<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: arp not found in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91655#M43659</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;. &amp;nbsp;We have a Cisco 3400 fiber switch that &amp;nbsp;is our next hop from the 3020. Within the static-route tab of the default-vr I did not change the next hop.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the fiber switch remains as our next hop I don't believe anything is out of place with regard to &amp;nbsp;next hop configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate the suggestions about clearing arp cache and checking arp stats!&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jun 2016 14:06:00 GMT</pubDate>
    <dc:creator>AndrewMoore</dc:creator>
    <dc:date>2016-06-23T14:06:00Z</dc:date>
    <item>
      <title>arp not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91641#M43654</link>
      <description>&lt;P&gt;Yesterday I attempted to move our Internet connection from a copper interface on ethernet1/1 to fiber optic on ethernet 1/13 on a Palo Alto 3020.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ensured both interfaces were members of the &amp;nbsp;same security zone and modified the Default route of default-vr to use ethernet 1/13 instead of 1/1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While I and the NOC technician confirmed the fiber port was&amp;nbsp;configured and up, I could not ping out to the Internet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During that time ran a show interfaces ethernet1/13 and found 13 instances of "arp not found" under the Logical interface counters read from CPU.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems that maybe I needed to clear the arp table? I say so because I believe the firewall was trying &amp;nbsp;to reach the MAC of our next hop ( our fiber switch ) through ethernet1/1 instead of ethernet1/13.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any advice would be greatly appreciated!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 13:35:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91641#M43654</guid>
      <dc:creator>AndrewMoore</dc:creator>
      <dc:date>2016-06-23T13:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: arp not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91647#M43655</link>
      <description>&lt;P&gt;was the next-hop IP identical for the fiber as what it was on copper ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you could try clearing the arp cache with &amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&amp;gt; clear arp ethernet1/1 &lt;/PRE&gt;
&lt;P&gt;to verify if the issue's related to arp, you can check the global counters for more detailed information:&lt;/P&gt;
&lt;PRE&gt;&amp;gt; show counter global filter delta yes | match arp&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 13:44:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91647#M43655</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-06-23T13:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: arp not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91652#M43656</link>
      <description>&lt;P&gt;Have you changed the zones? like ethernet 1/1 zone name and ethernet 1/13 zone?&lt;/P&gt;&lt;P&gt;If same zone you are using, no issue.&lt;/P&gt;&lt;P&gt;otherwie security rule should be created&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 13:49:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91652#M43656</guid>
      <dc:creator>Roby_Sreejith</dc:creator>
      <dc:date>2016-06-23T13:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: arp not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91654#M43658</link>
      <description>&lt;P&gt;Thanks for the reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39225"&gt;@Roby_Sreejith﻿&lt;/a&gt;. I confirmed before the switch over that the new fiber port ethernet1/13 had been assigned to the same seucurity zone, L3-Untrusted, as ethernet1/1 had been assigned to.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 14:01:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91654#M43658</guid>
      <dc:creator>AndrewMoore</dc:creator>
      <dc:date>2016-06-23T14:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: arp not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91655#M43659</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;. &amp;nbsp;We have a Cisco 3400 fiber switch that &amp;nbsp;is our next hop from the 3020. Within the static-route tab of the default-vr I did not change the next hop.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the fiber switch remains as our next hop I don't believe anything is out of place with regard to &amp;nbsp;next hop configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate the suggestions about clearing arp cache and checking arp stats!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 14:06:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91655#M43659</guid>
      <dc:creator>AndrewMoore</dc:creator>
      <dc:date>2016-06-23T14:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: arp not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91663#M43660</link>
      <description>&lt;P&gt;This was the state of our fiber port yesterday before I abandoned ship and moved back over to copper on eth1/1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;bob@pafw&amp;gt; show interface ethernet1/13
--------------------------------------------------------------------------------
Name: ethernet1/13, ID: 28
Link status:
Runtime link speed/duplex/state: 1000/full/up
Configured link speed/duplex/state: 1000/auto/auto
MAC address:
Port MAC address d4:f4:be:ab:cd:ef
Operation mode: layer3
Untagged sub-interface support: no
--------------------------------------------------------------------------------
Name: ethernet1/13, ID: 28
Operation mode: layer3
Virtual router default-vr
Interface MTU 1500
Interface IP address: 17.22.113.34/28
17.22.113.37/32
Interface management profile: N/A
Service configured: IKE
Zone: L3-Untrusted, virtual system: vsys1
Adjust TCP MSS: no
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Physical port counters read from MAC:
--------------------------------------------------------------------------------
rx-broadcast 0
rx-bytes 0
rx-multicast 0
rx-unicast 0
tx-broadcast 8
tx-bytes 512
tx-multicast 0
tx-unicast 0
--------------------------------------------------------------------------------
Hardware interface counters read from CPU:
--------------------------------------------------------------------------------
bytes received 1614
bytes transmitted 336
packets received 13
packets transmitted 8
receive incoming errors 0
receive discarded 0
receive errors 0
packets dropped 0
--------------------------------------------------------------------------------
Logical interface counters read from CPU:
--------------------------------------------------------------------------------
bytes received 1614
bytes transmitted 336
packets received 13
packets transmitted 8
receive errors 0
packets dropped 0
packets dropped by flow state check 0
forwarding errors 0
no route 0
arp not found 13
neighbor not found 0
neighbor info pending 0
mac not found 0
packets routed to different zone 0
land attacks 0
ping-of-death attacks 0
teardrop attacks 0
ip spoof attacks 0
mac spoof attacks 0
ICMP fragment 0
layer2 encapsulated packets 0
layer2 decapsulated packets 0
--------------------------------------------------------------------------------

bob@pafw&amp;gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 14:11:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91663#M43660</guid>
      <dc:creator>AndrewMoore</dc:creator>
      <dc:date>2016-06-23T14:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: arp not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91665#M43662</link>
      <description>&lt;P&gt;Hi Andrew.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;So both ports are in the same subnet? Any logs from the Cisco switch? ARP table&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 14:23:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91665#M43662</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-06-23T14:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: arp not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91672#M43663</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife﻿&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our ISP has assigned us a block of /28 IP addresses. In my description I was trying to emphasize that I copied/mirrored the same settings on eth1/13 from eth1/1. As a result both interfaces have the same addresses assigned, just not at the same time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In other words, &amp;nbsp;before pulling the copper line and installing the fiber I did the following to produce a valid configuration that would commit. After the following steps I pull copper and plug in optical.&lt;/P&gt;&lt;P&gt;1) Assign eth1/13 to same Security Zone as eth1/1 - that is L3-Untrusted.&lt;/P&gt;&lt;P&gt;2) Remove IP addresses&amp;nbsp;AAA.BBB.CCC.34/28 &amp;nbsp;&amp;amp; &amp;nbsp;AAA.BBB.CCC.37 and assign to eth1/13&lt;/P&gt;&lt;P&gt;3) Modify default-vr to include int1/13 and assign as interface to be used for the Default Route.&lt;/P&gt;&lt;P&gt;4) Move IKE Gatway interface assignment from eth1/1 to eth1/13&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not own, manage, or have console access to the Cisco switch but could inquire with the NOC for any specific statistics if you have any suggestions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Much appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 14:39:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91672#M43663</guid>
      <dc:creator>AndrewMoore</dc:creator>
      <dc:date>2016-06-23T14:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: arp not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91686#M43664</link>
      <description>&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try to run PCAP on the 1/13 interface to see for the ARP packets. Configure the filter for this interface and capture Receive and Transmit packets only. &amp;nbsp;KB article below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Run-a-Packet-Capture/ta-p/62390" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Run-a-Packet-Capture/ta-p/62390&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try GUI option, it is easier&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 14:55:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91686#M43664</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-06-23T14:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: arp not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91687#M43665</link>
      <description>&lt;P&gt;Have you verified the NAT policy?&lt;/P&gt;&lt;P&gt;Just make sure you have migrated everything belongs to e1/1 to e1/13 in NAT&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 14:55:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91687#M43665</guid>
      <dc:creator>Roby_Sreejith</dc:creator>
      <dc:date>2016-06-23T14:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: arp not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91708#M43666</link>
      <description>&lt;P&gt;Excellent suggestion&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39225"&gt;@Roby_Sreejith﻿&lt;/a&gt;!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my previous posts it's clear that I did not modify the Dynamic NAT policy to use eth1/13 instead of eth1/1.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I was trying to ping 8.8.8.8 from the Palo Alto CLI using the AAA.BBB.CCC.34/28 and AAA.BBB.CCC.37 IP addresses, which, I suspect, do not get translated using NAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope my assumptions are right but happy to be wrong and learn something new (-:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll be switching over again today around 12:15 CST so I'll be sure to try your and other suggestions, like clearing ARP tables, capturing packets and filtering ARP traffic, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you again!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 15:16:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91708#M43666</guid>
      <dc:creator>AndrewMoore</dc:creator>
      <dc:date>2016-06-23T15:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: arp not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91727#M43667</link>
      <description>&lt;P&gt;Agree with Roby.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please confirm Cisco port MAC address and that you actually can see it in your arp table:&lt;/P&gt;&lt;P&gt;&amp;gt; show arp ethernet1/13&lt;/P&gt;&lt;P&gt;Also, when pinging 8.8.8.8 try to source the ping from the fibre interface (&lt;SPAN&gt;ethernet1/13)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; ping source (fibre interface IP) host 8.8.8.8&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 15:34:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91727#M43667</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-06-23T15:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: arp not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91744#M43669</link>
      <description>&lt;P&gt;Thanks again&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife﻿&lt;/a&gt;. I can confirm that during the switch to fiber on ethernet1/13 I ran pings from the PA's eth1/13 interface like so:&lt;/P&gt;&lt;PRE&gt;&amp;gt; ping source AAA.BBB.CCC.34 host 8.8.8.8&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will confirm the MAC address tied to the current interface (Cisco) connected to eth1/1.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you to everyone for the big assist this morning.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 16:25:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91744#M43669</guid>
      <dc:creator>AndrewMoore</dc:creator>
      <dc:date>2016-06-23T16:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: arp not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91794#M43670</link>
      <description>&lt;P&gt;Thank you to everyone for your suggestions.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wanted to let you know the conversion from copper to fiber was a success over lunch today&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The solution was I had to issue gratuitous ARPs from a few IPs in my address block - this quickly solved everything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers to everyone!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 19:08:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91794#M43670</guid>
      <dc:creator>AndrewMoore</dc:creator>
      <dc:date>2016-06-23T19:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: arp not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91874#M43675</link>
      <description>&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Glad to hear it! You can mark this topic as "fixed" now&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All the best.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 22:25:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-not-found/m-p/91874#M43675</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-06-23T22:25:00Z</dc:date>
    </item>
  </channel>
</rss>

