<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't get internet access, routing problem? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-internet-access-routing-problem/m-p/15001#M10995</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you confirm that you can ping next hop from outside interface?&lt;/P&gt;&lt;P&gt;admin@PA&amp;gt;ping source&amp;nbsp; 68.231.208.87 host&amp;nbsp; 68.231.208.82&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, Just to confirm, did you set up NAT policy as the following:-&lt;/P&gt;&lt;P&gt;Source Zone:- Trust&lt;/P&gt;&lt;P&gt;Destination Zone:-&amp;nbsp; Untrust&lt;/P&gt;&lt;P&gt;Source Address:- Any&lt;/P&gt;&lt;P&gt;Destination Address:- any&lt;/P&gt;&lt;P&gt;Source Translation: Dynamic IP and Port, , Untrust Interface, 68.231.208.87/29&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Oct 2012 16:07:44 GMT</pubDate>
    <dc:creator>ppatel</dc:creator>
    <dc:date>2012-10-05T16:07:44Z</dc:date>
    <item>
      <title>Can't get internet access, routing problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-internet-access-routing-problem/m-p/15000#M10994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have worked with many different types of firewalls, but this is my first time with the Palo Alto 5050. Currently I have a basic configuration, a single internet connection and a VR with a default route, properly addressed interface, policy that allows all traffic, zones, etc. Right now I just want to be able to ping out to the internet, the rest of the setup will be fairly straight forward as I have already began working on it. For some reason I can not make a connection to the internet, I can ping all my interface that I have setup internally but not the gateway. Right now I have been provided with an address such as (fake address), 68.231.208.87/29 (Interface address) and a gateway of 68.231.208.82. I have a VR with a default route of 0.0.0.0/0 to 68.231.208.82 the zone is untrusted and my policy is built to allow all traffic in both directions for the time being. What am I missing? I used this document, &lt;SPAN style="font-size: 10.0pt; font-family: 'Tahoma','sans-serif'; color: black;"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1195"&gt;https://live.paloaltonetworks.com/docs/DOC-1195&lt;/A&gt;&lt;/SPAN&gt; which was helpful but still can not make a connection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2012 15:33:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-internet-access-routing-problem/m-p/15000#M10994</guid>
      <dc:creator>mgross</dc:creator>
      <dc:date>2012-10-05T15:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get internet access, routing problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-internet-access-routing-problem/m-p/15001#M10995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you confirm that you can ping next hop from outside interface?&lt;/P&gt;&lt;P&gt;admin@PA&amp;gt;ping source&amp;nbsp; 68.231.208.87 host&amp;nbsp; 68.231.208.82&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, Just to confirm, did you set up NAT policy as the following:-&lt;/P&gt;&lt;P&gt;Source Zone:- Trust&lt;/P&gt;&lt;P&gt;Destination Zone:-&amp;nbsp; Untrust&lt;/P&gt;&lt;P&gt;Source Address:- Any&lt;/P&gt;&lt;P&gt;Destination Address:- any&lt;/P&gt;&lt;P&gt;Source Translation: Dynamic IP and Port, , Untrust Interface, 68.231.208.87/29&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2012 16:07:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-internet-access-routing-problem/m-p/15001#M10995</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-05T16:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get internet access, routing problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-internet-access-routing-problem/m-p/15002#M10996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can ping the next hop from that address. I didn't have my NAT setup, so I did that but still cannot ping out. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It loos like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Name: Internet&lt;/P&gt;&lt;P&gt;Tag: None&lt;/P&gt;&lt;P&gt;Source Zone: trust&lt;/P&gt;&lt;P&gt;Destination Zone: untrust&lt;/P&gt;&lt;P&gt;Destination Interface: any&lt;/P&gt;&lt;P&gt;Source Address: any&lt;/P&gt;&lt;P&gt;Destination Address: any&lt;/P&gt;&lt;P&gt;Service: any&lt;/P&gt;&lt;P&gt;Source Translation: dynamic-ip-and-port, ethernet1/1, 68.231.208.87/29&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2012 16:27:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-internet-access-routing-problem/m-p/15002#M10996</guid>
      <dc:creator>mgross</dc:creator>
      <dc:date>2012-10-05T16:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get internet access, routing problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-internet-access-routing-problem/m-p/15003#M10997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you ping the next hop from the internal interface?&lt;/P&gt;&lt;P&gt;Is the DNS configured on the firewall , under Device &amp;gt; Setup &amp;gt; Management &amp;gt; Services &amp;gt; DNS settings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2012 16:32:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-internet-access-routing-problem/m-p/15003#M10997</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-05T16:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get internet access, routing problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-internet-access-routing-problem/m-p/15004#M10998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apologies, I am able to ping from an internal interface, just not through the console. I am not sure why though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2012 16:34:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-internet-access-routing-problem/m-p/15004#M10998</guid>
      <dc:creator>mgross</dc:creator>
      <dc:date>2012-10-05T16:34:33Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get internet access, routing problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-internet-access-routing-problem/m-p/15005#M10999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you mean,&amp;nbsp; you are not able to ping the gateway from the management ip-address of the firewall?&lt;/P&gt;&lt;P&gt;Does the following ping fail?&lt;/P&gt;&lt;P&gt;&amp;gt;ping host &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;68.231.208.8&lt;/SPAN&gt;2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that is the case, the management interface network might no be configured to have internet access.&lt;/P&gt;&lt;P&gt;Management interface does not take part in the routing through the firewall unless you configure a Service route configuration for specific services&amp;nbsp; to use one of the datplane interfaces.&lt;/P&gt;&lt;P&gt;Device&amp;gt;Setup&amp;gt;Service&amp;gt;Service Route configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, make sure DNS is set up on the firewall.&lt;/P&gt;&lt;P&gt;Let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2012 16:43:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-internet-access-routing-problem/m-p/15005#M10999</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-05T16:43:39Z</dc:date>
    </item>
  </channel>
</rss>

