<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: issues after deployed VM-PA under VMware in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/108654#M44957</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you activated the setting:&amp;nbsp;&lt;/P&gt;&lt;TABLE cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="TB_TableBody"&gt;Use Hypervisor Assigned MAC Addresses (VM-Series firewalls only)&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="TB_TableBody"&gt;Select this option to have the VM-Series firewall use the MAC address that the hypervisor assigned, instead of generating a MAC address using the PAN-OS&lt;SPAN&gt;®&lt;/SPAN&gt;custom schema.&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Is under Device - Setup - Management&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had this problem also, but after i activated this setting everything works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
    <pubDate>Tue, 30 Aug 2016 07:27:36 GMT</pubDate>
    <dc:creator>FJU-ITCS</dc:creator>
    <dc:date>2016-08-30T07:27:36Z</dc:date>
    <item>
      <title>issues after deployed VM-PA under VMware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/108567#M44951</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm creating a lab with vmware vsphere 5.5.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I deployed two firewall with the following network configuration in vmware.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is from the firewall I can to ping to my untrust and trust interfaces. But when I doing ping to the linux pc the ping failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the linux pc try to reseach to internet and the connection is failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the vmware I set up the promiscuos mode is enable.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vmwareconfig.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5380iDAE733A957E9899F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vmwareconfig.JPG" alt="vmwareconfig.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the PA config interfaces and policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="PA interfaces.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5381iDEF8CAD3CEDC7231/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA interfaces.JPG" alt="PA interfaces.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="PApolicies.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5383iC749F7CE462FE0B3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PApolicies.JPG" alt="PApolicies.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please your help to continue with my lab.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;&lt;P&gt;Andres&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2016 03:00:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/108567#M44951</guid>
      <dc:creator>Apadilla</dc:creator>
      <dc:date>2016-08-30T03:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: issues after deployed VM-PA under VMware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/108601#M44953</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Usually, you will be able to ping your own (itself) interfaces.&amp;nbsp;&lt;/P&gt;&lt;P&gt;First thing configures a mgmt profile and attach&amp;nbsp;to the interface so it will be easy to troubleshoot. See below hot to do it:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Allow-Ping-and-ICMP-on-Layer-3-Interface-of-Your-Palo/ta-p/58932" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Allow-Ping-and-ICMP-on-Layer-3-Interface-of-Your-Palo/ta-p/58932&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Check the interface &amp;nbsp;mapping:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;network adapter = BRIDGED. This is actually your management interface and you don't see it in the network&amp;nbsp;TAB of the device&lt;/P&gt;&lt;P&gt;network adapter 2 = VMnet(X)&amp;nbsp;&lt;SPAN&gt;This is actually your first interface = ethernet1/1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;network adapter 3 =&amp;nbsp;VMnet(X)&amp;nbsp;This is actually your first interface = ethernet1/2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;network adapter 4 =&amp;nbsp;VMnet(X)&amp;nbsp;This is actually your first interface = ethernet1/3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After this you know that Palo&amp;nbsp;is going to reply for the ping. So the first step is to make sure Linux&amp;nbsp;host can ping PA interface.&lt;/P&gt;&lt;P&gt;Check the arp table on the Linux machine to confirm you are on the&amp;nbsp;same Layer 2 broadcast domain with Palo.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Check if the Palo can resolve DNS requests.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2016 06:53:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/108601#M44953</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-08-30T06:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: issues after deployed VM-PA under VMware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/108650#M44955</link>
      <description>&lt;P&gt;You have to allow ping in a interface management profile. And assign it to your interfaces&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Starting from pan-os 7.0&amp;nbsp; promiscuous mode is no longer required&lt;/P&gt;&lt;P&gt;see here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/newfeaturesguide/virtualization-features/support-for-hypervisor-assigned-mac-addresses" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/70/pan-os/newfeaturesguide/virtualization-features/support-for-hypervisor-assigned-mac-addresses&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2016 07:58:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/108650#M44955</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2016-08-30T07:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: issues after deployed VM-PA under VMware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/108654#M44957</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you activated the setting:&amp;nbsp;&lt;/P&gt;&lt;TABLE cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="TB_TableBody"&gt;Use Hypervisor Assigned MAC Addresses (VM-Series firewalls only)&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="TB_TableBody"&gt;Select this option to have the VM-Series firewall use the MAC address that the hypervisor assigned, instead of generating a MAC address using the PAN-OS&lt;SPAN&gt;®&lt;/SPAN&gt;custom schema.&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Is under Device - Setup - Management&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had this problem also, but after i activated this setting everything works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2016 07:27:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/108654#M44957</guid>
      <dc:creator>FJU-ITCS</dc:creator>
      <dc:date>2016-08-30T07:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: issues after deployed VM-PA under VMware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/108953#M44967</link>
      <description>&lt;P&gt;thanks, today I will proceeding with this changes.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2016 19:27:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/108953#M44967</guid>
      <dc:creator>Apadilla</dc:creator>
      <dc:date>2016-08-30T19:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: issues after deployed VM-PA under VMware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/110643#M45050</link>
      <description>&lt;P&gt;Me again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can to ping the untrust zone or ethernet 1/2(192.168.120.21)&amp;nbsp; from the linux machine. but when I try to ping the trust zone (172.16.10.2) the linux console show the following message " Time to live exceded "&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Change ip&amp;nbsp; the linux pc from 192.168.120.9 to 172.16.10.20 and try to ping the untrust zone&amp;nbsp; or trust zone and the result is failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And try to access to internet from the linux pc, and fail.&lt;/P&gt;&lt;P&gt;So I do not know if I'm missing some configuration in the firewall or in my vsphere.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the config running&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@fw01&amp;gt; show config running&lt;/P&gt;&lt;P&gt;config {&lt;BR /&gt;mgt-config {&lt;BR /&gt;users {&lt;BR /&gt;admin {&lt;BR /&gt;phash fnRL/G5lXVMug;&lt;BR /&gt;permissions {&lt;BR /&gt;role-based {&lt;BR /&gt;superuser yes;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;shared {&lt;BR /&gt;application;&lt;BR /&gt;application-group;&lt;BR /&gt;service;&lt;BR /&gt;service-group;&lt;BR /&gt;botnet {&lt;BR /&gt;configuration {&lt;BR /&gt;http {&lt;BR /&gt;dynamic-dns {&lt;BR /&gt;enabled yes;&lt;BR /&gt;threshold 5;&lt;BR /&gt;}&lt;BR /&gt;malware-sites {&lt;BR /&gt;enabled yes;&lt;BR /&gt;threshold 5;&lt;BR /&gt;}&lt;BR /&gt;recent-domains {&lt;BR /&gt;enabled yes;&lt;BR /&gt;threshold 5;&lt;BR /&gt;}&lt;BR /&gt;ip-domains {&lt;BR /&gt;enabled yes;&lt;BR /&gt;threshold 10;&lt;BR /&gt;}&lt;BR /&gt;executables-from-unknown-sites {&lt;BR /&gt;enabled yes;&lt;BR /&gt;threshold 5;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;other-applications {&lt;BR /&gt;irc yes;&lt;BR /&gt;}&lt;BR /&gt;unknown-applications {&lt;BR /&gt;unknown-tcp {&lt;BR /&gt;destinations-per-hour 10;&lt;BR /&gt;sessions-per-hour 10;&lt;BR /&gt;session-length {&lt;BR /&gt;maximum-bytes 100;&lt;BR /&gt;minimum-bytes 50;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;unknown-udp {&lt;BR /&gt;destinations-per-hour 10;&lt;BR /&gt;sessions-per-hour 10;&lt;BR /&gt;session-length {&lt;BR /&gt;maximum-bytes 100;&lt;BR /&gt;minimum-bytes 50;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;report {&lt;BR /&gt;topn 100;&lt;BR /&gt;scheduled yes;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;devices {&lt;BR /&gt;localhost.localdomain {&lt;BR /&gt;network {&lt;BR /&gt;interface {&lt;BR /&gt;ethernet {&lt;BR /&gt;ethernet1/1 {&lt;BR /&gt;layer3 {&lt;BR /&gt;ipv6 {&lt;BR /&gt;neighbor-discovery {&lt;BR /&gt;router-advertisement {&lt;BR /&gt;enable no;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;ndp-proxy {&lt;BR /&gt;enabled no;&lt;BR /&gt;}&lt;BR /&gt;ip {&lt;BR /&gt;172.16.10.2;&lt;BR /&gt;}&lt;BR /&gt;lldp {&lt;BR /&gt;enable no;&lt;BR /&gt;}&lt;BR /&gt;interface-management-profile "mgm profile";&lt;BR /&gt;}&lt;BR /&gt;comment trust;&lt;BR /&gt;}&lt;BR /&gt;ethernet1/2 {&lt;BR /&gt;layer3 {&lt;BR /&gt;ipv6 {&lt;BR /&gt;neighbor-discovery {&lt;BR /&gt;router-advertisement {&lt;BR /&gt;enable no;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;ndp-proxy {&lt;BR /&gt;enabled no;&lt;BR /&gt;}&lt;BR /&gt;ip {&lt;BR /&gt;192.168.120.21;&lt;BR /&gt;}&lt;BR /&gt;lldp {&lt;BR /&gt;enable no;&lt;BR /&gt;}&lt;BR /&gt;interface-management-profile "mgm profile";&lt;BR /&gt;}&lt;BR /&gt;comment untrust;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;profiles {&lt;BR /&gt;monitor-profile {&lt;BR /&gt;default {&lt;BR /&gt;interval 3;&lt;BR /&gt;threshold 5;&lt;BR /&gt;action wait-recover;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;interface-management-profile {&lt;BR /&gt;"mgm profile" {&lt;BR /&gt;https yes;&lt;BR /&gt;ssh yes;&lt;BR /&gt;ping yes;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;ike {&lt;BR /&gt;crypto-profiles {&lt;BR /&gt;ike-crypto-profiles {&lt;BR /&gt;default {&lt;BR /&gt;encryption [ aes-128-cbc 3des];&lt;BR /&gt;hash sha1;&lt;BR /&gt;dh-group group2;&lt;BR /&gt;lifetime {&lt;BR /&gt;hours 8;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;Suite-B-GCM-128 {&lt;BR /&gt;encryption aes-128-cbc;&lt;BR /&gt;hash sha256;&lt;BR /&gt;dh-group group19;&lt;BR /&gt;lifetime {&lt;BR /&gt;hours 8;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;Suite-B-GCM-256 {&lt;BR /&gt;encryption aes-256-cbc;&lt;BR /&gt;hash sha384;&lt;BR /&gt;dh-group group20;&lt;BR /&gt;lifetime {&lt;BR /&gt;hours 8;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;ipsec-crypto-profiles {&lt;BR /&gt;default {&lt;BR /&gt;esp {&lt;BR /&gt;encryption [ aes-128-cbc 3des];&lt;BR /&gt;authentication sha1;&lt;BR /&gt;}&lt;BR /&gt;dh-group group2;&lt;BR /&gt;lifetime {&lt;BR /&gt;hours 1;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;Suite-B-GCM-128 {&lt;BR /&gt;esp {&lt;BR /&gt;encryption aes-128-gcm;&lt;BR /&gt;authentication none;&lt;BR /&gt;}&lt;BR /&gt;dh-group group19;&lt;BR /&gt;lifetime {&lt;BR /&gt;hours 1;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;Suite-B-GCM-256 {&lt;BR /&gt;esp {&lt;BR /&gt;encryption aes-256-gcm;&lt;BR /&gt;authentication none;&lt;BR /&gt;}&lt;BR /&gt;dh-group group20;&lt;BR /&gt;lifetime {&lt;BR /&gt;hours 1;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;global-protect-app-crypto-profiles {&lt;BR /&gt;default {&lt;BR /&gt;encryption aes-128-cbc;&lt;BR /&gt;authentication sha1;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;qos {&lt;BR /&gt;profile {&lt;BR /&gt;default {&lt;BR /&gt;class {&lt;BR /&gt;class1 {&lt;BR /&gt;priority real-time;&lt;BR /&gt;}&lt;BR /&gt;class2 {&lt;BR /&gt;priority high;&lt;BR /&gt;}&lt;BR /&gt;class3 {&lt;BR /&gt;priority high;&lt;BR /&gt;}&lt;BR /&gt;class4 {&lt;BR /&gt;priority medium;&lt;BR /&gt;}&lt;BR /&gt;class5 {&lt;BR /&gt;priority medium;&lt;BR /&gt;}&lt;BR /&gt;class6 {&lt;BR /&gt;priority low;&lt;BR /&gt;}&lt;BR /&gt;class7 {&lt;BR /&gt;priority low;&lt;BR /&gt;}&lt;BR /&gt;class8 {&lt;BR /&gt;priority low;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;virtual-router {&lt;BR /&gt;default {&lt;BR /&gt;protocol {&lt;BR /&gt;bgp {&lt;BR /&gt;enable no;&lt;BR /&gt;dampening-profile {&lt;BR /&gt;default {&lt;BR /&gt;cutoff 1.25;&lt;BR /&gt;reuse 0.5;&lt;BR /&gt;max-hold-time 900;&lt;BR /&gt;decay-half-life-reachable 300;&lt;BR /&gt;decay-half-life-unreachable 900;&lt;BR /&gt;enable yes;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;routing-options {&lt;BR /&gt;graceful-restart {&lt;BR /&gt;enable yes;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;interface [ ethernet1/1 ethernet1/2];&lt;BR /&gt;ecmp {&lt;BR /&gt;algorithm {&lt;BR /&gt;ip-modulo;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;routing-table {&lt;BR /&gt;ip {&lt;BR /&gt;static-route {&lt;BR /&gt;default-gateway {&lt;BR /&gt;nexthop {&lt;BR /&gt;ip-address 192.168.120.1;&lt;BR /&gt;}&lt;BR /&gt;bfd {&lt;BR /&gt;profile None;&lt;BR /&gt;}&lt;BR /&gt;interface ethernet1/2;&lt;BR /&gt;metric 10;&lt;BR /&gt;destination 0.0.0.0/0;&lt;BR /&gt;}&lt;BR /&gt;intranet {&lt;BR /&gt;nexthop {&lt;BR /&gt;ip-address 0.0.0.0;&lt;BR /&gt;}&lt;BR /&gt;bfd {&lt;BR /&gt;profile None;&lt;BR /&gt;}&lt;BR /&gt;interface ethernet1/2;&lt;BR /&gt;metric 10;&lt;BR /&gt;destination 192.168.120.0/24;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;deviceconfig {&lt;BR /&gt;system {&lt;BR /&gt;ip-address 192.168.120.20;&lt;BR /&gt;netmask 255.255.255.0;&lt;BR /&gt;update-server updates.paloaltonetworks.com;&lt;BR /&gt;update-schedule {&lt;BR /&gt;threats {&lt;BR /&gt;recurring {&lt;BR /&gt;weekly {&lt;BR /&gt;day-of-week wednesday;&lt;BR /&gt;at 01:02;&lt;BR /&gt;action download-only;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;timezone US/Pacific;&lt;BR /&gt;service {&lt;BR /&gt;disable-telnet yes;&lt;BR /&gt;disable-http yes;&lt;BR /&gt;}&lt;BR /&gt;hostname fw01;&lt;BR /&gt;default-gateway 192.168.120.1;&lt;BR /&gt;dns-setting {&lt;BR /&gt;servers {&lt;BR /&gt;primary 8.8.8.8;&lt;BR /&gt;secondary 200.91.75.5;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;setting {&lt;BR /&gt;config {&lt;BR /&gt;rematch yes;&lt;BR /&gt;}&lt;BR /&gt;management {&lt;BR /&gt;hostname-type-in-syslog FQDN;&lt;BR /&gt;}&lt;BR /&gt;auto-mac-detect yes;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;vsys {&lt;BR /&gt;vsys1 {&lt;BR /&gt;application;&lt;BR /&gt;application-group;&lt;BR /&gt;zone {&lt;BR /&gt;trust {&lt;BR /&gt;network {&lt;BR /&gt;layer3 ethernet1/1;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;untrust {&lt;BR /&gt;network {&lt;BR /&gt;layer3 ethernet1/2;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;service;&lt;BR /&gt;service-group;&lt;BR /&gt;schedule;&lt;BR /&gt;rulebase {&lt;BR /&gt;security {&lt;BR /&gt;rules {&lt;BR /&gt;"allow access to internet" {&lt;BR /&gt;to untrust;&lt;BR /&gt;from trust;&lt;BR /&gt;source any;&lt;BR /&gt;destination any;&lt;BR /&gt;source-user any;&lt;BR /&gt;category any;&lt;BR /&gt;application any;&lt;BR /&gt;service any;&lt;BR /&gt;hip-profiles any;&lt;BR /&gt;action allow;&lt;BR /&gt;}&lt;BR /&gt;"allow access" {&lt;BR /&gt;to trust;&lt;BR /&gt;from untrust;&lt;BR /&gt;source any;&lt;BR /&gt;destination any;&lt;BR /&gt;source-user any;&lt;BR /&gt;category any;&lt;BR /&gt;application any;&lt;BR /&gt;service any;&lt;BR /&gt;hip-profiles any;&lt;BR /&gt;action allow;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;nat {&lt;BR /&gt;rules;&lt;BR /&gt;}&lt;BR /&gt;default-security-rules {&lt;BR /&gt;rules {&lt;BR /&gt;intrazone-default {&lt;BR /&gt;action allow;&lt;BR /&gt;log-start no;&lt;BR /&gt;log-end yes;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;import {&lt;BR /&gt;network {&lt;BR /&gt;interface [ ethernet1/1 ethernet1/2];&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;admin@fw01&amp;gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2016 20:10:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/110643#M45050</guid>
      <dc:creator>Apadilla</dc:creator>
      <dc:date>2016-09-05T20:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: issues after deployed VM-PA under VMware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/110645#M45051</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can to ping the google.com and updates.paloaltonetworks.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ping.JPG" style="width: 747px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5461i1E1FC300F76B693E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ping.JPG" alt="ping.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2016 20:24:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/110645#M45051</guid>
      <dc:creator>Apadilla</dc:creator>
      <dc:date>2016-09-05T20:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: issues after deployed VM-PA under VMware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/110646#M45052</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Changing ip on the linux&amp;nbsp;box&amp;nbsp;&lt;SPAN&gt;from one subnet to another&lt;/SPAN&gt; will not help&amp;nbsp;as you need to remap&amp;nbsp;you VM interface to one that connects to the Palo. Are you free now ? Can you email to mlskrypka@gmail.com&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2016 20:54:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/110646#M45052</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-09-05T20:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: issues after deployed VM-PA under VMware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/110705#M45055</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My email is apadillav21@gmail.com&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2016 04:55:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-after-deployed-vm-pa-under-vmware/m-p/110705#M45055</guid>
      <dc:creator>Apadilla</dc:creator>
      <dc:date>2016-09-06T04:55:02Z</dc:date>
    </item>
  </channel>
</rss>

