<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto Intergrade with ACI- Cannot see hop firewall on tranceroute in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-intergrade-with-aci-cannot-see-hop-firewall-on/m-p/593471#M118113</link>
    <description>&lt;P&gt;To be able to see the firewall in traceroute or ping, you need to set an interface management profile on both interfaces with 'ping' enabled&lt;/P&gt;
&lt;P&gt;Next a rule needs to allow your hosts to communicate with the firewall interfaces (depends on how strictly you set your rulebase)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_0-1722328789221.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61221iEE2857075F1989CF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="reaper_0-1722328789221.png" alt="reaper_0-1722328789221.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jul 2024 08:40:12 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2024-07-30T08:40:12Z</dc:date>
    <item>
      <title>Palo Alto Intergrade with ACI- Cannot see hop firewall on tranceroute</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-intergrade-with-aci-cannot-see-hop-firewall-on/m-p/593299#M118082</link>
      <description>&lt;P&gt;I Integrade Firewall Palo Alto with ACI One Arm , &lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;virtual system divided into 2 for North South and East West&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;On Firewall config Subinterface Layer3 ( Vlan Tag) set IP and config default route to Gateway one ACI. (reference guide)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/vm-series/10-2/vm-series-deployment/set-up-a-firewall-in-cisco-aci/integrate-the-firewall-with-cisco-aci-in-network-policy-mode/deploy-a-north-south-firewall-in-unmanaged-mode-in-cisco-aci" target="_blank"&gt;https://docs.paloaltonetworks.com/vm-series/10-2/vm-series-deployment/set-up-a-firewall-in-cisco-aci/integrate-the-firewall-with-cisco-aci-in-network-policy-mode/deploy-a-north-south-firewall-in-unmanaged-mode-in-cisco-aci&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;Traffic from ACI will use PBR to route through Palo Alto, and Palo Alto will return back to ACI using the default route&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;But when I check tracert between 2 host on traceroute table with traffic throught firewall, I can see all host &lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;except the Firewall host&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;On the firewall I tried opening the policy allow any any, turning off Zone Protection, turning off Packet Buffer Protection but still can't see the firewall hop in the traceroute message. ping between 2 hosts works fine,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;When I capture firewall, on TX i see firewall sent icmp ttl exeeded to client but destination MAC is &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;00:0c:0c:0c:0c:0c (anycast MAC of ACI) &lt;/STRONG&gt;not MAC Address Of client in ARP table&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;Except for TTL Exceeded all other messages sent to the client are sent to the correct MAC address seen in the ARP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;also.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;when i test ping traceroute from host to firewall, ping and tracert are ok and with this traceroute i can see the host of firewall&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;Has anyone ever deployed Palo Alto firewall with ACI and tested tracert with packets passing through the firewall?&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="jCAhz"&gt;&lt;SPAN class="ryNqvb"&gt;Looking forward to sharing experiences.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz"&gt;Many tks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 11:14:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-intergrade-with-aci-cannot-see-hop-firewall-on/m-p/593299#M118082</guid>
      <dc:creator>LeNgocTan</dc:creator>
      <dc:date>2024-07-29T11:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Intergrade with ACI- Cannot see hop firewall on tranceroute</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-intergrade-with-aci-cannot-see-hop-firewall-on/m-p/593471#M118113</link>
      <description>&lt;P&gt;To be able to see the firewall in traceroute or ping, you need to set an interface management profile on both interfaces with 'ping' enabled&lt;/P&gt;
&lt;P&gt;Next a rule needs to allow your hosts to communicate with the firewall interfaces (depends on how strictly you set your rulebase)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_0-1722328789221.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61221iEE2857075F1989CF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="reaper_0-1722328789221.png" alt="reaper_0-1722328789221.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 08:40:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-intergrade-with-aci-cannot-see-hop-firewall-on/m-p/593471#M118113</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-07-30T08:40:12Z</dc:date>
    </item>
  </channel>
</rss>

