interface for ping. If you want to verify reachability of data plane interface you can change source: ping source &amp;lt;int 1/2 ip address&amp;gt; host &amp;lt;destination ip&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Sun, 19 Dec 2021 21:03:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454256#M101444</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-12-19T21:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: A connection issue between PA and SW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454261#M101445</link>
      <description>&lt;P&gt;Thank you for your reply! Now PA can ping SW, but the SW cannot ping PA. Maybe its default router configuration issue?&lt;/P&gt;&lt;P&gt;PA e1/2 10.200.255.1/24 ------------f1/5 SW 10.200.255.2/24&lt;/P&gt;&lt;P&gt;Below is virtual router vRTR-INET-Core:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DavidyPalo_0-1639955826500.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38224iBDF52B5F68A80DD1/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DavidyPalo_0-1639955826500.png" alt="DavidyPalo_0-1639955826500.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Dec 2021 23:21:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454261#M101445</guid>
      <dc:creator>DavidyPalo</dc:creator>
      <dc:date>2021-12-19T23:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: A connection issue between PA and SW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454263#M101446</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203590"&gt;@DavidyPalo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since you can ping Switch from Firewall and it is directly connected link, there should be no issue with routing. Have you checked Firewall's Traffic log to confirm ICMP arrives Firewall? Unless you have custom rule, this should hit by default: intrazone-default rule. Make sure that logging is enabled under: Actions &amp;gt; Log Setting &amp;gt; Log at session end, otherwise you will not see any logs hitting this rule.&lt;/P&gt;&lt;P&gt;Note: I can see that you have not configured Interface for static route. It is not mandatory if you have next hop, however if you want to make sure that next hop is reachable over certain interface you can hardcode it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Sun, 19 Dec 2021 23:49:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454263#M101446</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-12-19T23:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: A connection issue between PA and SW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454266#M101447</link>
      <description>&lt;P&gt;Hi PaveIK, where to enable Traffic Log?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;under: Actions &amp;gt; Log Setting &amp;gt; Log&amp;nbsp;, it cannot be found.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DavidyPalo_0-1639967641444.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38225iCECE4BC0B6F0A380/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DavidyPalo_0-1639967641444.png" alt="DavidyPalo_0-1639967641444.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 02:36:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454266#M101447</guid>
      <dc:creator>DavidyPalo</dc:creator>
      <dc:date>2021-12-20T02:36:25Z</dc:date>
    </item>
    <item>
      <title>Re: A connection issue between PA and SW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454272#M101448</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203590"&gt;@DavidyPalo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it is under security rule:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1639970304261.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38226iB101EA0589B9CFDE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1639970304261.png" alt="PavelK_0-1639970304261.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 03:19:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454272#M101448</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-12-20T03:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: A connection issue between PA and SW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454277#M101449</link>
      <description>&lt;P&gt;Why my PA show read-only? I did not setup Panorama&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DavidyPalo_0-1639973460318.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38227iD001214E7741076D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DavidyPalo_0-1639973460318.png" alt="DavidyPalo_0-1639973460318.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 04:14:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454277#M101449</guid>
      <dc:creator>DavidyPalo</dc:creator>
      <dc:date>2021-12-20T04:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: A connection issue between PA and SW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454279#M101450</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203590"&gt;@DavidyPalo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could you click on green gear icon and press override?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1639974024459.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38228i499F83F5724F6125/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PavelK_0-1639974024459.png" alt="PavelK_0-1639974024459.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;then you will be able to edit and commit the change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 04:21:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454279#M101450</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-12-20T04:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: A connection issue between PA and SW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454284#M101451</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203590"&gt;@DavidyPalo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure Ping is allowed to PA interface under Network and Interface MGMT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 05:04:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454284#M101451</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2021-12-20T05:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: A connection issue between PA and SW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454485#M101473</link>
      <description>&lt;P&gt;Thank you for feedback&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203590"&gt;@DavidyPalo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am sorry, I would like to confirm one point. In your first post you mentioned:&amp;nbsp;&lt;SPAN&gt;"The Virtual router and Security zone and Management profile Ping are configured." Since you mentioned it ping is working after creating new management profile, does it mean ping was not allowed in your previous management profile or it was not applied to interface from the beginning?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regarding overriding, the intrazone-default rule, could you please click on in&amp;nbsp;intrazone-default and navigate to the bottom of the page and click on overrride button?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1640035637138.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38246iE6D4CFB3AB4E0F9D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1640035637138.png" alt="PavelK_0-1640035637138.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you and Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 21:27:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454485#M101473</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-12-20T21:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: A connection issue between PA and SW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454779#M101502</link>
      <description>&lt;P&gt;Thank you!!&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 20:01:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-connection-issue-between-pa-and-sw/m-p/454779#M101502</guid>
      <dc:creator>DavidyPalo</dc:creator>
      <dc:date>2021-12-21T20:01:19Z</dc:date>
    </item>
  </channel>
</rss>

