<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best guides for new Firewall Deployment in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/best-guides-for-new-firewall-deployment/m-p/514758#M106834</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Sounds like a routing/policy issues with the original PAN you deployed. I wouldnt recommend having the management interface internet facing unless you lock it down to source IP's. However you can change the services, so they use a different interface to reaching out and grabbing updates, etc.&lt;/P&gt;
&lt;P&gt;If you're adventurous&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-articles/secure-day-one-configuration-not-for-the-faint-of-heart/ta-p/435501" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-articles/secure-day-one-configuration-not-for-the-faint-of-heart/ta-p/435501&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;it blocks almost everything so be careful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Tue, 13 Sep 2022 20:16:09 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2022-09-13T20:16:09Z</dc:date>
    <item>
      <title>Best guides for new Firewall Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-guides-for-new-firewall-deployment/m-p/514501#M106796</link>
      <description>&lt;P&gt;I am deploying a new firewall for a PoC however I am having some issues. I have deployed and activated the server on Azure, I am using VM-Series. However despite on the Azure side there being no restrictions, there server is not able to connect to the internet for updates.&amp;nbsp;&lt;BR /&gt;I must be missing something basic in understand/setup so any pointers would be great.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Sep 2022 11:21:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-guides-for-new-firewall-deployment/m-p/514501#M106796</guid>
      <dc:creator>Nhussain</dc:creator>
      <dc:date>2022-09-11T11:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: Best guides for new Firewall Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-guides-for-new-firewall-deployment/m-p/514529#M106800</link>
      <description>&lt;P&gt;is the server in the same vnet and subnet as the internal interface and how have you set the default gateway of the server?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;most commonly the internal interface of the palo will be dhcp client and the server behind has a default gateway to x.x.x.4&lt;/P&gt;
&lt;P&gt;Set the palo external interface also to dhcp client and enable dynamic port/ip NAT and only assign the interface (don't set an IP)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;see if that helps&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 08:01:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-guides-for-new-firewall-deployment/m-p/514529#M106800</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2022-09-12T08:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: Best guides for new Firewall Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-guides-for-new-firewall-deployment/m-p/514574#M106810</link>
      <description>&lt;P&gt;The server is on the same virtual network as the internal interface but not the same subnet. The Internal interface has been configured with DHCP, however I have not done anything specific to define the gateway, where would this be done?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 12:27:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-guides-for-new-firewall-deployment/m-p/514574#M106810</guid>
      <dc:creator>Nhussain</dc:creator>
      <dc:date>2022-09-12T12:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Best guides for new Firewall Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-guides-for-new-firewall-deployment/m-p/514625#M106813</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231978"&gt;@Nhussain&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;What are you seeing in the traffic logs? Do you see the traffic coming in from the server in question? Do you see it properly your NAT statement?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 18:18:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-guides-for-new-firewall-deployment/m-p/514625#M106813</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-09-12T18:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: Best guides for new Firewall Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-guides-for-new-firewall-deployment/m-p/514664#M106818</link>
      <description>&lt;P&gt;So Logs show traffic is allowed and the NAT is also being applied.&lt;BR /&gt;&lt;BR /&gt;however after all that nothing worked, so I deployed another Palo ALto instance but this time it had a public IP on the management interface. it worked,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Added a public IP on the server I was working on and internet connectivity worked. My question is why? Azure does nat'ing for you, it should not need a public IP to get out to the internet? Does anyone know why?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 22:03:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-guides-for-new-firewall-deployment/m-p/514664#M106818</guid>
      <dc:creator>Nhussain</dc:creator>
      <dc:date>2022-09-12T22:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: Best guides for new Firewall Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-guides-for-new-firewall-deployment/m-p/514758#M106834</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Sounds like a routing/policy issues with the original PAN you deployed. I wouldnt recommend having the management interface internet facing unless you lock it down to source IP's. However you can change the services, so they use a different interface to reaching out and grabbing updates, etc.&lt;/P&gt;
&lt;P&gt;If you're adventurous&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-articles/secure-day-one-configuration-not-for-the-faint-of-heart/ta-p/435501" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-articles/secure-day-one-configuration-not-for-the-faint-of-heart/ta-p/435501&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;it blocks almost everything so be careful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 20:16:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-guides-for-new-firewall-deployment/m-p/514758#M106834</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-09-13T20:16:09Z</dc:date>
    </item>
  </channel>
</rss>

