<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto in Virtual Wire mode :  Traffic not passing throught internet perimeter Firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67394#M39509</link>
    <description>&lt;P&gt;Because when i disable permit any any rule.. there is no log about that. I will try to make deny any any rule before i disable permit any any rule so i can get the log about that. Once more i wanna ask, do i need to permit rule from untrust to trust for spesific application or port like http/web browsing or https/sll, or something like that?&lt;/P&gt;</description>
    <pubDate>Wed, 28 Oct 2015 10:14:30 GMT</pubDate>
    <dc:creator>gabriel.simatupang</dc:creator>
    <dc:date>2015-10-28T10:14:30Z</dc:date>
    <item>
      <title>Palo Alto in Virtual Wire mode :  Traffic not passing throught internet perimeter Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67251#M39479</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN class="hps"&gt;I&lt;/SPAN&gt;&lt;SPAN class=""&gt;'m&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;doing&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;POC &lt;/SPAN&gt;&lt;SPAN class="hps"&gt;at&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;customer who use&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;Checkpoint as Internet Firewall. So i deploy Palo Alto behind Checkpoint firewall in vwire mode. After We configure and install policy everything running well and to minimize the risk we configure permit all any any in the bottom of security policy. At the end of the PoC we try to disable the Permit all rule, but traffic not passing throught. Is there is any port or application or something i need to allow from palo alto? or there is spesific port from checkpoint i need to allow?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN class="hps"&gt;My rule style is like this:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN class="hps"&gt;- permit spesific plus security profile&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN class="hps"&gt;- permit General plus security profile&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN class="hps"&gt;- permit any any&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;SPAN class="short_text"&gt;&lt;SPAN class="hps"&gt;Topology:&amp;nbsp; Router----Checkpoint----Paloalto-----Switch&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 04:35:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67251#M39479</guid>
      <dc:creator>gabriel.simatupang</dc:creator>
      <dc:date>2015-10-26T04:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto in Virtual Wire mode :  Traffic not passing throught internet perimeter Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67252#M39480</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;What does the traffic log say? Do you see the sessions? Are they allowed or denied?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 07:02:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67252#M39480</guid>
      <dc:creator>mvidic</dc:creator>
      <dc:date>2015-10-26T07:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto in Virtual Wire mode :  Traffic not passing throught internet perimeter Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67254#M39481</link>
      <description>&lt;P&gt;Hi Gabriel&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you switch the permit any rule to a block any rule, you should see what is being blocked exactly. This can help you pinpoint any service that may need to pass though.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you verify in the traffic logs that the source and destination zones are correct? A common issue with vwire configuration is that trust and untrust get switched by accidentally switching the cables. If you then disable the any rule traffic will start getting blocked as it is flowing in the "wrong" direction.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 08:25:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67254#M39481</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-10-26T08:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto in Virtual Wire mode :  Traffic not passing throught internet perimeter Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67271#M39485</link>
      <description>&lt;P&gt;Hi Gabriel,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please check &amp;nbsp;all licenses are activated or not. if yes than check the your network configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Satish&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 11:46:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67271#M39485</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2015-10-26T11:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto in Virtual Wire mode :  Traffic not passing throught internet perimeter Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67294#M39492</link>
      <description>&lt;P&gt;Check the logs for the original permit rule and you will see what traffic is hitting this even before you turn it off or to block.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 22:58:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67294#M39492</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-10-26T22:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto in Virtual Wire mode :  Traffic not passing throught internet perimeter Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67394#M39509</link>
      <description>&lt;P&gt;Because when i disable permit any any rule.. there is no log about that. I will try to make deny any any rule before i disable permit any any rule so i can get the log about that. Once more i wanna ask, do i need to permit rule from untrust to trust for spesific application or port like http/web browsing or https/sll, or something like that?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 10:14:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67394#M39509</guid>
      <dc:creator>gabriel.simatupang</dc:creator>
      <dc:date>2015-10-28T10:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto in Virtual Wire mode :  Traffic not passing throught internet perimeter Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67398#M39511</link>
      <description>&lt;P&gt;You can override last default inter zone rule and enable logging traffic that matches that rule.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 11:58:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67398#M39511</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-10-28T11:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto in Virtual Wire mode :  Traffic not passing throught internet perimeter Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67422#M39521</link>
      <description>&lt;P&gt;Gabriel,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rules are only needed in the zone direction for which the traffic is initiated at the tcp level. &amp;nbsp;You do not need a matching reverse direction rule as the firewall is "stateful" and aware of the session traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So web browsing (http/https) from trust to untrust only needs a permit rule from trust to untrust. &amp;nbsp;You do not need an untrust to trust rule for this to work.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 22:38:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/67422#M39521</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-10-28T22:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto in Virtual Wire mode :  Traffic not passing throught internet perimeter Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/1250146#M126140</link>
      <description>&lt;P&gt;I know this one is very old but the provided solution was not working for me. I experienced the issue that i've configured the virtual wire like described on documentation and traffic forwarding and DHCP was not working. In my environment I use ESXI 7.0 Update 3. Palo Alto VM 11.2.10h3 as edge FW and 12.1.5 as virtual wire. Client behind didn't get any IP and saw no ARPs. The problem was on the ESXI virtual switch. The solution was:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Create two Port Groups (e.g., vWire-Outside and vWire-Inside) on your VSwitch.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Crucial:&lt;/STRONG&gt; On both Port Groups, set &lt;STRONG&gt;Promiscuous Mode&lt;/STRONG&gt;, &lt;STRONG&gt;MAC Address Changes&lt;/STRONG&gt;, and &lt;STRONG&gt;Forged Transmits&lt;/STRONG&gt; to &lt;STRONG&gt;Accept&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Add two network adapters to the Palo Alto VM: one for each port group&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 13 Mar 2026 11:15:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/1250146#M126140</guid>
      <dc:creator>K.Kreilos</dc:creator>
      <dc:date>2026-03-13T11:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto in Virtual Wire mode :  Traffic not passing throught internet perimeter Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/1250158#M126142</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/859136773"&gt;@K.Kreilos&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P data-path-to-node="3"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="4"&gt;Thank for sharing this!&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;This is a perfect reminder for anyone running a lab or a virtual edge on 11.2 or 12.1.&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;Thanks again for taking the time to post the specific fix!&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2026 13:19:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-in-virtual-wire-mode-traffic-not-passing-throught/m-p/1250158#M126142</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2026-03-13T13:19:18Z</dc:date>
    </item>
  </channel>
</rss>

