<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Proper &amp;quot;outside&amp;quot; interface configuration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/proper-quot-outside-quot-interface-configuration/m-p/1226614#M124006</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;Just add the IP's of NAT policies to the interface...&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Ok, like this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;194.204.1.6/26&lt;/P&gt;
&lt;P&gt;194.204.1.10/26&lt;/P&gt;
&lt;P&gt;194.204.1.11/26&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or should the subnet masks be /32?&lt;/P&gt;</description>
    <pubDate>Tue, 15 Apr 2025 19:32:11 GMT</pubDate>
    <dc:creator>relayer</dc:creator>
    <dc:date>2025-04-15T19:32:11Z</dc:date>
    <item>
      <title>Proper "outside" interface configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proper-quot-outside-quot-interface-configuration/m-p/1226599#M123998</link>
      <description>&lt;P&gt;Hello all!&lt;BR /&gt;&lt;BR /&gt;I'm facing an issue which brings me to ask what the proper configuration should be for an outside interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Given the attached diagram and captures, do I have the correct outside interface (vlan.100) configuration?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="diagram" style="width: 517px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67132i8318D328FF439F35/image-size/large?v=v2&amp;amp;px=999" role="button" title="if-cfg-question_202504151350.jpg" alt="diagram" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;diagram&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Outbound traffic from the local users is being NATed to 194.204.1.6&lt;/LI&gt;
&lt;LI&gt;Inbound web traffic from the Internet is being NATed to 194.204.1.10&lt;/LI&gt;
&lt;LI&gt;Inbound FTP traffic from the Internet is being NATed to 194.204.1.11&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Outbound traffic is not reaching Internet because the ARP entry for the default gateway (194.204.1.1) is incomplete in the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="arp-incomplete" style="width: 417px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67133i5B142EAF77690B15/image-size/large?v=v2&amp;amp;px=999" role="button" title="2025-04-15_14-15-22.jpg" alt="arp-incomplete" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;arp-incomplete&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think that is happening because the firewall is sourcing its ARP requests with the network IP (194.204.1.0).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="capture" style="width: 715px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67134iE0CACDC34219169D/image-size/large?v=v2&amp;amp;px=999" role="button" title="2025-04-15_14-04-22.jpg" alt="capture" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;capture&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is that because of my outside interface configuration?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-04-15_13-52-51.jpg" style="width: 840px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67135iF8D5D1023F1AE2E1/image-size/large?v=v2&amp;amp;px=999" role="button" title="2025-04-15_13-52-51.jpg" alt="2025-04-15_13-52-51.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 18:43:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proper-quot-outside-quot-interface-configuration/m-p/1226599#M123998</guid>
      <dc:creator>relayer</dc:creator>
      <dc:date>2025-04-15T18:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Proper "outside" interface configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proper-quot-outside-quot-interface-configuration/m-p/1226605#M123999</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;The only weird thing I saw was that you have 194.204.1.0/26 as an IP address (which its not). However check the routing as well to make sure 0.0.0.0/0 is going to 192.204.1.1 and internal traffic is going to the respective vlan. The traffic logs should show if the traffic is allowed etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 18:44:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proper-quot-outside-quot-interface-configuration/m-p/1226605#M123999</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-04-15T18:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: Proper "outside" interface configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proper-quot-outside-quot-interface-configuration/m-p/1226611#M124004</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;...&lt;SPAN&gt;you have 194.204.1.0/26 as an IP address...&lt;/SPAN&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Thank you for pointing that out, I inherited this configuration and couldn't understand why that is there, unless to make sure that the firewall will claim (from an ARP standpoint) all addresses in the 194.204.1.0/26 range. For instance, when the upstream router wants to deliver a packet for 194.204.1.10, it will ask "Who has 194.204.1.10?", and I thought this part of the interface configuration was responsible for making sure that the firewall replies "I am 194.204.1.10" without having to list all the addresses in that subnet.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 19:01:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proper-quot-outside-quot-interface-configuration/m-p/1226611#M124004</guid>
      <dc:creator>relayer</dc:creator>
      <dc:date>2025-04-15T19:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: Proper "outside" interface configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proper-quot-outside-quot-interface-configuration/m-p/1226612#M124005</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Just add the IP's of NAT policies to the interface is the ARP is send etc. Per your config they would be: 194.204.1.6, 194.204.1.10, and 194.204.1.11&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 19:05:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proper-quot-outside-quot-interface-configuration/m-p/1226612#M124005</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-04-15T19:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: Proper "outside" interface configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proper-quot-outside-quot-interface-configuration/m-p/1226614#M124006</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;Just add the IP's of NAT policies to the interface...&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Ok, like this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;194.204.1.6/26&lt;/P&gt;
&lt;P&gt;194.204.1.10/26&lt;/P&gt;
&lt;P&gt;194.204.1.11/26&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or should the subnet masks be /32?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 19:32:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proper-quot-outside-quot-interface-configuration/m-p/1226614#M124006</guid>
      <dc:creator>relayer</dc:creator>
      <dc:date>2025-04-15T19:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: Proper "outside" interface configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proper-quot-outside-quot-interface-configuration/m-p/1226615#M124007</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Either way would work, I usually go with the /32 myself for preference. Or you can just put the IP and no subnet mask.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 19:36:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proper-quot-outside-quot-interface-configuration/m-p/1226615#M124007</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-04-15T19:36:04Z</dc:date>
    </item>
  </channel>
</rss>

