<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Internal route problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/internal-route-problem/m-p/18400#M13429</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Had a question about internal routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have eth port assigned to a trust network which is a 192.168 network.&amp;nbsp; We also have a Avaya VoIP PBX that is vLan'd on this network and the routing is managed on an internal core switch to access this network.&amp;nbsp; In our single virtual router I have a route for the 192.168.0.00/16 with next hop to the Gateway.&amp;nbsp; I also have a network and an additional 172.16.0.0/17 route with a next hop to the core switch.&amp;nbsp; We put our PAN2020's in place this past weekend, and our old firewall had a static route for the phone system exactly like this.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to ping the phone server at the 172.16.x.x range, and can traceroute it as well (however the first hop times out). However trying to access the web management of the server, or using a service tool, or any application that can connect into the phone server fails. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I monitor the connections on the firewall, it just say the applications are incomplete as if it makes the connection, but does not return the connection. What am I missing?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Jun 2012 17:21:14 GMT</pubDate>
    <dc:creator>cmateam</dc:creator>
    <dc:date>2012-06-26T17:21:14Z</dc:date>
    <item>
      <title>Internal route problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-route-problem/m-p/18400#M13429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Had a question about internal routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have eth port assigned to a trust network which is a 192.168 network.&amp;nbsp; We also have a Avaya VoIP PBX that is vLan'd on this network and the routing is managed on an internal core switch to access this network.&amp;nbsp; In our single virtual router I have a route for the 192.168.0.00/16 with next hop to the Gateway.&amp;nbsp; I also have a network and an additional 172.16.0.0/17 route with a next hop to the core switch.&amp;nbsp; We put our PAN2020's in place this past weekend, and our old firewall had a static route for the phone system exactly like this.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to ping the phone server at the 172.16.x.x range, and can traceroute it as well (however the first hop times out). However trying to access the web management of the server, or using a service tool, or any application that can connect into the phone server fails. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I monitor the connections on the firewall, it just say the applications are incomplete as if it makes the connection, but does not return the connection. What am I missing?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2012 17:21:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-route-problem/m-p/18400#M13429</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2012-06-26T17:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: Internal route problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-route-problem/m-p/18401#M13430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm having an internal routing issue still....anyone? anyone? I opened a support case last night but have not heard anything more.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2012 14:44:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-route-problem/m-p/18401#M13430</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2012-07-11T14:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: Internal route problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-route-problem/m-p/18402#M13431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any chances of asymmetric routing : refer &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1260"&gt;https://live.paloaltonetworks.com/docs/DOC-1260&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If not, check the security rules if its missing the application .&lt;/P&gt;&lt;P&gt;Add a test rule allowing Application any between the source and destination and place this rule at the top.&amp;lt;commit&amp;gt;&lt;/P&gt;&lt;P&gt;If this works ,monitor the traffic log for this rule ,delete the test rule and change the original security-rule accommodating the Applications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ameya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2012 19:26:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-route-problem/m-p/18402#M13431</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2012-07-11T19:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Internal route problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-route-problem/m-p/18403#M13432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you so much!&amp;nbsp; That did the trick!&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2012 19:45:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-route-problem/m-p/18403#M13432</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2012-07-11T19:45:20Z</dc:date>
    </item>
  </channel>
</rss>

