<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Newbie looking for some guidance in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529720#M109334</link>
    <description>&lt;P&gt;Can you share screenshot of security and nat policy?&lt;/P&gt;
&lt;P&gt;Have you permitted incoming ping in laptops (or disabled firewall)?&lt;/P&gt;</description>
    <pubDate>Fri, 03 Feb 2023 02:09:00 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2023-02-03T02:09:00Z</dc:date>
    <item>
      <title>Newbie looking for some guidance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529469#M109308</link>
      <description>&lt;P&gt;Hello everyone.&amp;nbsp; I am new to Palo Alto firewalls.&amp;nbsp; We have bought many new PA-440's and I am having trouble with my very first installation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a site that is currently using a TP-Link AX1500 router.&lt;/P&gt;
&lt;P&gt;Very simple setup.... ISPmodem----WANportOfAX1500/LANportOfAX1500----Clients.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tried, without success, to mimic the setup of the AX1500 and replace it with the PA-440.&amp;nbsp; I have the PA-440 acting as a DHCP server.&amp;nbsp; My clients get IP addresses, and then can ping the PA-440.&amp;nbsp; They cannot ping anything on the Internet.&amp;nbsp; From the PA-440 command line, I also cannot ping anything on the Internet (ping host 8.8.8.8 for example).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know this post leaves many questions, but is there a guide on a very basic setup like this?&amp;nbsp; I am sure I am missing something small but have been unable to put my finger on it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you -- Walter&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 14:21:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529469#M109308</guid>
      <dc:creator>walter35161</dc:creator>
      <dc:date>2023-02-01T14:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie looking for some guidance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529475#M109310</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;ping host 8.8.8.8" sends ping requests out from Palo mgmt interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For this to work mgmt interface needs to be connected, NAT and security policy need to be in place.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do you see those sessions under "Monitor &amp;gt; Traffic"?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;By default "interzone-default" and "intrazone-default" rules don't log so it is suggested to override them and check "Log at session end" on Actions tab.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can also try "ping source 1.2.3.4 host 8.8.8.8" (replace 1.2.3.4 with your WAN IP).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In this case ping goes out from WAN interface. NAT is not needed and by default "intrazone-default" rule will permit this traffic.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you share output of your results we can help you get them connected.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 14:32:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529475#M109310</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-02-01T14:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie looking for some guidance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529676#M109329</link>
      <description>&lt;P&gt;Thank you very much for responding.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am now working on the bench in my office.&amp;nbsp; I have two Windows laptops, one Windows PC, and the Palo.&lt;/P&gt;
&lt;P&gt;I have attached a picture of the connections.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The Palo &lt;U&gt;can&lt;/U&gt; successfully ping either of it's own interfaces (10.10.150.1 or&amp;nbsp;24.197.46.86).&lt;/LI&gt;
&lt;LI&gt;Palo cannot ping either laptop from the command line.&lt;/LI&gt;
&lt;LI&gt;Dell laptop &lt;U&gt;can&lt;/U&gt; ping 24.197.46.86, but not 10.10.150.1.&lt;/LI&gt;
&lt;LI&gt;HP laptop &lt;U&gt;can&lt;/U&gt; ping 10.10.150.1, but not&amp;nbsp;24.197.46.86.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I am sure I am missing something fundamental.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo1.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47606iDC0E467162CD3326/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="palo1.JPG" alt="palo1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 21:32:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529676#M109329</guid>
      <dc:creator>walter35161</dc:creator>
      <dc:date>2023-02-02T21:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie looking for some guidance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529720#M109334</link>
      <description>&lt;P&gt;Can you share screenshot of security and nat policy?&lt;/P&gt;
&lt;P&gt;Have you permitted incoming ping in laptops (or disabled firewall)?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 02:09:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529720#M109334</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-02-03T02:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie looking for some guidance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529783#M109337</link>
      <description>&lt;P&gt;I have the Windows firewall disabled on both laptops.&amp;nbsp; Just to make sure of pingability, I changed one laptop to match the subnet of the other laptop, cross-connected them via Ethernet, and they were able to ping each other.&lt;/P&gt;
&lt;P&gt;I am attaching 7 screenshots.&amp;nbsp; Thanks again for your help.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo1.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47627i7A7F31853D5B6D22/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="palo1.jpg" alt="palo1.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo2.jpg" style="width: 803px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47628i9422505AA1F146DA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="palo2.jpg" alt="palo2.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo3.jpg" style="width: 803px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47630iE5C6EED2AC29C669/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="palo3.jpg" alt="palo3.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo4.jpg" style="width: 804px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47629iDCD758D8063CA06F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="palo4.jpg" alt="palo4.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo6.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47632i94069209E8ED05AB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="palo6.jpg" alt="palo6.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo5.jpg" style="width: 846px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47631iB45EAD7C0A2FAFEB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="palo5.jpg" alt="palo5.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo7.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47633i91966B2F873FAAEB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="palo7.jpg" alt="palo7.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 14:28:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529783#M109337</guid>
      <dc:creator>walter35161</dc:creator>
      <dc:date>2023-02-03T14:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie looking for some guidance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529784#M109338</link>
      <description>&lt;P&gt;Those 2 commands don't work?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;ping source 24.197.46.86 host 24.197.46.85&lt;BR /&gt;ping source 10.10.150.1 host 10.10.150.51&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 14:40:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529784#M109338</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-02-03T14:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie looking for some guidance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529787#M109340</link>
      <description>&lt;P&gt;Yes, both of those commands do work. I apologize... I thought "ping host 10.10.150.1" would work.&lt;/P&gt;
&lt;P&gt;I get replies using both of these commands:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ping source 24.197.46.86 host 24.197.46.85&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ping source 10.10.150.1 host 10.10.150.51&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 15:07:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529787#M109340</guid>
      <dc:creator>walter35161</dc:creator>
      <dc:date>2023-02-03T15:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie looking for some guidance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529789#M109341</link>
      <description>&lt;P&gt;If you don't specify source IP (like&amp;nbsp;&lt;SPAN&gt;ping host 10.10.150.51) then ping requests go out from mgmt interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;There is no interconnection inside firewall between mgmt port and dataplane port.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For mgmt port to have connectivity you need to connect fw internal interface and mgmt port into switch so they can see each other.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 15:30:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529789#M109341</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-02-03T15:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie looking for some guidance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529805#M109343</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/271151"&gt;@walter35161&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You don't appear to be logging your interzone-default policy, for troubleshooting I'd enable that so you can ensure that the traffic is actually being processed properly and isn't getting dropped. Couple things I would look at:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Traffic Logs - Do you see this traffic in your current traffic logs at all? If you have it recorded in the logs as being allowed, make sure that you've actually verified via the detailed log view that things are routing properly and going out the proper interface. If you don't have records prior to enabling the interzone-default logging, this traffic wasn't matching your rules and getting dropped.&lt;/LI&gt;
&lt;LI&gt;Routing - Kinda covered this above, but make sure that your traffic is actually routing properly via your traffic logs.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 03 Feb 2023 17:54:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbie-looking-for-some-guidance/m-p/529805#M109343</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-02-03T17:54:24Z</dc:date>
    </item>
  </channel>
</rss>

