<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with my Palo Alto Lab in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73720#M41513</link>
    <description>&lt;P&gt;It's working ! I had a NAT in-place but it was wrong . I fixed it and it worked.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 27 Feb 2016 19:18:27 GMT</pubDate>
    <dc:creator>akhalighi</dc:creator>
    <dc:date>2016-02-27T19:18:27Z</dc:date>
    <item>
      <title>Issue with my Palo Alto Lab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73643#M41484</link>
      <description>&lt;P&gt;Hello folks&lt;BR /&gt;&lt;BR /&gt;I have a strange issue in my lab , here is the scenario :&lt;BR /&gt;&lt;BR /&gt;VM-100 on ESXi &lt;BR /&gt;PAN OS 7.0.5&lt;BR /&gt;Inside interface connected to internal zone (10.0.1.0/24 network) &lt;BR /&gt;outside interface connected to my home firewall ( 192.168.1.0/24 network) &lt;BR /&gt;&lt;BR /&gt;Interfaces have IPs on the same range as their zones : 10.0.1.10 inside interface , 192.168.1.10 outside. &lt;BR /&gt;Modem IP is 192.168.1.1 &lt;BR /&gt;&lt;BR /&gt;- Lab workstations can ping inside interface successfully &lt;BR /&gt;- Firewall DNS is working , able to download URL filtering database , able to resolve DNS via outside interface&lt;BR /&gt;- Created a universal policy to allow any-&amp;gt;any for now . &lt;BR /&gt;- both interfaces are using the same virtual router that has a static route to 0.0.0.0/0 for next hop 192.168.1.1(modem)&lt;BR /&gt;- Firewall is fully licensed . &lt;/P&gt;
&lt;P&gt;Issue : Inside workstations unable to browse internet . &lt;/P&gt;
&lt;P&gt;- Tried connecting both interfaces to default router - same&lt;/P&gt;
&lt;P&gt;- Traffic log shows that DNS request is coming from internal host and it is allowed but it ends with "aged out" error . seems like there is no response . capture shows that request hits the inside interface but not going further .&lt;/P&gt;
&lt;P&gt;- these are directly connected to interface so routing doesn't seem tobe the issue here . &lt;BR /&gt;&lt;BR /&gt;any help would be appreciated.&lt;/P&gt;
&lt;P&gt;Thanks &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2016 05:36:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73643#M41484</guid>
      <dc:creator>akhalighi</dc:creator>
      <dc:date>2016-02-26T05:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with my Palo Alto Lab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73649#M41486</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have a DNS proxy configured?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you do then check this article, it shows that if the firewall recieves a suspicious query then the DNS session from the the firewall to the DNS server will be set into a discard state.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Blocking-Suspicious-DNS-Queries-with-DNS-Proxy-Enabled/ta-p/66037" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Blocking-Suspicious-DNS-Queries-with-DNS-Proxy-Enabled/ta-p/66037&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps,&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2016 09:15:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73649#M41486</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-02-26T09:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with my Palo Alto Lab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73657#M41489</link>
      <description>&lt;P&gt;Do you have a NAT rule from the inside zone to NAT on the outside interface? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Without one you 10 address would probably not get NAT for the trip tothe DNS server on the internet. &amp;nbsp;Or internet access for the sites that resolve.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2016 11:34:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73657#M41489</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-02-26T11:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with my Palo Alto Lab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73678#M41495</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Also check your routing from the 'outside' of the PAN to the modem and internet and vice versa.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2016 14:41:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73678#M41495</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2016-02-26T14:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with my Palo Alto Lab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73686#M41500</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as pulukas pointed out - sounds like NAT issue in the virtual firewall, if allow-all is only policy you have. Simple -if you can reach public internet from firewall (download URL updateS) but can't reach anything from behind firewall, and only security policy is allow-all - than it's NAT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On a further note - I have a fairly complex setup of ESXi with plenty of vlans and stuff running through my PA-200 at home; I am not sure I understood your layout completely - can you elaborate a bit? I am lost at what firewall connects to:&lt;/P&gt;
&lt;P&gt;VM guests (10.0.1.x/24) -----&amp;gt; trust of VM_FW(10.0.1.10) -- Untrust of VM_FW(192.168.1.10) -------&amp;gt; Modem or firewall at 192.168.1.0?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have trunk on ESXi or you are assigning interfaces to firewall, are your hosts behind firewall virtual machines (vm guests) or they are real devices in your home network? In any case, you are doing nat twice for those hosts behind VM_FW - do you have physical firewall box as well, or you have some of those modems with integrated security? I passed public IP onto my PA-200 and trunked ESXi server onto one port of FW, and am working with sub-interfaces for VMs inside of ESXi... prolly not helping you at all but anyways...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2016 17:33:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73686#M41500</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2016-02-26T17:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with my Palo Alto Lab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73707#M41506</link>
      <description>&lt;P&gt;Do I need a NAT really ? like from 10.0.1.0/24 network to 192.168.1.0/24 network ? I tried to create a NAT but I got rejected . it was saying there is an overlap of addresses . I did a source NAT .&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2016 21:10:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73707#M41506</guid>
      <dc:creator>akhalighi</dc:creator>
      <dc:date>2016-02-26T21:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with my Palo Alto Lab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73708#M41507</link>
      <description>&lt;P&gt;no there is no DNS proxy . but DNS is on external network .&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2016 21:11:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73708#M41507</guid>
      <dc:creator>akhalighi</dc:creator>
      <dc:date>2016-02-26T21:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with my Palo Alto Lab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73709#M41508</link>
      <description>&lt;P&gt;external interfface has Internet access , I confimred it by pinging outside machines and resovle public DNSs.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2016 21:11:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73709#M41508</guid>
      <dc:creator>akhalighi</dc:creator>
      <dc:date>2016-02-26T21:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with my Palo Alto Lab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73713#M41509</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In order for hosts from 10.0.1.0/24 to access internet through their gateway 10.0.1.10 (trust zone IP) and further through 192.168.1.10 (untrust zone IP) you need to create NAT rule that will have tabs:&lt;/P&gt;
&lt;P&gt;general: whatever the name of your nAT rule is &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;original packet: translate from TRUST zone, destination zone UNTRUST, interface any, service any, source address - your scope (10.0.1.0/24), destination address any;&lt;/P&gt;
&lt;P&gt;translated packet: translation type: dynamic IP and port, address type: interface address, interface (ethernet - whatever is 192.168.1.10), ip address 192.168.1.10 (select from dropdown), leave "destination address translation" unchecked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Voila, hosts from 10.0.1.0/24 should be able to access internet through TRUST and exit on UNTRUST, reverse translation for sessions is implied.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try it and let us know if it helps.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Best regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2016 22:27:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73713#M41509</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2016-02-26T22:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with my Palo Alto Lab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73720#M41513</link>
      <description>&lt;P&gt;It's working ! I had a NAT in-place but it was wrong . I fixed it and it worked.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Feb 2016 19:18:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-my-palo-alto-lab/m-p/73720#M41513</guid>
      <dc:creator>akhalighi</dc:creator>
      <dc:date>2016-02-27T19:18:27Z</dc:date>
    </item>
  </channel>
</rss>

