<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ping between server is not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79183#M43193</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created a rule to allow ping between to and fro from servers below is the scenario&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;source zone: A, B, C&lt;/P&gt;
&lt;P&gt;Source IP: 1 , 2 , 3&lt;/P&gt;
&lt;P&gt;Destination zone: A, B, C&lt;/P&gt;
&lt;P&gt;Destination IP: 1, 2, 3&lt;/P&gt;
&lt;P&gt;Application: Ping&lt;/P&gt;
&lt;P&gt;Service: application-default&lt;/P&gt;
&lt;P&gt;action: Allow&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But the rule is not triggering, the traffic is denied due to dafault deny...&lt;/P&gt;
&lt;P&gt;can anyboady tell me the whats the &amp;nbsp;reason for this?? and how i can resolve it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jun 2016 12:27:14 GMT</pubDate>
    <dc:creator>KotreshaMC</dc:creator>
    <dc:date>2016-06-07T12:27:14Z</dc:date>
    <item>
      <title>ping between server is not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79183#M43193</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created a rule to allow ping between to and fro from servers below is the scenario&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;source zone: A, B, C&lt;/P&gt;
&lt;P&gt;Source IP: 1 , 2 , 3&lt;/P&gt;
&lt;P&gt;Destination zone: A, B, C&lt;/P&gt;
&lt;P&gt;Destination IP: 1, 2, 3&lt;/P&gt;
&lt;P&gt;Application: Ping&lt;/P&gt;
&lt;P&gt;Service: application-default&lt;/P&gt;
&lt;P&gt;action: Allow&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But the rule is not triggering, the traffic is denied due to dafault deny...&lt;/P&gt;
&lt;P&gt;can anyboady tell me the whats the &amp;nbsp;reason for this?? and how i can resolve it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 12:27:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79183#M43193</guid>
      <dc:creator>KotreshaMC</dc:creator>
      <dc:date>2016-06-07T12:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: ping between serve is not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79187#M43197</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reason is that the traffic is not hitting&amp;nbsp;your policy, instead hits your default deny rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2016 14:37:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79187#M43197</guid>
      <dc:creator>Transporter</dc:creator>
      <dc:date>2016-06-06T14:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: ping between serve is not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79194#M43201</link>
      <description>&lt;P&gt;As the policy is Top-down, it will match on the rules in order.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have created the rule to allow Ping, but the question is where is this rule in the policy?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2016 15:54:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79194#M43201</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2016-06-06T15:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: ping between serve is not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79240#M43211</link>
      <description>&lt;P&gt;the rule is on the top of default deny but still it's not working.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 06:55:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79240#M43211</guid>
      <dc:creator>KotreshaMC</dc:creator>
      <dc:date>2016-06-07T06:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: ping between serve is not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79242#M43212</link>
      <description>&lt;P&gt;Can you enable logging of your default deny rule (this is not enabled by default). &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you confirm the zones / IP's when you check the actual drop log ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 07:40:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79242#M43212</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2016-06-07T07:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: ping between serve is not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79243#M43213</link>
      <description>&lt;P&gt;Yes we have enabled it and i can see it the Zones and ips are correct but still it's not working&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 07:43:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79243#M43213</guid>
      <dc:creator>KotreshaMC</dc:creator>
      <dc:date>2016-06-07T07:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: ping between serve is not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79244#M43214</link>
      <description>&lt;P&gt;are you seeing ICMP ping being dropped or UDP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the AppID application 'ping' is for ICMP echo requests only. if your host is sending out UDP pings, they will not match&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 07:50:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79244#M43214</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-06-07T07:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: ping between serve is not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79245#M43215</link>
      <description>&lt;P&gt;I can see ICMP IP protocol in the logs.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 08:10:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79245#M43215</guid>
      <dc:creator>KotreshaMC</dc:creator>
      <dc:date>2016-06-07T08:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: ping between serve is not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79249#M43218</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just for test add in the policy application field "ping" and "ICMP" apps and try.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 08:49:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79249#M43218</guid>
      <dc:creator>Transporter</dc:creator>
      <dc:date>2016-06-07T08:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: ping between serve is not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79262#M43219</link>
      <description>&lt;P&gt;Is the server is located behind the firewall and you are trying to ping from outside ? ( nat and security policy needs to be checked )&lt;/P&gt;
&lt;P&gt;If that is not the case then it may also happen the new sessions are getting matched with the old discard sessions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Most likely as me peers mentioned above either the deny policy is above the allow policy or there the zones and the ips needs to be cross checked once again&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tarang&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 10:48:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79262#M43219</guid>
      <dc:creator>tsrivastav</dc:creator>
      <dc:date>2016-06-07T10:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: ping between serve is not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79266#M43221</link>
      <description>&lt;P&gt;Yes i can confirm that the rule is above the default deny and we are allowing ping to and fro from cloud servers to internal servers. There no NAT applied on this.&lt;/P&gt;
&lt;P&gt;however i have added ICMP to the rule and waiting for the test&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 12:26:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/79266#M43221</guid>
      <dc:creator>KotreshaMC</dc:creator>
      <dc:date>2016-06-07T12:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: ping between serve is not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/84311#M43340</link>
      <description>&lt;P&gt;After adding icmp to application it's started working fine.&lt;/P&gt;
&lt;P&gt;Thanks for your all support guys.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2016 04:38:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/84311#M43340</guid>
      <dc:creator>KotreshaMC</dc:creator>
      <dc:date>2016-06-13T04:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: ping between serve is not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/84417#M43342</link>
      <description>&lt;P&gt;Glad it is working!&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2016 08:26:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-between-server-is-not-working/m-p/84417#M43342</guid>
      <dc:creator>Transporter</dc:creator>
      <dc:date>2016-06-13T08:26:06Z</dc:date>
    </item>
  </channel>
</rss>

