<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Different subnets on the same interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129796#M46785</link>
    <description>&lt;P&gt;perfect&lt;/P&gt;</description>
    <pubDate>Wed, 30 Nov 2016 09:26:30 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2016-11-30T09:26:30Z</dc:date>
    <item>
      <title>Different subnets on the same interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129118#M46743</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my ISP has assigned me with a /30 for the p2p connection and it is routing a /24 public subnet towards that /30. Meaning the WAN interface in the Palo will have to respond to many different ips on two different subnets. I haven't found any Kb that describe this scenario. Also please consider we are migrating from another devicewhich is perfectly working fine with this configuration, this in case we want to start pointing fingers to the ISP. No, it is definitely the Palo. Also for the sake of the conversation i am running a p3020 with 7.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- outbound traffic works (a machine inside the LAN can go out to the internet and uses one of the /24 addresses using the NAT rule i have configured).&lt;/P&gt;&lt;P&gt;- Inbound traffic (published services) do not work at all, it seems that the Palo never answer with an ARP to tell the other device that it "has" those ips.&lt;/P&gt;&lt;P&gt;- tried using loopbacks, or to add the additional subnet in the interface configuratio, i have zero traffic hitting the interface (no ARP sent)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Digging around i found two solutions, didnt manage to test them thou:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- forcing a GARP within the CLI (this is an horrible solution, and i would need to do this everytime i restart the Palo?)&lt;/P&gt;&lt;P&gt;- Add a fake route in the virtual router. Add a route to the /24 with next hop None, so that the Palo installs a route and start accepting the traffic. This is still a horrible workaround.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am wondering how you guys do it,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Nov 2016 22:25:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129118#M46743</guid>
      <dc:creator>myrdin</dc:creator>
      <dc:date>2016-11-27T22:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: Different subnets on the same interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129207#M46747</link>
      <description>&lt;P&gt;I have absolutely no issues with the same scenario on PA. Everything is working normally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the interface I have mutliple IPs, for example:&lt;/P&gt;&lt;P&gt;- 1.1.1.1/30 (connected network for routing)&lt;/P&gt;&lt;P&gt;- 2.2.2.x/24 (one IP from routed network)&lt;/P&gt;&lt;P&gt;- 2.2.2.y/32, 2.2.2.z/32, 2.2.2.c/32...... (other IPs from routed network) &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can use all IPs from SNAT, DNAT... No problems at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Grautitious ARP will be needed only right after from switching cables from previous device to PA. No fake routes are needed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2016 07:25:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129207#M46747</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-11-28T07:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Different subnets on the same interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129227#M46748</link>
      <description>&lt;P&gt;The GARP command from CLI is purely there for testing or temporary need to do so&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you add the second subnet to the itnerface and commit, the firewall will start responding to ARP requests for any IP that's configured in a proper inbound NAT policy (untrust to untrust , any to &amp;lt;externalIP&amp;gt;, translate to &amp;lt;internal IP&amp;gt;)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2016-11-28_11-02-13.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="2016-11-28_11-02-13.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2016 10:02:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129227#M46748</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-28T10:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Different subnets on the same interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129383#M46766</link>
      <description>&lt;P&gt;mmm thanks, so you have to add all the IPs one by one? I mean if i have 200 addresses in use on the /24, do i have to add them to the interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2016 21:33:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129383#M46766</guid>
      <dc:creator>myrdin</dc:creator>
      <dc:date>2016-11-28T21:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Different subnets on the same interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129478#M46769</link>
      <description>&lt;P&gt;In some cases yes; if you want to use one of those address for PA management you have to add&amp;nbsp;it to interface.&lt;/P&gt;&lt;P&gt;But in general no. If you use an addres in NAT rule it should be enough.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 07:09:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129478#M46769</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-11-29T07:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Different subnets on the same interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129518#M46770</link>
      <description>&lt;P&gt;u only need to add the ones you want the firewall to take ownership of&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;adding a subnet range to your interface only binds the one IP to that interface, granting 'ownership' to the firewall and making it respond to arp requests (eg 10.0.0.1/24 only has the firewall respond for .1, the rest is just 'the subnet' it belongs to)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you provide additional ip addresses for it to use, by creating NAT rules for example (or loopback interfaces), the firewall will start taking ownership for those&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;at one point you will need to define most of the IP addresses in a NAT policy anyway, as you don't want/need the firewall responding for an IP address that's not being used in policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P.S. you don't necessarily need to define them one by one, you can also create a &lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Network-Address-Translation-NAT/ta-p/116340" target="_blank"&gt;many-to-many&lt;/A&gt; policy that blankets the whole public subnet to an internal subnet, but I would recommend creating a policy per IP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 10:39:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129518#M46770</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-29T10:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: Different subnets on the same interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129712#M46781</link>
      <description>&lt;P&gt;Allright thanks very much guys. So this is what i am going to do:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- have the /30 configured in the WAN interface&lt;/P&gt;&lt;P&gt;- add also the /24 on the same WAN interface, with no /32 ip specified&lt;/P&gt;&lt;P&gt;- NAT rules are already there.&lt;/P&gt;&lt;P&gt;- use the GARP once i switch the cable to force the ISP device to update its own MAC table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;does this sound right?&lt;/P&gt;&lt;P&gt;thanks heaps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 21:39:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129712#M46781</guid>
      <dc:creator>myrdin</dc:creator>
      <dc:date>2016-11-29T21:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: Different subnets on the same interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129793#M46784</link>
      <description>&lt;P&gt;Yep, should be ok. Install policy also does a gratitious ARP so you can do that instead.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 09:19:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129793#M46784</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-11-30T09:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: Different subnets on the same interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129796#M46785</link>
      <description>&lt;P&gt;perfect&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 09:26:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/129796#M46785</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-30T09:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Different subnets on the same interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/131025#M46892</link>
      <description>&lt;P&gt;Hi guys thanks for all your help, turns out it was the ISP device that for some reason was working with the previous device and not with the Palo for unknown reasons. We bypassed that ISP router completely and boom everything started working straight away.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Dec 2016 23:34:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/131025#M46892</guid>
      <dc:creator>myrdin</dc:creator>
      <dc:date>2016-12-04T23:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Different subnets on the same interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/131424#M46953</link>
      <description>&lt;P&gt;they may have configured static ARP entries for your previous device &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 11:26:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-subnets-on-the-same-interface/m-p/131424#M46953</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-12-06T11:26:02Z</dc:date>
    </item>
  </channel>
</rss>

