<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Static Routes not Working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/static-routes-not-working/m-p/103461#M44624</link>
    <description>&lt;P&gt;I originaly had the next hop set as 192.168.3.1 but that didn't work. &amp;nbsp;I will go and change it back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can ping with a source of 192.168.3.251 to host 192.168.3.1 and it works. But I can not ping 192.168.3.1 from 192.168.111.10. &amp;nbsp;Is this just not a function of the palo alto to be able to ping from a source to a non connected host?&lt;/P&gt;</description>
    <pubDate>Tue, 16 Aug 2016 14:45:46 GMT</pubDate>
    <dc:creator>trees</dc:creator>
    <dc:date>2016-08-16T14:45:46Z</dc:date>
    <item>
      <title>Static Routes not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-routes-not-working/m-p/103222#M44611</link>
      <description>&lt;P&gt;I have a network with in my network that I am trying to control access with user-id in the palo alto. &amp;nbsp;Before I can do this I need to get routing working. &amp;nbsp;The routing works just fine up to the palo alto in my test environment. &amp;nbsp;Each interface can talk to the next hop on the otherside but traffic isn't routing across the interfaces. &amp;nbsp;I can not ping source 192.168.111.10 to 192.168.2.1 &amp;nbsp;but I can ping source 192.168.111.10 to 192.168.111.1. This is the same for all interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a copy of my routing table&lt;/P&gt;&lt;P&gt;VIRTUAL ROUTER: TEST&amp;nbsp;(id 15)&lt;BR /&gt;==========&lt;BR /&gt;destination nexthop&lt;BR /&gt;metric flags age interface next-AS&lt;BR /&gt;192.168.0.0/16 192.168.2.1&lt;BR /&gt;15 A S ethernet1/3.9514&lt;BR /&gt;192.168.3.0/24 192.168.3.251&lt;BR /&gt;0 A C ethernet1/3.9514&lt;BR /&gt;192.168.3.251/32 0.0.0.0&lt;BR /&gt;0 A H&lt;BR /&gt;192.168.111.0/24 192.168.111.1&lt;BR /&gt;10 S ethernet1/4.9509&lt;BR /&gt;192.168.111.0/24 192.168.111.10&lt;BR /&gt;0 A C ethernet1/4.9509&lt;BR /&gt;192.168.111.10/32 0.0.0.0&lt;BR /&gt;0 A H&lt;BR /&gt;192.168.112.0/24 192.168.112.1&lt;BR /&gt;10 S ethernet1/4.9510&lt;BR /&gt;192.168.112.0/24 192.168.112.10&lt;BR /&gt;0 A C ethernet1/4.9510&lt;BR /&gt;192.168.112.10/32 0.0.0.0&lt;BR /&gt;0 A H&lt;BR /&gt;total routes shown: 9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is how the layer 3 interface is setup&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Name: ethernet1/3.9514, ID: 265&lt;BR /&gt;Operation mode: layer3&lt;BR /&gt;Virtual router&amp;nbsp;TEST&lt;BR /&gt;Interface MTU 1500&lt;BR /&gt;Interface IP address: 192.168.3.251/24&lt;BR /&gt;Interface management profile: Default&lt;BR /&gt;ping: yes telnet: no ssh: no http: no https: no&lt;BR /&gt;snmp: no response-pages: no userid-service: yes&lt;BR /&gt;Service configured:&lt;BR /&gt;Interface belong to same subnet as management interface: Yes&lt;BR /&gt;Zone: TEST_Untrust, virtual system: vsys1&lt;BR /&gt;Adjust TCP MSS: no&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Name: ethernet1/4.9509, ID: 266&lt;BR /&gt;Operation mode: layer3&lt;BR /&gt;Virtual router TEST&lt;BR /&gt;Interface MTU 1500&lt;BR /&gt;Interface IP address: 192.168.111.10/24&lt;BR /&gt;Interface management profile: Default&lt;BR /&gt;ping: yes telnet: no ssh: no http: no https: no&lt;BR /&gt;snmp: no response-pages: no userid-service: yes&lt;BR /&gt;Service configured:&lt;BR /&gt;Zone: TEST_Trust, virtual system: vsys1&lt;BR /&gt;Adjust TCP MSS: no&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Name: ethernet1/4.9510, ID: 267&lt;BR /&gt;Operation mode: layer3&lt;BR /&gt;Virtual router TEST&lt;BR /&gt;Interface MTU 1500&lt;BR /&gt;Interface IP address: 192.168.112.10/24&lt;BR /&gt;Interface management profile: Default&lt;BR /&gt;ping: yes telnet: no ssh: no http: no https: no&lt;BR /&gt;snmp: no response-pages: no userid-service: yes&lt;BR /&gt;Service configured:&lt;BR /&gt;Zone: TEST_Trust, virtual system: vsys1&lt;BR /&gt;Adjust TCP MSS: no&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;Here are the security policy associated with virtual routes and interfaces&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Inbound TEST untrust to trust" {&lt;BR /&gt;from TEST_Untrust;&lt;BR /&gt;source any;&lt;BR /&gt;source-region none;&lt;BR /&gt;to TEST_Trust;&lt;BR /&gt;destination any;&lt;BR /&gt;destination-region none;&lt;BR /&gt;user any;&lt;BR /&gt;category any;&lt;BR /&gt;application/service any/any/any/any;&lt;BR /&gt;action allow;&lt;BR /&gt;icmp-unreachable: no&lt;BR /&gt;terminal yes;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;"Outbound TEST trust to untrust" {&lt;BR /&gt;from TEST_Trust;&lt;BR /&gt;source any;&lt;BR /&gt;source-region none;&lt;BR /&gt;to TEST_Untrust;&lt;BR /&gt;destination any;&lt;BR /&gt;destination-region none;&lt;BR /&gt;user any;&lt;BR /&gt;category any;&lt;BR /&gt;application/service any/any/any/any;&lt;BR /&gt;action allow;&lt;BR /&gt;icmp-unreachable: no&lt;BR /&gt;terminal yes;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help or advice would be greatly apreciated. &amp;nbsp;I have concidered using a virtual wire but now I really just want to figure this out after spending a day on it with no success.&lt;/P&gt;&lt;P&gt;-Michael&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 02:15:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-routes-not-working/m-p/103222#M44611</guid>
      <dc:creator>trees</dc:creator>
      <dc:date>2016-08-16T02:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Static Routes not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-routes-not-working/m-p/103229#M44612</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I believe following static route is mis-configuration:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;192.168.0.0/16 192.168.2.1 15 A S ethernet1/3.9514&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ethernet1/3.9514 has&amp;nbsp;192.168.3.251/24.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Then nexthop should be in range of 192.168.3.0/24, you can't reach to 192.168.2.1.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 02:38:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-routes-not-working/m-p/103229#M44612</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2016-08-16T02:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: Static Routes not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-routes-not-working/m-p/103436#M44620</link>
      <description>&lt;P&gt;Yeah, routes can only point to connected networks.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 12:51:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-routes-not-working/m-p/103436#M44620</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-08-16T12:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: Static Routes not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-routes-not-working/m-p/103461#M44624</link>
      <description>&lt;P&gt;I originaly had the next hop set as 192.168.3.1 but that didn't work. &amp;nbsp;I will go and change it back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can ping with a source of 192.168.3.251 to host 192.168.3.1 and it works. But I can not ping 192.168.3.1 from 192.168.111.10. &amp;nbsp;Is this just not a function of the palo alto to be able to ping from a source to a non connected host?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 14:45:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-routes-not-working/m-p/103461#M44624</guid>
      <dc:creator>trees</dc:creator>
      <dc:date>2016-08-16T14:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Static Routes not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-routes-not-working/m-p/103805#M44650</link>
      <description>&lt;P&gt;Well wherever you point your route to it should be a router (in connected network) and it should have a route for&amp;nbsp;&lt;SPAN&gt;192.168.111.0/24 as well pointing back at your device (through connected network).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 06:22:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-routes-not-working/m-p/103805#M44650</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-08-17T06:22:28Z</dc:date>
    </item>
  </channel>
</rss>

