<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Communication within different Trust Zones in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/communication-within-different-trust-zones/m-p/21375#M15591</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;I am working with PAN-3020 Ver 5.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;I have configured 2 trust zones and 2 untrusted zones with two VRs configured as default routes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;l3-trust IP 192.168.0.254/22; l3-untrust 200.78.x.x&amp;nbsp; ,&amp;nbsp;&amp;nbsp; VR1 (NAT, configured as default route)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;l3-trust2 IP 192.168.10.254/24; l3-untrust2 201.161.x.x ,&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;VR2 (NAT, configured as default route)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;I need that users from l3-trust get access to servers located at l3-trust2.&lt;/P&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;Could you please help how to implement on this scenario?&lt;/P&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Jun 2013 02:18:10 GMT</pubDate>
    <dc:creator>znlwin</dc:creator>
    <dc:date>2013-06-12T02:18:10Z</dc:date>
    <item>
      <title>Communication within different Trust Zones</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/communication-within-different-trust-zones/m-p/21372#M15588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working with PAN-500 3.0.9.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured 2 trust zones and 2 untrusted zones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;l3-trust IP 192.168.0.254/22; l3-untrust 200.78.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;l3-trust2 IP 192.168.10.254/24; l3-untrust 201.161.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need that users from l3-trust get access to servers located at l3-trust2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have this policy:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From l3-trust2 to l3-trust source address 192.168.10.0/24 destination address 192.168.0.10-192.168.0.25 Action Allow.&lt;/P&gt;&lt;P&gt;From l3-trust to l3-trust2 source address 192.168.0.10-192.168.0.25 destination address 192.168.10.0/24 Action Allow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now, this is not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you could help me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 May 2010 19:26:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/communication-within-different-trust-zones/m-p/21372#M15588</guid>
      <dc:creator>BBDOmexico</dc:creator>
      <dc:date>2010-05-26T19:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Communication within different Trust Zones</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/communication-within-different-trust-zones/m-p/21373#M15589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;you sceneario looks very straight forward.&lt;/P&gt;&lt;P&gt;I would verify the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. the l3-trust and l3-trust2 interfaces are on the same virtual router on the Paloalto device&lt;/P&gt;&lt;P&gt;2. Are there any NAT rules that any of the traffic between these two zones could be catching.....for example do you have a NAT rule that says source zone: l3-trust and destination zone any....&lt;/P&gt;&lt;P&gt;3. For now you can make sure that the application and the service are both set "any"......this of course is only while you are troubleshooting to illiminate the possibility of you not allowing the applications you are expecting to pass traffic (...like ping)&lt;/P&gt;&lt;P&gt;4. You can set the source and destination addresses to any also....this is to make sure that you did not make mistake while typing in the source and destination address or while creating the address objects.&lt;/P&gt;&lt;P&gt;5. Verify the routing in your network. Basically make sure that the network that when the network 192.168.0.254 tries to route to 192.168.10.x, it is pointed to the Paloalto device....check this going the other way also. Please be dilligent is checking the routing as this is often the root of issues like this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are still having issues after checking the above then please call into support and we can aid in isolating the source of this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 May 2010 21:00:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/communication-within-different-trust-zones/m-p/21373#M15589</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-05-26T21:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Communication within different Trust Zones</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/communication-within-different-trust-zones/m-p/21374#M15590</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt; The similar problem we also facing...both the trust and trust2 communication is happening if i put NAT rule (likey source zone trust and destination zone trust2 and destination interface should be the trust interface) then its working...though some time ICMP is not working between two trust zones where as FTP and remote desktop is working..the same as been tested with different OS and different model of PAN.suggest me to fix this problem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jun 2010 10:45:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/communication-within-different-trust-zones/m-p/21374#M15590</guid>
      <dc:creator>veera12883</dc:creator>
      <dc:date>2010-06-08T10:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: Communication within different Trust Zones</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/communication-within-different-trust-zones/m-p/21375#M15591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;I am working with PAN-3020 Ver 5.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;I have configured 2 trust zones and 2 untrusted zones with two VRs configured as default routes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;l3-trust IP 192.168.0.254/22; l3-untrust 200.78.x.x&amp;nbsp; ,&amp;nbsp;&amp;nbsp; VR1 (NAT, configured as default route)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;l3-trust2 IP 192.168.10.254/24; l3-untrust2 201.161.x.x ,&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;VR2 (NAT, configured as default route)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;I need that users from l3-trust get access to servers located at l3-trust2.&lt;/P&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;Could you please help how to implement on this scenario?&lt;/P&gt;&lt;P style="font-weight: normal; font-style: normal; font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; text-align: left; text-indent: 0px; background-color: #ffffff;"&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 02:18:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/communication-within-different-trust-zones/m-p/21375#M15591</guid>
      <dc:creator>znlwin</dc:creator>
      <dc:date>2013-06-12T02:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: Communication within different Trust Zones</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/communication-within-different-trust-zones/m-p/21376#M15592</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi znlwin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VR1 you have to add route 192.168.10.0/24 next VR VR2 &lt;/P&gt;&lt;P&gt;VR2 you have to add route 192.168.0.0./24 next VR&amp;nbsp; VR1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 06:37:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/communication-within-different-trust-zones/m-p/21376#M15592</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-12T06:37:44Z</dc:date>
    </item>
  </channel>
</rss>

