<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: L3 gateway Interface traffic relaying in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/l3-gateway-interface-traffic-relaying/m-p/50576#M37242</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like you need a route for &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13.3333330154419px;"&gt;192.168.50.0/24 on the firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Feb 2015 13:18:41 GMT</pubDate>
    <dc:creator>ITNetworksTeam</dc:creator>
    <dc:date>2015-02-25T13:18:41Z</dc:date>
    <item>
      <title>L3 gateway Interface traffic relaying</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/l3-gateway-interface-traffic-relaying/m-p/50574#M37240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;just want to share one thought about problem which I faced with. One of L3 interface on PAN 500 was configured as default gateway (192.168.0.1/24 sec zone "trusted") for one network. On that trusted network I have two servers, one terminal 192.168.0.10/24 and VPN 192.168.0.15/24. VPN clients with IP pool 192.168.50.0/24 are making connection's to terminal server. Response going through gateway interface 192.168.0.1, where vrouter has route 192.168.50.0/24 via 192.168.0.15/24. Problem begins in moment when terminal server had to make connection to VPN client, but it didn't. To cope with problem only solution is to add static route to terminal server &lt;SPAN style="font-size: 13.3333330154419px;"&gt;192.168.50.0/24 via 192.168.0.15/24, and then working as well (bypassing default gateway). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;If considering that traffic by default were permitted within same security zone, I'm unable to understand why traffic cannot be relayed even I make explicit policy, which permits all traffic within trusted zone. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;From perspective of securing traffic, there is no needed any filtering, just traffic relaying within same subnet and same sec zone. Before this setup we have some simple linux firewall with ip tables, where this working, without sec rule, just routing and relaying.....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;Tician &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2015 10:36:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/l3-gateway-interface-traffic-relaying/m-p/50574#M37240</guid>
      <dc:creator>Tician</dc:creator>
      <dc:date>2015-02-23T10:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: L3 gateway Interface traffic relaying</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/l3-gateway-interface-traffic-relaying/m-p/50575#M37241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tician,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First of all I would recommend opening a case with tech support. There are a few things that could go wrong here so I would start with the traffic logs. If you have an explicit rule in place there should be logging for the session to verify it is allowed and the log details will confirm if packets are being sent and received. Assuming everything looks ok here try running a packet capture with filters for both directions (.10 to .15 and vice versa) and all 4 stages set. The drop stage will show if anything is being dropped out and counters may give the reason for any drops. This doc should help with setting up the filters and checking the counters. &lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1506"&gt;Packet Capture, Debug Flow-basic and Counter Commands&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Brandon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2015 06:03:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/l3-gateway-interface-traffic-relaying/m-p/50575#M37241</guid>
      <dc:creator>bfarely</dc:creator>
      <dc:date>2015-02-25T06:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: L3 gateway Interface traffic relaying</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/l3-gateway-interface-traffic-relaying/m-p/50576#M37242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like you need a route for &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13.3333330154419px;"&gt;192.168.50.0/24 on the firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2015 13:18:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/l3-gateway-interface-traffic-relaying/m-p/50576#M37242</guid>
      <dc:creator>ITNetworksTeam</dc:creator>
      <dc:date>2015-02-25T13:18:41Z</dc:date>
    </item>
  </channel>
</rss>

