<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Route check on PA firewall - Longest match not there?? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/route-check-on-pa-firewall-longest-match-not-there/m-p/123141#M46197</link>
    <description>&lt;P&gt;Thanks. Unfortunately traceroute is not allowed on firewall. For outgoing self traffic of firewall, like ping/traceroute, should I need intra-zone policy to allow source address: self ip of firewall, destination: any ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But surprisingly, show routing route command does not show matching route. Strange ! or I am missing something&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciated your reply&lt;/P&gt;</description>
    <pubDate>Wed, 02 Nov 2016 06:48:38 GMT</pubDate>
    <dc:creator>ghostrider</dc:creator>
    <dc:date>2016-11-02T06:48:38Z</dc:date>
    <item>
      <title>Route check on PA firewall - Longest match not there??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-check-on-pa-firewall-longest-match-not-there/m-p/123007#M46191</link>
      <description>&lt;P&gt;Hello Experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to check which route is matching for some host IP like 10.155.7.33, so I can check the outgoing interface and destination zone for policy lookup. When I run the command “show routing route destination 10.155.7.33/32”, it is showing nothing. Although I have matching route 10.115.7.0/24 in the routing table.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly help !&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2016 20:11:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-check-on-pa-firewall-longest-match-not-there/m-p/123007#M46191</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-11-01T20:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: Route check on PA firewall - Longest match not there??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-check-on-pa-firewall-longest-match-not-there/m-p/123043#M46192</link>
      <description>&lt;P&gt;Use traceroute command&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2016 22:08:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-check-on-pa-firewall-longest-match-not-there/m-p/123043#M46192</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-11-01T22:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: Route check on PA firewall - Longest match not there??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-check-on-pa-firewall-longest-match-not-there/m-p/123141#M46197</link>
      <description>&lt;P&gt;Thanks. Unfortunately traceroute is not allowed on firewall. For outgoing self traffic of firewall, like ping/traceroute, should I need intra-zone policy to allow source address: self ip of firewall, destination: any ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But surprisingly, show routing route command does not show matching route. Strange ! or I am missing something&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciated your reply&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 06:48:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-check-on-pa-firewall-longest-match-not-there/m-p/123141#M46197</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-11-02T06:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: Route check on PA firewall - Longest match not there??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-check-on-pa-firewall-longest-match-not-there/m-p/123158#M46201</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;intra-zone traffic is permitted by default on FW. Self-traffic is not scanned by security policies, so if it is destined to the FW or initiated by FW.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 09:14:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-check-on-pa-firewall-longest-match-not-there/m-p/123158#M46201</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-11-02T09:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: Route check on PA firewall - Longest match not there??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-check-on-pa-firewall-longest-match-not-there/m-p/123199#M46205</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our fw, intra-zone policies are blocked so In this case I need to create explicit rules for traffic destined to the FW or initiated by FW?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciated your reply&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 11:16:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-check-on-pa-firewall-longest-match-not-there/m-p/123199#M46205</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-11-02T11:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Route check on PA firewall - Longest match not there??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-check-on-pa-firewall-longest-match-not-there/m-p/125103#M46397</link>
      <description>&lt;P&gt;The "show" command would only find something if you had a route exactly for&amp;nbsp;&lt;SPAN&gt;10.155.7.33/32.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, what you want to use is the "test" command:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;test routing fib-lookup virtual-router default ip &amp;lt;destination-ip&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Output will show which route matches this destination IP address.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 22:00:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-check-on-pa-firewall-longest-match-not-there/m-p/125103#M46397</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2016-11-08T22:00:24Z</dc:date>
    </item>
  </channel>
</rss>

