<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Routing issues on PA410 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-on-pa410/m-p/493689#M105018</link>
    <description>&lt;P&gt;&lt;BR /&gt;I cannot get traffic to go out my outside interface - it will only go out the Management interface&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I have a PA-410 with several Inside interfaces / Outside (connected to an ASA) / Management (connected to my Inside network)&lt;BR /&gt;Note: I changed the Outside IP's first 3 octets from the real to 3.3.3. in this post to protect the future public IP for this firewall.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Setup looks like this&lt;BR /&gt;PC &amp;lt;-&amp;gt; switch &amp;lt;-&amp;gt; (ethernet1/2.32)PA-410(eithernet1/1) &amp;lt;-&amp;gt; (eithernet0/0)ASA (ethernet0/1)&amp;lt;-&amp;gt; Inside network &amp;lt;-&amp;gt; ISP&lt;/P&gt;&lt;P&gt;If I plug directly into the ASA's 0/0 interface &amp;amp; give my PC an IP in the 3.3.3.104/29 range -&amp;nbsp; I can connect just fine to the internet&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Management: 192.168.0.3/24&lt;BR /&gt;Inside: 172.31.32.1/24&amp;nbsp;&lt;BR /&gt;Internet: 3.3.3.109/29&amp;nbsp;&amp;nbsp;&lt;BR /&gt;ASA: 3.3.3.110/29 - The ASA will PAT all traffic so it can cross the Inside network and get to the Internet.&lt;BR /&gt;VR - All interfaces added&lt;BR /&gt;Includes static route 0.0.0.0/0 -&amp;gt; 3.3.3.110 (See below)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;When I connect with my PC to the Palo I get no internet&lt;BR /&gt;From the PC I can ping the gateway 172.31.32.1&amp;nbsp;&lt;BR /&gt;From the PC I can NOT ping google 8.8.8.8&lt;BR /&gt;From the ASA I can ping the Palo outside 3.3.3.109 interface&lt;BR /&gt;From the ASA I can ping google (8.8.8.8)&lt;BR /&gt;From the Palo CLI I can NOT ping the ASA interface 3.3.3.110&lt;BR /&gt;From the Palo CLI I can ping itself 3.3.3.109&lt;BR /&gt;From the Palo CLI I can ping google (8.8.8.8) but the ping goes out the management interface not the Outside interface&lt;/P&gt;&lt;P&gt;VIRTUAL ROUTER: DCS-Campus (id 1)&lt;BR /&gt;==========&lt;BR /&gt;destination nexthop metric flags age interface next-AS&lt;BR /&gt;0.0.0.0/0 3.3.3.110 10 A S ethernet1/1&lt;BR /&gt;3.3.3.104/29 3.3.3.109 0 A C ethernet1/1&lt;BR /&gt;3.3.3.109/32 0.0.0.0 0 A H&lt;BR /&gt;172.31.8.0/24 172.31.8.1 0 A C ethernet1/2.8&lt;BR /&gt;172.31.8.1/32 0.0.0.0 0 A H&lt;BR /&gt;172.31.16.0/24 172.31.16.1 0 A C ethernet1/2.16&lt;BR /&gt;172.31.16.1/32 0.0.0.0 0 A H&lt;BR /&gt;172.31.24.0/24 172.31.24.1 0 A C ethernet1/2.24&lt;BR /&gt;172.31.24.1/32 0.0.0.0 0 A H&lt;BR /&gt;172.31.32.0/24 172.31.32.1 0 A C ethernet1/2.32&lt;BR /&gt;172.31.32.1/32 0.0.0.0 0 A H&lt;BR /&gt;172.31.128.0/24 172.31.128.1 0 A C ethernet1/2.128&lt;BR /&gt;172.31.128.1/32 0.0.0.0 0 A H&lt;BR /&gt;172.31.192.0/24 172.31.192.1 0 A C ethernet1/2.192&lt;BR /&gt;172.31.192.1/32 0.0.0.0 0 A H&lt;BR /&gt;172.31.248.0/24 172.31.248.1 0 A C ethernet1/2.248&lt;BR /&gt;172.31.248.1/32 0.0.0.0 0 A H&lt;BR /&gt;total routes shown: 17&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 27 May 2022 14:45:48 GMT</pubDate>
    <dc:creator>sos66sos</dc:creator>
    <dc:date>2022-05-27T14:45:48Z</dc:date>
    <item>
      <title>Routing issues on PA410</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-on-pa410/m-p/493689#M105018</link>
      <description>&lt;P&gt;&lt;BR /&gt;I cannot get traffic to go out my outside interface - it will only go out the Management interface&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I have a PA-410 with several Inside interfaces / Outside (connected to an ASA) / Management (connected to my Inside network)&lt;BR /&gt;Note: I changed the Outside IP's first 3 octets from the real to 3.3.3. in this post to protect the future public IP for this firewall.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Setup looks like this&lt;BR /&gt;PC &amp;lt;-&amp;gt; switch &amp;lt;-&amp;gt; (ethernet1/2.32)PA-410(eithernet1/1) &amp;lt;-&amp;gt; (eithernet0/0)ASA (ethernet0/1)&amp;lt;-&amp;gt; Inside network &amp;lt;-&amp;gt; ISP&lt;/P&gt;&lt;P&gt;If I plug directly into the ASA's 0/0 interface &amp;amp; give my PC an IP in the 3.3.3.104/29 range -&amp;nbsp; I can connect just fine to the internet&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Management: 192.168.0.3/24&lt;BR /&gt;Inside: 172.31.32.1/24&amp;nbsp;&lt;BR /&gt;Internet: 3.3.3.109/29&amp;nbsp;&amp;nbsp;&lt;BR /&gt;ASA: 3.3.3.110/29 - The ASA will PAT all traffic so it can cross the Inside network and get to the Internet.&lt;BR /&gt;VR - All interfaces added&lt;BR /&gt;Includes static route 0.0.0.0/0 -&amp;gt; 3.3.3.110 (See below)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;When I connect with my PC to the Palo I get no internet&lt;BR /&gt;From the PC I can ping the gateway 172.31.32.1&amp;nbsp;&lt;BR /&gt;From the PC I can NOT ping google 8.8.8.8&lt;BR /&gt;From the ASA I can ping the Palo outside 3.3.3.109 interface&lt;BR /&gt;From the ASA I can ping google (8.8.8.8)&lt;BR /&gt;From the Palo CLI I can NOT ping the ASA interface 3.3.3.110&lt;BR /&gt;From the Palo CLI I can ping itself 3.3.3.109&lt;BR /&gt;From the Palo CLI I can ping google (8.8.8.8) but the ping goes out the management interface not the Outside interface&lt;/P&gt;&lt;P&gt;VIRTUAL ROUTER: DCS-Campus (id 1)&lt;BR /&gt;==========&lt;BR /&gt;destination nexthop metric flags age interface next-AS&lt;BR /&gt;0.0.0.0/0 3.3.3.110 10 A S ethernet1/1&lt;BR /&gt;3.3.3.104/29 3.3.3.109 0 A C ethernet1/1&lt;BR /&gt;3.3.3.109/32 0.0.0.0 0 A H&lt;BR /&gt;172.31.8.0/24 172.31.8.1 0 A C ethernet1/2.8&lt;BR /&gt;172.31.8.1/32 0.0.0.0 0 A H&lt;BR /&gt;172.31.16.0/24 172.31.16.1 0 A C ethernet1/2.16&lt;BR /&gt;172.31.16.1/32 0.0.0.0 0 A H&lt;BR /&gt;172.31.24.0/24 172.31.24.1 0 A C ethernet1/2.24&lt;BR /&gt;172.31.24.1/32 0.0.0.0 0 A H&lt;BR /&gt;172.31.32.0/24 172.31.32.1 0 A C ethernet1/2.32&lt;BR /&gt;172.31.32.1/32 0.0.0.0 0 A H&lt;BR /&gt;172.31.128.0/24 172.31.128.1 0 A C ethernet1/2.128&lt;BR /&gt;172.31.128.1/32 0.0.0.0 0 A H&lt;BR /&gt;172.31.192.0/24 172.31.192.1 0 A C ethernet1/2.192&lt;BR /&gt;172.31.192.1/32 0.0.0.0 0 A H&lt;BR /&gt;172.31.248.0/24 172.31.248.1 0 A C ethernet1/2.248&lt;BR /&gt;172.31.248.1/32 0.0.0.0 0 A H&lt;BR /&gt;total routes shown: 17&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 14:45:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-on-pa410/m-p/493689#M105018</guid>
      <dc:creator>sos66sos</dc:creator>
      <dc:date>2022-05-27T14:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: Routing issues on PA410</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-on-pa410/m-p/493986#M105034</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206204"&gt;@sos66sos&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you paste a screenshot of the traffic logs to include the advanced view when clicking on the microscope icon?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jay&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 21:28:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-on-pa410/m-p/493986#M105034</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2022-05-27T21:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: Routing issues on PA410</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-on-pa410/m-p/494071#M105037</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206204"&gt;@sos66sos&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for providing so many details.&amp;nbsp; I have a couple questions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;"From the Palo CLI I can ping google (8.8.8.8) but the ping goes out the management interface not the Outside interface"&amp;nbsp; Did you use the "source" parameter?&amp;nbsp; By default, CLI pings are sourced from the management interface.&amp;nbsp; You need to specify the outside interface IP as a source if you want it to go out that interface.&lt;/LI&gt;&lt;LI&gt;"From the PC I can NOT ping google 8.8.8.8"&amp;nbsp; Does the ASA have a route back to the Palo for the 172.31.32.0/24 network?&amp;nbsp; It sounds like it does not.&amp;nbsp; It also sounds like it &lt;EM&gt;does&lt;/EM&gt; have a route for the 192.168.0.0/24 network.&lt;/LI&gt;&lt;LI&gt;"From the Palo CLI I can NOT ping the ASA interface 3.3.3.110"&amp;nbsp; Are pings to the inside interface enabled on the ASA?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sat, 28 May 2022 01:28:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-on-pa410/m-p/494071#M105037</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-05-28T01:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: Routing issues on PA410</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-on-pa410/m-p/494201#M105046</link>
      <description>&lt;P&gt;I have backed out my configuration and started over - I now see traffic leaving the outside interface.&amp;nbsp; I obviously had something configured incorrectly so I'm not sure what the solution was but I appreciate everyone's input.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 May 2022 16:32:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-on-pa410/m-p/494201#M105046</guid>
      <dc:creator>sos66sos</dc:creator>
      <dc:date>2022-05-28T16:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Routing issues on PA410</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-on-pa410/m-p/494206#M105047</link>
      <description>&lt;P&gt;This was the resolution to the ping issue - I did not source from the outside interface.&lt;BR /&gt;I still could not ping until I removed everything and started over.&amp;nbsp; I must have had something configured incorrection - I should not build firewalls when I'm half asleep &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 May 2022 16:34:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-on-pa410/m-p/494206#M105047</guid>
      <dc:creator>sos66sos</dc:creator>
      <dc:date>2022-05-28T16:34:46Z</dc:date>
    </item>
  </channel>
</rss>

