<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote site internet in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/remote-site-internet/m-p/35825#M26335</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible for you to setup a simple drawing for how everything is connected?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As debug (if possible) you could in the PA setup a rule at top which says:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From zone: Any&lt;/P&gt;&lt;P&gt;From address: Any&lt;/P&gt;&lt;P&gt;From user: Any&lt;/P&gt;&lt;P&gt;To zone: Any&lt;/P&gt;&lt;P&gt;To address: Any&lt;/P&gt;&lt;P&gt;Application: Any&lt;/P&gt;&lt;P&gt;Service: Any&lt;/P&gt;&lt;P&gt;Action: Allow&lt;/P&gt;&lt;P&gt;Options: Log on session start + Log on session end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above would allow anything back and forth through your PA. The idea is if the above doesnt work then you have a malfunction regarding routing OR nating in your PA-box - or something bad going on at your remotesite.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I would verifiy that the routing is correct at the PA-box (so the PA-box knows which interface to use to reach your remote site) but also verify so NAT-rules (if any) are correctly setup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 28 Jan 2013 19:03:56 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-01-28T19:03:56Z</dc:date>
    <item>
      <title>Remote site internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remote-site-internet/m-p/35824#M26334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello- Just recently migrated from an old Checkpoint to a PA-500. PA is setup in a Layer 3 configuration. So far so good with the exception of one thing. My remote location isn't able to get internet access. This remote location gets internet from my head end location as they do not have their own internet circuit. Everything for internal access works perfectly. This was working with the previous Checkpoint so it isn't a routing issue at the remote location. If I do a tracert from that remote location the trace stops at the trusted interface of the PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an outbound rule in place from Trust to Untrust and any application, but this is obviously not covering it for this remote location. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advice? I feel like I'm missing something really, really simple here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jan 2013 18:56:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remote-site-internet/m-p/35824#M26334</guid>
      <dc:creator>CCANCIENNE</dc:creator>
      <dc:date>2013-01-28T18:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: Remote site internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remote-site-internet/m-p/35825#M26335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible for you to setup a simple drawing for how everything is connected?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As debug (if possible) you could in the PA setup a rule at top which says:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From zone: Any&lt;/P&gt;&lt;P&gt;From address: Any&lt;/P&gt;&lt;P&gt;From user: Any&lt;/P&gt;&lt;P&gt;To zone: Any&lt;/P&gt;&lt;P&gt;To address: Any&lt;/P&gt;&lt;P&gt;Application: Any&lt;/P&gt;&lt;P&gt;Service: Any&lt;/P&gt;&lt;P&gt;Action: Allow&lt;/P&gt;&lt;P&gt;Options: Log on session start + Log on session end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above would allow anything back and forth through your PA. The idea is if the above doesnt work then you have a malfunction regarding routing OR nating in your PA-box - or something bad going on at your remotesite.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I would verifiy that the routing is correct at the PA-box (so the PA-box knows which interface to use to reach your remote site) but also verify so NAT-rules (if any) are correctly setup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jan 2013 19:03:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remote-site-internet/m-p/35825#M26335</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-01-28T19:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Remote site internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remote-site-internet/m-p/35826#M26336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Drawing attached... Wondering if this a NAT issue since you mentioned it. Outside of the Top Level NAT rule I created when doing the layer 3 configuration I have no NAT rules in place specifically for the remote site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="WAN.JPG" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/5372_WAN.JPG" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jan 2013 19:57:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remote-site-internet/m-p/35826#M26336</guid>
      <dc:creator>CCANCIENNE</dc:creator>
      <dc:date>2013-01-28T19:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Remote site internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remote-site-internet/m-p/35827#M26337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Issue resolved. I ended up opening a ticket with PA.&lt;/P&gt;&lt;P&gt;-Added a static route to the default virtual route for the specific location's network.&lt;/P&gt;&lt;P&gt;Thanks mikand for the initial help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2013 15:13:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remote-site-internet/m-p/35827#M26337</guid>
      <dc:creator>CCANCIENNE</dc:creator>
      <dc:date>2013-01-29T15:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: Remote site internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remote-site-internet/m-p/35828#M26338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You already had:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route 0.0.0.0/0 nexthop internetrouter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you added:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route &amp;lt;remotesite&amp;gt;/&amp;lt;range&amp;gt; nexthop &amp;lt;headendrouter&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2013 16:46:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remote-site-internet/m-p/35828#M26338</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-01-29T16:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: Remote site internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remote-site-internet/m-p/35829#M26339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2013 16:49:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remote-site-internet/m-p/35829#M26339</guid>
      <dc:creator>CCANCIENNE</dc:creator>
      <dc:date>2013-01-29T16:49:48Z</dc:date>
    </item>
  </channel>
</rss>

