<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PA is connected to a router in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-is-connected-to-a-router/m-p/538898#M110586</link>
    <description>&lt;P&gt;Hi PA(non-management interface) is connected to a router via a cable .&amp;nbsp; What is minimus condition for the two device to ping each other?&lt;/P&gt;
&lt;P&gt;1. ip address in interface are in same subnet,&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp; interface associated with management profile to allow ping&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. interface type is L3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any else?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The reason why i ask the question is the two device cannot see each other via arp. is this physical connection issue?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sun, 16 Apr 2023 04:33:46 GMT</pubDate>
    <dc:creator>DavidyPalo</dc:creator>
    <dc:date>2023-04-16T04:33:46Z</dc:date>
    <item>
      <title>PA is connected to a router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-is-connected-to-a-router/m-p/538898#M110586</link>
      <description>&lt;P&gt;Hi PA(non-management interface) is connected to a router via a cable .&amp;nbsp; What is minimus condition for the two device to ping each other?&lt;/P&gt;
&lt;P&gt;1. ip address in interface are in same subnet,&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp; interface associated with management profile to allow ping&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. interface type is L3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any else?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The reason why i ask the question is the two device cannot see each other via arp. is this physical connection issue?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 16 Apr 2023 04:33:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-is-connected-to-a-router/m-p/538898#M110586</guid>
      <dc:creator>DavidyPalo</dc:creator>
      <dc:date>2023-04-16T04:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: PA is connected to a router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-is-connected-to-a-router/m-p/538902#M110587</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203590"&gt;@DavidyPalo&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are a couple more minimal conditions I would add.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Make sure you source your ping from the desired interface.&amp;nbsp; If you do not specify the source option, pings are sourced from the management interface.&lt;/LI&gt;
&lt;LI&gt;You always need a security policy rule for any traffic to go to or through the NGFW.&amp;nbsp; In your case, the intrazone-default rule will allow the traffic.&lt;/LI&gt;
&lt;LI&gt;The router should not ave any ACLs applied to it also.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Then the "show arp" command on the CLI should show a MAC address for the router.&amp;nbsp; If not, you do not have layer 2 connectivity between the NGFW and router.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sun, 16 Apr 2023 09:13:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-is-connected-to-a-router/m-p/538902#M110587</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-04-16T09:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: PA is connected to a router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-is-connected-to-a-router/m-p/538912#M110589</link>
      <description>&lt;P&gt;Great!&lt;/P&gt;
&lt;P&gt;After security policy is added, the ping can work. but after removing the security policy, the ping still can work. why it happen like that?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Apr 2023 15:20:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-is-connected-to-a-router/m-p/538912#M110589</guid>
      <dc:creator>DavidyPalo</dc:creator>
      <dc:date>2023-04-16T15:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: PA is connected to a router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-is-connected-to-a-router/m-p/538913#M110590</link>
      <description>&lt;P&gt;Under "Device &amp;gt; Config Audit" at the bottom there are droppdowns where you can choose different configs to compare.&lt;BR /&gt;Running config - currently active config&lt;BR /&gt;Candidate config - new changed config that has not been committed yet&lt;BR /&gt;"Go" button will initiate compare task.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Apr 2023 15:24:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-is-connected-to-a-router/m-p/538913#M110590</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-04-16T15:24:03Z</dc:date>
    </item>
  </channel>
</rss>

