<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Home configuration PA-200 help in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/68074#M39785</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Looks like your default route is pointing at interface Ethernet1/1. It should be pointing to the next hop gateway. I also see that the same IP for Ethernet1/1 is he same one for your ISP router. It may help us help you if you can tell us how the two devices are connected and how they are to operate. ISP router -&amp;gt; PAN -&amp;gt; teust network or PAN -&amp;gt;ISP router -&amp;gt; trust network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also make sure your policies are allowing the traffic, trust -&amp;gt;untrust. (this is not pictured) also do you have a NAT for the internal traffic to the untrust network?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for the layer 2 interface and layer 3vlan. that part looks OK so far.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Fri, 13 Nov 2015 00:27:46 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2015-11-13T00:27:46Z</dc:date>
    <item>
      <title>Home configuration PA-200 help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/68071#M39782</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Im new to this and im trying to install a pa-200 at home. I have managed to install it in a layer 2 configuration but i would like to install it now in a layer 3 configuration.&lt;/P&gt;
&lt;P&gt;I have followed this article &lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Setting-Up-the-PA-200-for-Home-and-Small-Office/ta-p/61838" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Setting-Up-the-PA-200-for-Home-and-Small-Office/ta-p/61838&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;but without success.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Equipment&lt;/P&gt;
&lt;P&gt;-pa-200&lt;/P&gt;
&lt;P&gt;- isp modem&lt;/P&gt;
&lt;P&gt;- switch&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These are the settings that i get on the isp&amp;nbsp;modem.&lt;/P&gt;
&lt;P&gt;&lt;IMG title="modem.png" alt="modem.png" src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1171i7F61DD42C255C6A4/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and here are some config pictures&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interfaces&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG title="interfaces.png" alt="interfaces.png" src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1172i71E351C9BBE6FE6F/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;vlan&lt;/P&gt;
&lt;P&gt;&lt;IMG title="vlan1.png" alt="vlan1.png" src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1173i573DEF0B3B5BDF5B/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG title="vlan2.png" alt="vlan2.png" src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1174i5F8D473956C03612/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;zones&lt;/P&gt;
&lt;P&gt;&lt;IMG title="dhcp.png" alt="dhcp.png" src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1175iFFD3666FFD6F3DCB/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;virtual router&lt;/P&gt;
&lt;P&gt;&lt;IMG title="virtual router.png" alt="virtual router.png" src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1176i865CEF28CCF34266/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG title="vr2.png" alt="vr2.png" src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1177i49454DCD069CF46C/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dhcp&lt;/P&gt;
&lt;P&gt;&lt;IMG title="dhcp.png" alt="dhcp.png" src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1178i290F60E1FC2CC643/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some suggestions / advice would be helpfull because im stuck.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tnx!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 23:43:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/68071#M39782</guid>
      <dc:creator>Florin.Chirla</dc:creator>
      <dc:date>2015-11-12T23:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: Home configuration PA-200 help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/68074#M39785</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Looks like your default route is pointing at interface Ethernet1/1. It should be pointing to the next hop gateway. I also see that the same IP for Ethernet1/1 is he same one for your ISP router. It may help us help you if you can tell us how the two devices are connected and how they are to operate. ISP router -&amp;gt; PAN -&amp;gt; teust network or PAN -&amp;gt;ISP router -&amp;gt; trust network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also make sure your policies are allowing the traffic, trust -&amp;gt;untrust. (this is not pictured) also do you have a NAT for the internal traffic to the untrust network?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for the layer 2 interface and layer 3vlan. that part looks OK so far.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 00:27:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/68074#M39785</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-11-13T00:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: Home configuration PA-200 help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/68076#M39787</link>
      <description>&lt;P&gt;Your ISP modem needs to be set in bridge mode if you're going to put the firewall's external interface in L3. Both can't have the same external IP address. At least in the US, many common ISPs like Comcast and AT&amp;amp;T will not help you with configuration or connectivity issues if the modem is in bridge mode, so do that at your own risk (if your ISP even lets you do it).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The other option would be to set your external L3 interface to something on the modem's LAN interface, 192.168.0.1 (it's probably a /24, but that's not shown on your modem's screenshot). You'll probably want to separate your internal LAN interface with a different subnet as well, just to keep it very clear what is internal and what is external.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;Greg&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 00:50:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/68076#M39787</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2015-11-13T00:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: Home configuration PA-200 help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/68088#M39792</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;first tnx for your answer.&lt;/P&gt;
&lt;P&gt;So i have changed ethernet 1/1 to an intern adress (192.168.0.130)&lt;/P&gt;
&lt;P&gt;and vlan to 192.168.0.254/25&lt;/P&gt;
&lt;P&gt;the next hop on the router is now 192.168.0.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1182i1B1A34A537898B69/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="2015-11-13 09_07_17-FLORIN-LPT - TeamViewer.png" title="2015-11-13 09_07_17-FLORIN-LPT - TeamViewer.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the configuration is ISP modem - PA-200 - switch to trust network - trust network (computers)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here are the pictures for the policies and nat rule&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1179iE22C3353AC599C23/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="2015-11-13 08_59_02-FLORIN-LPT - TeamViewer.png" title="2015-11-13 08_59_02-FLORIN-LPT - TeamViewer.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1180i81664723A392EDF3/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="2015-11-13 08_57_58-FLORIN-LPT - TeamViewer.png" title="2015-11-13 08_57_58-FLORIN-LPT - TeamViewer.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and also a picture of a traceroute before the firewall setup&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1181i0861CF3119AD9E9D/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="2015-11-13 08_15_54-FLORIN-LPT - TeamViewer.png" title="2015-11-13 08_15_54-FLORIN-LPT - TeamViewer.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but its still not moving &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 08:19:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/68088#M39792</guid>
      <dc:creator>Florin.Chirla</dc:creator>
      <dc:date>2015-11-13T08:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Home configuration PA-200 help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/68090#M39793</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28203"&gt;@gwesson﻿&lt;/a&gt;&amp;nbsp;you are right 2 devices cant have the same ip adres &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; so i have changed it now to an intern adress 192.168.0.130&lt;/P&gt;
&lt;P&gt;I cant set the modem to bridged ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And the lan interface that i get from the modem is indeed a /24&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This config doesent want to work either&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tnx again&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 08:18:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/68090#M39793</guid>
      <dc:creator>Florin.Chirla</dc:creator>
      <dc:date>2015-11-13T08:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Home configuration PA-200 help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/68091#M39794</link>
      <description>&lt;P&gt;Hi Florin&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you'll probably want to set the untrust interface to 192.168.0.x/24, default gateway routing to 192.168.0.1,the trust interface to a completely different subnet, like 10.0.0.1/24, then configure NAT and enable a DHCP server on the trust interface&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please take a look at these "getting started" articles we've created to help you get on your way:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px; padding: 0px; color: #333333; font-family: Lato, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 20px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px;"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-preparing-the-firewall/ta-p/66582" target="_self"&gt;I've unpacked my firewall, now what?&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0px; padding: 0px; color: #333333; font-family: Lato, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 20px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px;"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-layer3-NAT-DHCP/ta-p/66999" target="_self"&gt;I've unpacked my firewall and did what you told me, now what?&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0px; padding: 0px; color: #333333; font-family: Lato, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 20px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px;"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-layer3-subinterfaces/ta-p/67395" target="_self"&gt;I've unpacked my firewall and want to configure VLANs — subinterfaces&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0px; padding: 0px; color: #333333; font-family: Lato, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 20px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px;"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Logging/ta-p/67638" target="_self"&gt;I’ve unpacked my firewall, but where are the logs?&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 08:57:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/68091#M39794</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-11-13T08:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: Home configuration PA-200 help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/68146#M39813</link>
      <description>&lt;P&gt;It works&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tnx!&lt;/P&gt;</description>
      <pubDate>Sat, 14 Nov 2015 11:11:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/68146#M39813</guid>
      <dc:creator>Florin.Chirla</dc:creator>
      <dc:date>2015-11-14T11:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: Home configuration PA-200 help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/76389#M42298</link>
      <description>&lt;P&gt;The device you show as your modem is actually a&amp;nbsp;layer3 device&amp;nbsp;doing NAT.&lt;/P&gt;
&lt;P&gt;If you want to hook up your firewall in Layer3 mode, then the Untrusted network for the firewall will be in the 192.168.0.0/24 network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is likely that the modem will give you an IP by DHCP in this network.&lt;/P&gt;
&lt;P&gt;You could ignore DHCP and set your Ethernet1/1 with IP 192.168.0.2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Add a default route in your VR making 0.0.0.0 point to 192.168.0.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your LAN needs to be a different subnet than 192.168.0.0/24, so make sure you configure a different one in your DHCP server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you ever want to make any servers visible in the outside, you will have to configure a double Destination NAT setup, forward first in your modem, or try configuring what they call a DMZ Host (all ports in UDP and TCP forwarded to a single host). The full forward should point to 192.168.0.2 (your firewall's untrust interface in Ethernet1/1). The second DNAT jump is configured in the firewall with a DNAT policy.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 01:28:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/home-configuration-pa-200-help/m-p/76389#M42298</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2016-04-14T01:28:58Z</dc:date>
    </item>
  </channel>
</rss>

