<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Interface mgmt services (ping,ssh,https,etc..) have no response in WAN2 if the default route is WAN1 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/interface-mgmt-services-ping-ssh-https-etc-have-no-response-in/m-p/5673#M4152</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;panos, thanks a lot, it's helpful idea.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Jan 2014 03:04:53 GMT</pubDate>
    <dc:creator>paloalto.netfos</dc:creator>
    <dc:date>2014-01-14T03:04:53Z</dc:date>
    <item>
      <title>Interface mgmt services (ping,ssh,https,etc..) have no response in WAN2 if the default route is WAN1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-mgmt-services-ping-ssh-https-etc-have-no-response-in/m-p/5670#M4149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;:Hi, all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Suppose I have a following simple network architecture :&lt;/P&gt;&lt;P&gt;- WAN1 : 1.1.1.1/24 (GW: 1.1.1.254)&lt;/P&gt;&lt;P&gt;- WAN2 : 2.2.2.2/24 (GW: 2.2.2.254)&lt;/P&gt;&lt;P&gt;- Default Route : 1.1.1.254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In WAN1, all the interface mgmt services are workable, I can connect it from a internet address, I also can ping any internet address by orginating source address from 1.1.1.1.&lt;/P&gt;&lt;P&gt;But all above situations are unworkable in WAN2, even I configure a PBF rule as :&lt;/P&gt;&lt;P&gt;- source zone : WAN2&lt;/P&gt;&lt;P&gt;- source address : 2.2.2.2&lt;/P&gt;&lt;P&gt;- destination address and service : any&lt;/P&gt;&lt;P&gt;- action : forwarding to 2.2.2.254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why? and how can I resolve it? is there any workaround?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot,&lt;/P&gt;&lt;P&gt;Sample&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 12:02:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-mgmt-services-ping-ssh-https-etc-have-no-response-in/m-p/5670#M4149</guid>
      <dc:creator>paloalto.netfos</dc:creator>
      <dc:date>2014-01-13T12:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Interface mgmt services (ping,ssh,https,etc..) have no response in WAN2 if the default route is WAN1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-mgmt-services-ping-ssh-https-etc-have-no-response-in/m-p/5671#M4150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if you cerate another VR for WAN2 it will work (management services)give default gw 2.2.2.2254 for that VR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried that before just fixed it with another VR.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 13:22:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-mgmt-services-ping-ssh-https-etc-have-no-response-in/m-p/5671#M4150</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-01-13T13:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: Interface mgmt services (ping,ssh,https,etc..) have no response in WAN2 if the default route is WAN1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-mgmt-services-ping-ssh-https-etc-have-no-response-in/m-p/5672#M4151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can follow this DOC for configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1366"&gt;PAN-OS 3.1 ISP Redundancy Using Policy Based Forwarding &lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 22:17:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-mgmt-services-ping-ssh-https-etc-have-no-response-in/m-p/5672#M4151</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2014-01-13T22:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: Interface mgmt services (ping,ssh,https,etc..) have no response in WAN2 if the default route is WAN1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-mgmt-services-ping-ssh-https-etc-have-no-response-in/m-p/5673#M4152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;panos, thanks a lot, it's helpful idea.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 03:04:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-mgmt-services-ping-ssh-https-etc-have-no-response-in/m-p/5673#M4152</guid>
      <dc:creator>paloalto.netfos</dc:creator>
      <dc:date>2014-01-14T03:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: Interface mgmt services (ping,ssh,https,etc..) have no response in WAN2 if the default route is WAN1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-mgmt-services-ping-ssh-https-etc-have-no-response-in/m-p/5674#M4153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;craymond, thanks a lot, ^_^&lt;/P&gt;&lt;P&gt;but my question isn't it, but it's a helpful document&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 03:34:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-mgmt-services-ping-ssh-https-etc-have-no-response-in/m-p/5674#M4153</guid>
      <dc:creator>paloalto.netfos</dc:creator>
      <dc:date>2014-01-14T03:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Interface mgmt services (ping,ssh,https,etc..) have no response in WAN2 if the default route is WAN1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-mgmt-services-ping-ssh-https-etc-have-no-response-in/m-p/5675#M4154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The reason this is happening is a routing issue.&amp;nbsp; When coming in from the internet the reply packets will use the default route out of the firewall.&amp;nbsp; In your case this is set to the primary interface.&amp;nbsp; Even if you were to get two default routes active you would not necessarily be able to control which wan interface got the reply packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The separation into virtual routers overcomes this problem by giving each wan interface their own routing table and default route.&amp;nbsp; So the reply will return out to the internet on the ingress interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For this solution you do need to make sure routing is setup between your two vr as you want to use the services.&amp;nbsp; For this you may want to use policy based routing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 12:51:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-mgmt-services-ping-ssh-https-etc-have-no-response-in/m-p/5675#M4154</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-01-14T12:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Interface mgmt services (ping,ssh,https,etc..) have no response in WAN2 if the default route is WAN1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-mgmt-services-ping-ssh-https-etc-have-no-response-in/m-p/5676#M4155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same problem. I think that this is a big problem and need to be resolved. Because, create two VR was make my administration and the troubleshooting more complex.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2014 17:05:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-mgmt-services-ping-ssh-https-etc-have-no-response-in/m-p/5676#M4155</guid>
      <dc:creator>lucaspassos</dc:creator>
      <dc:date>2014-03-10T17:05:31Z</dc:date>
    </item>
  </channel>
</rss>

