<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need assistance with PA-445: general setup/VR in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-pa-445-general-setup-vr/m-p/996949#M122422</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/74481791"&gt;@NoRaindropsInTheSky&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The cool thing about this document &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping&lt;/A&gt; is that is has example security and NAT policy rules on the bottom.&amp;nbsp; Follow those examples and your inbound traffic will work fine.&amp;nbsp; Pay close attention to the zones used, the correct configuration may not be intuitive at first.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With regard to your traffic logs, traffic that does not match a security policy rule will hit the interzone-default rule.&amp;nbsp; This rule does not log by default.&amp;nbsp; You will need to highlight the rule, click the Override button on the bottom, configure logging, and commit your changes.&amp;nbsp; Then you will see the dropped traffic in the logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since you have a NGFW and a CSP (Customer Support Portal) account, you can also log into Beacon.&amp;nbsp; &lt;A href="https://beacon.paloaltonetworks.com" target="_blank" rel="noopener"&gt;https://beacon.paloaltonetworks.com&lt;/A&gt;. From there, search "firewall essentials".&amp;nbsp; You will see the free 9.1 training.&amp;nbsp; The PAN-OS is old, but the foundational configuration is the same.&amp;nbsp; It is very good.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you don't like the older audio/video type training, you can search for "next generation firewall".&amp;nbsp; You will see training of the same name in the new interactive HTML format.&amp;nbsp; Both free training have lots of good material.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have any question as to why, feel free to ask.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Fri, 06 Dec 2024 12:03:25 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2024-12-06T12:03:25Z</dc:date>
    <item>
      <title>Need assistance with PA-445: general setup/VR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-pa-445-general-setup-vr/m-p/996873#M122414</link>
      <description>&lt;P&gt;Hello Everyone, I need a little assistance&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am new to Palo Altos...I have just received and trying to set up an PA-445...but I ran into the following issues:&lt;/P&gt;
&lt;P&gt;- no incoming traffic hitting on anything (outbound traffic is OK: computers plugged into PA-445 on other ports can reach Internet)&lt;/P&gt;
&lt;P&gt;- I would like inside computer 192.168.0.57 to have traffic routed to it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have attached a diagram of the network setup. Port eth1/1 is connected to the Internet (port on the ISP Switch/Modem), with a configuration of Layer3, Outside Zone, 10.1.10.25/32 IPv4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All other ports are configured as Layer2, with one vlan attached to all (called 'VLAN'). I made a zone called 'Inside', and vlan is part of it. This is also Layer3. vlan makes its subnet 192.168.0.1/24,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My Virtual Router has one router, and includes interfaces: eth1/1 + vlan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The routing table for Virtual Router is Dest: 0.0.0.0/0, hop is 10.1.10.1/32, on eth1/1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My Security Policy looks like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. From Outside (any), to Inside (any) - allow (no hits)&lt;/P&gt;
&lt;P&gt;2. From Inside (any) to Outside (any) - allow (works great!)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NAT policy:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. From Inside to Outside (any any any any), Source Translation: dynamic IP - 10.1.10.252/32, Dest. Translation : None&lt;/P&gt;
&lt;P&gt;2. From Outside to Outside (any any any any), Source Translation: None, Dest. Translation: Dynamic IP, 192.168.0.57/32&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The computer 192.168.0.57 can access the Internet...but absolutely no traffic is making it in (the Security Policy has 0 hits).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any advice what am I doing wrong ? I have attached diagram.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 05:56:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-pa-445-general-setup-vr/m-p/996873#M122414</guid>
      <dc:creator>NoRaindropsInTheSky</dc:creator>
      <dc:date>2024-12-06T05:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Need assistance with PA-445: general setup/VR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-pa-445-general-setup-vr/m-p/996949#M122422</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/74481791"&gt;@NoRaindropsInTheSky&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The cool thing about this document &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping&lt;/A&gt; is that is has example security and NAT policy rules on the bottom.&amp;nbsp; Follow those examples and your inbound traffic will work fine.&amp;nbsp; Pay close attention to the zones used, the correct configuration may not be intuitive at first.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With regard to your traffic logs, traffic that does not match a security policy rule will hit the interzone-default rule.&amp;nbsp; This rule does not log by default.&amp;nbsp; You will need to highlight the rule, click the Override button on the bottom, configure logging, and commit your changes.&amp;nbsp; Then you will see the dropped traffic in the logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since you have a NGFW and a CSP (Customer Support Portal) account, you can also log into Beacon.&amp;nbsp; &lt;A href="https://beacon.paloaltonetworks.com" target="_blank" rel="noopener"&gt;https://beacon.paloaltonetworks.com&lt;/A&gt;. From there, search "firewall essentials".&amp;nbsp; You will see the free 9.1 training.&amp;nbsp; The PAN-OS is old, but the foundational configuration is the same.&amp;nbsp; It is very good.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you don't like the older audio/video type training, you can search for "next generation firewall".&amp;nbsp; You will see training of the same name in the new interactive HTML format.&amp;nbsp; Both free training have lots of good material.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have any question as to why, feel free to ask.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 12:03:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-pa-445-general-setup-vr/m-p/996949#M122422</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-12-06T12:03:25Z</dc:date>
    </item>
  </channel>
</rss>

