<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PaloAlto failing communication for Kali Linux in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-failing-communication-for-kali-linux/m-p/517204#M107367</link>
    <description>&lt;P&gt;Kali, Windows and RHEL installed in a lab behind Palos on a directly connected Vlan. Windows and RHEL have no issue communicating to internet or ping firewall interface. But for Kali, Palo captures show only receive and no transmit or even drop packets.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All 3 are getting IP from DHCP on Palo interface, and share common NAT/security policies, routes . I have even tried removing profiles from the policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ping from Kali to firewall interface shows&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44503i5AF9C85E19E4F0DA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kali&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44504iFFEC7E1012589CFC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RHEL&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 925px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44505i0D0D72332D778121/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44506iBE3F8195C3B8E4BE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 09 Oct 2022 05:38:30 GMT</pubDate>
    <dc:creator>raji_toor</dc:creator>
    <dc:date>2022-10-09T05:38:30Z</dc:date>
    <item>
      <title>PaloAlto failing communication for Kali Linux</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-failing-communication-for-kali-linux/m-p/517204#M107367</link>
      <description>&lt;P&gt;Kali, Windows and RHEL installed in a lab behind Palos on a directly connected Vlan. Windows and RHEL have no issue communicating to internet or ping firewall interface. But for Kali, Palo captures show only receive and no transmit or even drop packets.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All 3 are getting IP from DHCP on Palo interface, and share common NAT/security policies, routes . I have even tried removing profiles from the policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ping from Kali to firewall interface shows&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44503i5AF9C85E19E4F0DA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kali&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44504iFFEC7E1012589CFC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RHEL&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 925px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44505i0D0D72332D778121/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44506iBE3F8195C3B8E4BE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Oct 2022 05:38:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-failing-communication-for-kali-linux/m-p/517204#M107367</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2022-10-09T05:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto failing communication for Kali Linux</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-failing-communication-for-kali-linux/m-p/517211#M107368</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The packet captures you have shown - where are they taken from? tcpdump from the VMs or packet capture from the PAN FW?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This doesn't seems to be PAN FW specific so I would suggest you to start with the basics:&lt;/P&gt;
&lt;P&gt;- Ping Kali VM from firewall - &amp;gt; ping source 192.168.99.1 host 192.168.99.5&lt;/P&gt;
&lt;P&gt;- Check if firewall have ARP entry for Kali VM -&amp;gt; show arp &amp;lt;interface-to-kali&amp;gt;&lt;/P&gt;
&lt;P&gt;- Repeat the same from Kali VM (it is good to run the ping before checking ARP to generate fresh ARP requests)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My assumption is that Kali VM is not setup properly and most probably either it is using vnic or using wrong VLAN so Kali VM is not actually connected in the same layer3 network as the PAN FW. Above steps are aming to confirm that - if you don't have ARP (incomplete) from FW to Kali or vice versa it seems you don't have layer2 connectivity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FW operates at layer3, so even if it is blocking the traffic (security rule, zone protection, content inspection etc) you must at least see ARP entry for Kali VM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If there is indeed ARP entry the best option to understand why traffic is being blocked is to use global conters with packet filter.&lt;/P&gt;
&lt;P&gt;Following link describe how to collect this information - &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;In summary:&lt;/P&gt;
&lt;P&gt;- Enable the filter&lt;/P&gt;
&lt;P&gt;- Run twice "&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;show counter global filter packet-filter yes delta yes" (before running any actual traffic to "clear" the delta )&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;- Run simple ping from Kali VM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;- Check global counters again and see what is the output.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Oct 2022 15:12:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-failing-communication-for-kali-linux/m-p/517211#M107368</guid>
      <dc:creator>A_Astardzhiev</dc:creator>
      <dc:date>2022-10-09T15:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto failing communication for Kali Linux</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-failing-communication-for-kali-linux/m-p/517234#M107370</link>
      <description>&lt;P&gt;Everything was in order, On looking at the routes i found Kali IP assigned to a loopback interface on PA causing duplicate IP issue. On excluding it from DHCP assignment range in PA resolved it.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Oct 2022 17:33:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-failing-communication-for-kali-linux/m-p/517234#M107370</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2022-10-09T17:33:22Z</dc:date>
    </item>
  </channel>
</rss>

