<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic icmp redirect support in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/icmp-redirect-support/m-p/23427#M17076</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;simple question:&lt;/P&gt;&lt;P&gt;Does PA devices send / support icmp redirect ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use case:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA device is the default GW for local LAN subnet (A).&lt;/P&gt;&lt;P&gt;PA device has a route to an another subnet (B). The next hop is on his LAN Interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Local Clients devices has only a default GW to PA LAN Interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my understanding and some tests:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA device does not send ICMP redirect to Local Clients when they try to reach another subnet (B).&lt;/P&gt;&lt;P&gt;icmp echo / reply are OK but other type of communications fall with strange behavior on monitor. Traffic form local subnet are seen from his outside interface (not the lan) with destination NAT etc... Traffic seems to "loop" on the PA device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If The local Client have a static route for B subnet everything is ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guillaume&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Jul 2013 15:07:16 GMT</pubDate>
    <dc:creator>glebon</dc:creator>
    <dc:date>2013-07-18T15:07:16Z</dc:date>
    <item>
      <title>icmp redirect support</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/icmp-redirect-support/m-p/23427#M17076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;simple question:&lt;/P&gt;&lt;P&gt;Does PA devices send / support icmp redirect ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use case:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA device is the default GW for local LAN subnet (A).&lt;/P&gt;&lt;P&gt;PA device has a route to an another subnet (B). The next hop is on his LAN Interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Local Clients devices has only a default GW to PA LAN Interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my understanding and some tests:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA device does not send ICMP redirect to Local Clients when they try to reach another subnet (B).&lt;/P&gt;&lt;P&gt;icmp echo / reply are OK but other type of communications fall with strange behavior on monitor. Traffic form local subnet are seen from his outside interface (not the lan) with destination NAT etc... Traffic seems to "loop" on the PA device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If The local Client have a static route for B subnet everything is ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guillaume&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 15:07:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/icmp-redirect-support/m-p/23427#M17076</guid>
      <dc:creator>glebon</dc:creator>
      <dc:date>2013-07-18T15:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: cimp redirect support</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/icmp-redirect-support/m-p/23428#M17077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exact, no icmp redirect in the palo.&lt;/P&gt;&lt;P&gt;But if yo just want your laptop be able to access to subnet B, two cases:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subnet B is connected to another Palo's interface then just need security rle for allowing traffic from Zone-Sub-A to Zone-Sub-B&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subnet B is not connected, then need same thing plus a route in your Vrouter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sense ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 16:36:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/icmp-redirect-support/m-p/23428#M17077</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-07-18T16:36:42Z</dc:date>
    </item>
    <item>
      <title>Re: cimp redirect support</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/icmp-redirect-support/m-p/23429#M17078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks you for your time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In fact Subnet B is a remote location.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Connectivity to branch offices (like B) pass through a router provided by an ISP which has an interface on local subnet A (the next hop used on the vr of the PA).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With static route on the host on subnet A it works but for admin purpose it is not optimal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guillaume&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jul 2013 06:47:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/icmp-redirect-support/m-p/23429#M17078</guid>
      <dc:creator>glebon</dc:creator>
      <dc:date>2013-07-19T06:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: cimp redirect support</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/icmp-redirect-support/m-p/23430#M17079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Static route not on the host but on the Palo &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Or if you've got time, configured dynamic routing like OSPF &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jul 2013 09:51:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/icmp-redirect-support/m-p/23430#M17079</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-07-19T09:51:52Z</dc:date>
    </item>
  </channel>
</rss>

