<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall Unable to connect to ISP Router in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527369#M108963</link>
    <description>&lt;P&gt;If you configure same public IP and gateway on your laptop and connect ISP cable directly to laptop can you get to internet or see arp from ISP?&lt;/P&gt;
&lt;P&gt;If yes we can help you troubleshoot Palo.&lt;/P&gt;
&lt;P&gt;If not then ISP needs to check their config.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jan 2023 13:15:50 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2023-01-17T13:15:50Z</dc:date>
    <item>
      <title>Firewall Unable to connect to ISP Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527357#M108960</link>
      <description>&lt;P&gt;I m setting up a small office network where the endpoints are connecting to a switch that is in turn trunked to a PA220 Firewall . The firewall external interface is configured with a static IP address within the same range as the ISP IP router .&lt;/P&gt;
&lt;P&gt;However it appears that neither the ISP router or the Palo can receive arp entries off each other let alone ping each other&lt;/P&gt;
&lt;P&gt;The ISP provider has also confirmed the internet connectivity is working fine .&lt;/P&gt;
&lt;P&gt;Can anyone&amp;nbsp; please advise ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 10:43:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527357#M108960</guid>
      <dc:creator>HassanThiam</dc:creator>
      <dc:date>2023-01-17T10:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Unable to connect to ISP Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527369#M108963</link>
      <description>&lt;P&gt;If you configure same public IP and gateway on your laptop and connect ISP cable directly to laptop can you get to internet or see arp from ISP?&lt;/P&gt;
&lt;P&gt;If yes we can help you troubleshoot Palo.&lt;/P&gt;
&lt;P&gt;If not then ISP needs to check their config.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 13:15:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527369#M108963</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-17T13:15:50Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Unable to connect to ISP Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527388#M108965</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the feedback .&amp;nbsp; Unfortunately at the time, I was unable to configure&amp;nbsp; my laptop IP address and Gateway because of admin restrictions ( working to get elevated privileges at the moment ) . The ISP sent an engineer onsite to check internet reachability&amp;nbsp; and he confirmed connectivity to the ISP default gateway by plugging a device directly into the router .What are the sort of config that could prevent the firewall from seeing the router ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 15:00:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527388#M108965</guid>
      <dc:creator>HassanThiam</dc:creator>
      <dc:date>2023-01-17T15:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Unable to connect to ISP Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527395#M108968</link>
      <description>&lt;P&gt;ISP provides connectivity over access port right (not tagged/trunk port)?&lt;/P&gt;
&lt;P&gt;Ask ISP if speed/duplex is set to auto/auto or if they have hardcoded those settings.&lt;/P&gt;
&lt;P&gt;If second option you need to match your side.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 15:37:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527395#M108968</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-17T15:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Unable to connect to ISP Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527432#M108973</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will enquire with the ISP about the speed/duplex settings , I would have thought they will be set to auto&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes the connectivity is provided through an access port&amp;nbsp; . As per the attached topology the firewall connect to an Onsite router that only function in bridge mode with so&amp;nbsp; layer 3 communication is between the firewall and the aggregate router .&lt;/P&gt;
&lt;P&gt;The ISP engineer&amp;nbsp; that&amp;nbsp; visited the site confirmed the Internet was working by plugging a portable device into the Onsite router ( LAN 1) and could get to the&amp;nbsp;&lt;SPAN&gt;ISP Aggregate&amp;nbsp; Router using IP addresses within the same range .&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Let me know if you have any further suggestions&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-01-17 17_43_57-WAN - diagrams.net.png" style="width: 522px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47138i314D6A9EDAC201D2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2023-01-17 17_43_57-WAN - diagrams.net.png" alt="2023-01-17 17_43_57-WAN - diagrams.net.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks in advance&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 17:49:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527432#M108973</guid>
      <dc:creator>HassanThiam</dc:creator>
      <dc:date>2023-01-17T17:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Unable to connect to ISP Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527692#M109010</link>
      <description>&lt;P&gt;Good Morning ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can now confirm I have Internet connectivity but I have set up a VPN with an ASA that s not coming up . The outside interface of the Palo is up and can ping the ASA outside interface .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any advice will be greatly appreciated&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 10:31:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527692#M109010</guid>
      <dc:creator>HassanThiam</dc:creator>
      <dc:date>2023-01-19T10:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Unable to connect to ISP Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527701#M109012</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/161552"&gt;@HassanThiam&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Do you have an interface profile applied to your interface connected to the ISP that allows pings?
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMmCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMmCAK&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Otherwise pings will not be allowed, and an ARP request will not be sent.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Do you source your pings from the IP applied to the interface connected to the ISP?
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/tips-amp-tricks-how-to-ping-from-the-cli/ba-p/468784" target="_blank"&gt;https://live.paloaltonetworks.com/t5/blogs/tips-amp-tricks-how-to-ping-from-the-cli/ba-p/468784&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Otherwise the pings will be sourced from the management IP address.&lt;/LI&gt;
&lt;LI&gt;Again, no ARP request will be sent out the ISP interface.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Do you see the pings in the traffic logs (Monitor &amp;gt; Logs &amp;gt; Traffic)?
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;Pings from an interface will be allowed by the intrazone-default rule.&lt;/LI&gt;
&lt;LI&gt;Logging will need to be enabled on the rule.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/best-practices/9-1/data-center-best-practices/data-center-best-practice-security-policy/log-and-monitor-data-center-traffic/log-intra-data-center-traffic-that-matches-the-intrazone-allow-rule" target="_blank"&gt;https://docs.paloaltonetworks.com/best-practices/9-1/data-center-best-practices/data-center-best-practice-security-policy/log-and-monitor-data-center-traffic/log-intra-data-center-traffic-that-matches-the-intrazone-allow-rule&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;You can also enable logging on the interzone-default rule.&amp;nbsp; Then you should see all IP traffic through the data plane, allowed or dropped.&lt;/LI&gt;
&lt;LI&gt;Logs confirm the NGFW is attempting to send pings.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Have you verified the NGFW is not receiving ARP by using the "show arp" command on the CLI?
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;You should see a MAC address (received) or incomplete (not received).&lt;/LI&gt;
&lt;LI&gt;The incomplete times out fairly quickly.&amp;nbsp; The command needs to be run as soon as the ping is done.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 12:12:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527701#M109012</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-01-19T12:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Unable to connect to ISP Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527929#M109029</link>
      <description>&lt;P&gt;Hi Tom&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the feedback .&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Do you have an interface profile applied to your interface connected to the ISP that allows pings?
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMmCAK" target="_blank" rel="nofollow noopener noreferrer"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMmCAK&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Otherwise pings will not be allowed, and an ARP request will not be sent.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Yes I do have an interface management profile that accept pings&amp;nbsp;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Do you source your pings from the IP applied to the interface connected to the ISP?
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/tips-amp-tricks-how-to-ping-from-the-cli/ba-p/468784" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/blogs/tips-amp-tricks-how-to-ping-from-the-cli/ba-p/468784&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Otherwise the pings will be sourced from the management IP address.&lt;/LI&gt;
&lt;LI&gt;Again, no ARP request will be sent out the ISP interface.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;When I source it from the Management interface it doesn't work but works from the NGFW outside interface&amp;nbsp;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Do you see the pings in the traffic logs (Monitor &amp;gt; Logs &amp;gt; Traffic)?
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;Pings from an interface will be allowed by the intrazone-default rule.&lt;/LI&gt;
&lt;LI&gt;Logging will need to be enabled on the rule.&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/best-practices/9-1/data-center-best-practices/data-center-best-practice-security-policy/log-and-monitor-data-center-traffic/log-intra-data-center-traffic-that-matches-the-intrazone-allow-rule" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.paloaltonetworks.com/best-practices/9-1/data-center-best-practices/data-center-best-pra...&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;You can also enable logging on the interzone-default rule.&amp;nbsp; Then you should see all IP traffic through the data plane, allowed or dropped.&lt;/LI&gt;
&lt;LI&gt;Logs confirm the NGFW is attempting to send pings.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Yes I can see the pings from the traffic logs&amp;nbsp;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Have you verified the NGFW is not receiving ARP by using the "show arp" command on the CLI?
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;You should see a MAC address (received) or incomplete (not received).&lt;/LI&gt;
&lt;LI&gt;The incomplete times out fairly quickly.&amp;nbsp; The command needs to be run as soon as the ping is done.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;To be confirmed&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;As per the topology I can t get the tunnel to the ASA working although the IKE parameters seem to match . The outside interface of the Palo can ping the ASA though . From an&amp;nbsp; ASA perspective I can t see nothing on the logs&amp;nbsp; .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This s the message I get from the NGFW .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HassanThiam_0-1674207833875.png" style="width: 705px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47273i30EF3EB8CE436104/image-dimensions/705x104/is-moderation-mode/true?v=v2" width="705" height="104" role="button" title="HassanThiam_0-1674207833875.png" alt="HassanThiam_0-1674207833875.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help will be greatly appreciated&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 09:45:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527929#M109029</guid>
      <dc:creator>HassanThiam</dc:creator>
      <dc:date>2023-01-20T09:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Unable to connect to ISP Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527951#M109036</link>
      <description>&lt;P&gt;Crypto settings don't match.&lt;/P&gt;
&lt;P&gt;Do you manage ASA side as well to check config?&lt;/P&gt;
&lt;P&gt;"show vpn-sessiondb detailed l2l" is helpful to use on ASA side.&lt;/P&gt;
&lt;P&gt;If you can't get this info then next step is to turn Palo side to passive mode and figure out what ASA is negotiating with using packet capture.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 13:21:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527951#M109036</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-20T13:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Unable to connect to ISP Router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527963#M109038</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/161552"&gt;@HassanThiam&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am glad the Internet is working now.&amp;nbsp; If my answer helped you get the ping working, please accept it as the solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With regard to the VPN, we would be glad to help on this thread, but technically it is a different topic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A good place to start with IPsec is the green lights under Network &amp;gt; IPSec Tunnels, and Monitor &amp;gt; Logs &amp;gt; System.&amp;nbsp; As &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt; mentioned, NO_PROPOSAL_CHOSEN means the crypto settings do not match and the tunnel is not up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 14:04:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-unable-to-connect-to-isp-router/m-p/527963#M109038</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-01-20T14:04:16Z</dc:date>
    </item>
  </channel>
</rss>

