<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LAN issue with PA200 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/lan-issue-with-pa200/m-p/16382#M11958</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sue,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to ping the firewall's interface, you'll need to attach a management profile allowing ping.&amp;nbsp; Create a new management profile with ping enabled on the Network Tab &amp;gt; Network Profiles &amp;gt; Interface Mgmt page and then select this management profile on ethernet1/2's interface configuration page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you perform the ping operation on the firewall, be sure to specify the source interface IP address that is capable of reaching the switch's IP of 10.130.8.20.&amp;nbsp; So the command would be "ping source 10.130.8.25 host 10.130.8.20".&amp;nbsp; Without specifying a source, the firewall will default to using the IP address assigned to the dedicated management port.&amp;nbsp; I'm guessing that your management port cannot reach the 10.130.8.0/24 subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nick Campagna&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Feb 2012 18:37:36 GMT</pubDate>
    <dc:creator>ncampagna</dc:creator>
    <dc:date>2012-02-10T18:37:36Z</dc:date>
    <item>
      <title>LAN issue with PA200</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lan-issue-with-pa200/m-p/16380#M11956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;gotta really wierd problem...&lt;/P&gt;&lt;P&gt;PA 200&lt;/P&gt;&lt;P&gt;configured for DHCP&lt;/P&gt;&lt;P&gt;eth1/2 Layer 3 IP address 10.130.8.25/24&lt;/P&gt;&lt;P&gt;default route via eth 1/2&lt;/P&gt;&lt;P&gt;eth1/2 connected to port on CISCO 2960S switch&lt;/P&gt;&lt;P&gt;PC connected to port on same CISCO 2960S switch&lt;/P&gt;&lt;P&gt;IP config IP Address. . . . . . . . . . . . : 10.130.8.151&lt;/P&gt;&lt;P&gt;Subnet Mask . . . . . . . . . . . : 255.255.255.0&lt;/P&gt;&lt;P&gt;Default Gateway . . . . . . . . . : 10.130.8.25&lt;/P&gt;&lt;P&gt;Switch config..... interface Vlan1 ip address 10.130.8.20 255.255.255.0&lt;/P&gt;&lt;P&gt;and also ip default-gateway 10.130.8.25&lt;/P&gt;&lt;P&gt;all interfaces are in this default vlan1&lt;/P&gt;&lt;P&gt;PC gets IP address from PA ok&lt;/P&gt;&lt;P&gt;PC can ping switch IP 10.130.8.20&lt;/P&gt;&lt;P&gt;PC cannot ping PA eth 1/2 10.130.8.25&lt;/P&gt;&lt;P&gt;PA has 1 rule ANY ANY ALLOW&lt;/P&gt;&lt;P&gt;COnsole access to PA and cannot ping switch at 10.130.8.20&lt;/P&gt;&lt;P&gt;LAN does not seem to be up in PA 200....&lt;/P&gt;&lt;P&gt;appreciate any help...problem is driving me insane&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 13:01:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lan-issue-with-pa200/m-p/16380#M11956</guid>
      <dc:creator>sue_town</dc:creator>
      <dc:date>2012-02-10T13:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: LAN issue with PA200</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lan-issue-with-pa200/m-p/16381#M11957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you done a debug icmp trace on the cisco switch to see if the packets are making it to the switch? make sure to do a term mon and logging console or monitor on the cisco switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;change the rule on the pa to deny any any and then check the PA traffic log to see if it's registering ICMP requests from your PC or Switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rod&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 14:10:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lan-issue-with-pa200/m-p/16381#M11957</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2012-02-10T14:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: LAN issue with PA200</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lan-issue-with-pa200/m-p/16382#M11958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sue,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to ping the firewall's interface, you'll need to attach a management profile allowing ping.&amp;nbsp; Create a new management profile with ping enabled on the Network Tab &amp;gt; Network Profiles &amp;gt; Interface Mgmt page and then select this management profile on ethernet1/2's interface configuration page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you perform the ping operation on the firewall, be sure to specify the source interface IP address that is capable of reaching the switch's IP of 10.130.8.20.&amp;nbsp; So the command would be "ping source 10.130.8.25 host 10.130.8.20".&amp;nbsp; Without specifying a source, the firewall will default to using the IP address assigned to the dedicated management port.&amp;nbsp; I'm guessing that your management port cannot reach the 10.130.8.0/24 subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nick Campagna&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 18:37:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lan-issue-with-pa200/m-p/16382#M11958</guid>
      <dc:creator>ncampagna</dc:creator>
      <dc:date>2012-02-10T18:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: LAN issue with PA200</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lan-issue-with-pa200/m-p/16383#M11959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks Nick - I had overlooked that...&lt;/P&gt;&lt;P&gt;Sue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Feb 2012 14:24:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lan-issue-with-pa200/m-p/16383#M11959</guid>
      <dc:creator>sue_town</dc:creator>
      <dc:date>2012-02-13T14:24:08Z</dc:date>
    </item>
  </channel>
</rss>

