<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with inter-subnet routing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-inter-subnet-routing/m-p/93250#M43776</link>
    <description>&lt;P&gt;Yea can you provide a bit more detail? What is (8) and (9)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please provide:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source and destination subnets you want to talk, and the zones and interfaces associated with each IP subnet.&lt;/P&gt;&lt;P&gt;Gateway address of clients in each source and destination subnet&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jun 2016 21:41:40 GMT</pubDate>
    <dc:creator>ShannonRowe</dc:creator>
    <dc:date>2016-06-28T21:41:40Z</dc:date>
    <item>
      <title>Help with inter-subnet routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-inter-subnet-routing/m-p/88921#M43514</link>
      <description>&lt;P&gt;Looking for input on a subnet routing, issue I am having.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I have let’s say for argument I have two zones, Trust and Untrust.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interfaces&lt;/P&gt;
&lt;P&gt;Int 1/1 - Untrust Internet 192.168.0.1&lt;/P&gt;
&lt;P&gt;Int 1/2 - Trust 10.8.1.20&lt;/P&gt;
&lt;P&gt;Int 1/3 - Trust 10.26.96.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a virtual router (default)&lt;/P&gt;
&lt;P&gt;Default&lt;/P&gt;
&lt;P&gt;Destination 0.0.0.0/0&lt;/P&gt;
&lt;P&gt;Int 1/1&lt;/P&gt;
&lt;P&gt;Net Hop Value 69.168.XX.XX&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is where I am getting confused!&lt;/P&gt;
&lt;P&gt;I want the Both (8)(9) be able to talk to each other&lt;/P&gt;
&lt;P&gt;Access Name&lt;/P&gt;
&lt;P&gt;Destination&amp;nbsp; 10.26.96.0/30&lt;/P&gt;
&lt;P&gt;Int 1/3&lt;/P&gt;
&lt;P&gt;Next Hop Value 10.26.96.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No Working, so? Need a little help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2016 12:36:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-inter-subnet-routing/m-p/88921#M43514</guid>
      <dc:creator>ckluck</dc:creator>
      <dc:date>2016-06-20T12:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: Help with inter-subnet routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-inter-subnet-routing/m-p/88931#M43517</link>
      <description>&lt;P&gt;Could you please tell me what are addresses (and subnets masks) of two hosts trying to communicate, where are they connected (zones/ports) and what are their default gw settings?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By default&amp;nbsp;hosts are able to talk within the zone (intra-zone traffic) interfaces and are denied for traffic between the zones (inter-zone traffic). And one&amp;nbsp;thing that seems to be not entirely correct - default route (0.0.0.0/0) should point to address within e1/3 range (basically gateway for that interface), because firewall does not know how to reach that&amp;nbsp;69.168.242.65 at the moment.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2016 20:37:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-inter-subnet-routing/m-p/88931#M43517</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2016-06-17T20:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: Help with inter-subnet routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-inter-subnet-routing/m-p/89592#M43543</link>
      <description>&lt;P style="margin: 0in; margin-bottom: .0001pt; line-height: 15.0pt;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica',sans-serif; color: #333333;"&gt;Zone is trusted&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; margin-bottom: .0001pt; line-height: 15.0pt; orphans: auto; text-align: start; widows: 1; -webkit-text-stroke-width: 0px; word-spacing: 0px;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica',sans-serif; color: #333333;"&gt;Int 2 - 10.8.1.20 Interface IP (255.255.255.0)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; margin-bottom: .0001pt; line-height: 15.0pt; orphans: auto; text-align: start; widows: 1; -webkit-text-stroke-width: 0px; word-spacing: 0px;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica',sans-serif; color: #333333;"&gt;Int 3 - 10.26.96.1 Interface IP (255.255.255.0)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; margin-bottom: .0001pt; line-height: 15.0pt; orphans: auto; text-align: start; widows: 1; -webkit-text-stroke-width: 0px; word-spacing: 0px;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica',sans-serif; color: #333333;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; margin-bottom: .0001pt; line-height: 15.0pt; orphans: auto; text-align: start; widows: 1; -webkit-text-stroke-width: 0px; word-spacing: 0px;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica',sans-serif; color: #333333;"&gt;I am using the int address(e)s as each of their own Default Gateways, I am then using a generic route rule 0.0.0.0/0 to route traffic to Int1/1 interface for internet.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2016 12:36:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-inter-subnet-routing/m-p/89592#M43543</guid>
      <dc:creator>ckluck</dc:creator>
      <dc:date>2016-06-20T12:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: Help with inter-subnet routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-inter-subnet-routing/m-p/89599#M43545</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is directly connected networks to Palo, &amp;nbsp;so they should be talking to each other without any additional static routes or routing. &amp;nbsp;Please confirm you can ping your subinterfaces and make sure that the policy in place and correct&amp;nbsp;traffic permitted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2016 13:03:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-inter-subnet-routing/m-p/89599#M43545</guid>
      <dc:creator>Transporter</dc:creator>
      <dc:date>2016-06-20T13:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Help with inter-subnet routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-inter-subnet-routing/m-p/89607#M43546</link>
      <description>&lt;P&gt;Yes, I tend to agree with Transporter, although the description is still kind of a blurry.&lt;/P&gt;
&lt;P&gt;Basically check everything step by step:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Check network settings on each - IP, mask, gw address (Palo Alto subinterface address and host/gw should be from the same subnet);&lt;/LI&gt;
&lt;LI&gt;Test if you can reach gateway from the end host (ping subinterface address, but make sure your subinterface mgmt profile allows pinging);&lt;/LI&gt;
&lt;LI&gt;Make sure your security rules have logging enabled;&lt;/LI&gt;
&lt;LI&gt;Inititate traffic from one end host to another and check Palo Alto logs - you should see what happended with that traffic;&lt;/LI&gt;
&lt;LI&gt;If nothing is visible from there - try capturing packets (&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Run-a-Packet-Capture/ta-p/62390" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Run-a-Packet-Capture/ta-p/62390&lt;/A&gt;) and see if traffic arrives at the Palo Alto at all.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 20 Jun 2016 13:15:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-inter-subnet-routing/m-p/89607#M43546</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2016-06-20T13:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: Help with inter-subnet routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-inter-subnet-routing/m-p/93250#M43776</link>
      <description>&lt;P&gt;Yea can you provide a bit more detail? What is (8) and (9)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please provide:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source and destination subnets you want to talk, and the zones and interfaces associated with each IP subnet.&lt;/P&gt;&lt;P&gt;Gateway address of clients in each source and destination subnet&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2016 21:41:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-inter-subnet-routing/m-p/93250#M43776</guid>
      <dc:creator>ShannonRowe</dc:creator>
      <dc:date>2016-06-28T21:41:40Z</dc:date>
    </item>
  </channel>
</rss>

