<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ping thru device and static route qestion in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ping-thru-device-and-static-route-qestion/m-p/21858#M15963</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. Your ping is failing because your interface isn't connected to anything. If you're sourcing your ping from Ethernet1/2, which is showing as configured but down, there is no way it could work. Even though your default gateway is set to use Eth1/1, since that interface is legitimately down, the packet cannot be sent using that interface. It works without specifying the interface because it uses the management interface as you guessed.&lt;/P&gt;&lt;P&gt;2. Since your Ethernet1/1 (ISP interface) is DHCP, the default gateway is configured by your ISP and there is no need to configure the 0.0.0.0/0 route on Eth1/1. You can remove that static route from your virtual router since it is not needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Apr 2015 18:58:18 GMT</pubDate>
    <dc:creator>gwesson</dc:creator>
    <dc:date>2015-04-02T18:58:18Z</dc:date>
    <item>
      <title>Ping thru device and static route qestion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-thru-device-and-static-route-qestion/m-p/21857#M15962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i have one 2050n device in my lab; device is running 4.1.6.&lt;/P&gt;&lt;P&gt;Interface 1/1 is configured for as dhcp client and i am able to ping update server and obtain dynamic updates. I have no devices/clients connected to inside LAN. Inside lan is on ethernet 1/2.&lt;/P&gt;&lt;P&gt;Interfaces 1/2 and 1/1 are setup for L3, zone is default (trust/untrust) with interface assigned to appropriate zones.&lt;/P&gt;&lt;P&gt;i setup ethernet 1/2 with ip address of internal LAN (10.1.1.1/24) but it is not physically connected to any switch or other devices. it shows interface 1/2 is configured but down (red link state).&lt;/P&gt;&lt;P&gt;Security policy is to allow any any from trust to untrust.&lt;/P&gt;&lt;P&gt;Virtual router is setup with default settings, both interfaces (1/1 and 1/2) are in virtual router, static route is setup for destination 0.0.0.0/0 on interface 1/1. If i try to enter default gateway in static route as a next hop, the commit is failing. Only way to get commit not to fail is to have Next hop - None. &lt;/P&gt;&lt;P&gt;Question 1:&lt;/P&gt;&lt;P&gt;i tried to use ping command from PAN CLI and not getting any response if i do following:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ping source 10.1.1.1 host 8.8.8.8&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;if i do &lt;STRONG&gt;ping host 8.8.8.8&lt;/STRONG&gt; = ping is fine (i am guessing in this case source is management interface)&lt;/P&gt;&lt;P&gt;Why i am unable to ping using source interface of 10.1.1.1?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question 2: &lt;/P&gt;&lt;P&gt;Is there are a reason why commit is failing when adding static route to use default gateway provided by ISP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your responses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Mar 2015 21:53:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-thru-device-and-static-route-qestion/m-p/21857#M15962</guid>
      <dc:creator>Dragan</dc:creator>
      <dc:date>2015-03-30T21:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: Ping thru device and static route qestion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-thru-device-and-static-route-qestion/m-p/21858#M15963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. Your ping is failing because your interface isn't connected to anything. If you're sourcing your ping from Ethernet1/2, which is showing as configured but down, there is no way it could work. Even though your default gateway is set to use Eth1/1, since that interface is legitimately down, the packet cannot be sent using that interface. It works without specifying the interface because it uses the management interface as you guessed.&lt;/P&gt;&lt;P&gt;2. Since your Ethernet1/1 (ISP interface) is DHCP, the default gateway is configured by your ISP and there is no need to configure the 0.0.0.0/0 route on Eth1/1. You can remove that static route from your virtual router since it is not needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 18:58:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-thru-device-and-static-route-qestion/m-p/21858#M15963</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2015-04-02T18:58:18Z</dc:date>
    </item>
  </channel>
</rss>

