<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Weird routing problem from mgmt interface. Icmp-redirects? If so, how to turn it off? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/146532#M49222</link>
    <description>&lt;P&gt;I have the packet capture. Looking at it in wireshark shows the same as the vwire capture. The ping requests are going to the right IP adress, but the wrong MAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the Palo's ARP table:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Address HWtype HWaddress Flags Mask Iface&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.160.0.3 ether 00:19:07:70:9c:00 C eth0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.160.0.4 ether a4:6c:2a:08:68:82 C eth0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;EM&gt;(This is the ASA)&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.160.0.6 ether bc:f1:f2:96:d0:42 C eth0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.160.0.2 ether 00:19:07:28:c8:40 C eth0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.160.0.1 ether 00:a2:ee:73:51:80 C eth0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;EM&gt;(This is the Palo's default gateway)&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Here's the outbound ping packet as shown in wireshark&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture1.JPG" style="width: 767px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8028i641935412BF7CE02/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture1.JPG" alt="Capture1.JPG" /&gt;&lt;/span&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Notice the destination MAC address is not the MAC address of the default gateway. It is the MAC address of the ASA.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Mar 2017 21:37:24 GMT</pubDate>
    <dc:creator>Ken_Cornetet</dc:creator>
    <dc:date>2017-03-07T21:37:24Z</dc:date>
    <item>
      <title>Weird routing problem from mgmt interface. Icmp-redirects? If so, how to turn it off?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/146436#M49192</link>
      <description>&lt;P&gt;I have a problem on a PA500. When it attempts to send traffic to one particular subnet via the management interface, the packets are sent to the wrong place. Instead of going to the default gateway, they go to an ASA. All other subnets route correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PA500 has a very simple config. The management interface is connected directly to a switch. A router is directly configured to the same switch. The Palo's default gateway is the router. &amp;nbsp; No dynamic routing is configured on the Palo. An ASA is connected to the switch through a vwire on this same unit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PA500 is only used in vwire mode with the switch-to-ASA vwire used to filter web browsing for the internal users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We noticed that this PA500 stopped getting updates a couple of weeks ago. When we checked why, we could see that DNS lookups were failing (the DNS server is on the problematic subnet). Attempts to ping anything on the problematic subnet from the cli fail. Access from the management interface to all other subnets work just fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When checking the monitor on the PA500, I can see that the traffic from the management interface to the problem subnet is going across the vwire to the ASA instead of to the router (which is the Palo's default gateway). The destination IP address is right, but the MAC address is the ASA's MAC, not the router's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at the ARP table on the Palo, the correct MAC is present for the IP address of the router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only mechanism I can think of that would explain this is if the Palo got an icmp-redirect from the router at some point telling it to use the ASA to get to the problem subnet. The router is doing dynamic routing, so it is possible that it termporarily lost a route to the problem subnet, and sent an icmp-redirect to the Palo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've searched the Palo docs, and I can't find mentions of the management interface supporting icmp-redirects, let alone how to clear it and turn it off.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there something else that could be causing this issue?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 16:03:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/146436#M49192</guid>
      <dc:creator>Ken_Cornetet</dc:creator>
      <dc:date>2017-03-07T16:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: Weird routing problem from mgmt interface. Icmp-redirects? If so, how to turn it off?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/146459#M49198</link>
      <description>&lt;P&gt;Interesting stuff! Can you do a &lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-To-Packet-Capture-tcpdump-On-Management-Interface/ta-p/55415" target="_self"&gt;PCAP&lt;/A&gt; from the&amp;nbsp;mgmt interface so that (hopefully) will explain a bit more.&amp;nbsp; Do you also remember what is changes since the&amp;nbsp;last time updates was working for you?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 17:05:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/146459#M49198</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-07T17:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: Weird routing problem from mgmt interface. Icmp-redirects? If so, how to turn it off?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/146495#M49209</link>
      <description>&lt;P&gt;I have a packet capture from the vwire. The source and destination IP, and source MAC addresses are as expected. The destination MAC is the ASA. Not much else to see. I don't see the management interface as an option in the packet capture filter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could span the switch port to a PC and wireshark it. I may do that. I do have an open ticket on this, but I'm waiting for a tech to contact me. If I don't hear anything soon, I'll do the port span.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This Palo has been in operation for at least a year without configuration changes (other than rule changes and updates).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 17:58:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/146495#M49209</guid>
      <dc:creator>Ken_Cornetet</dc:creator>
      <dc:date>2017-03-07T17:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: Weird routing problem from mgmt interface. Icmp-redirects? If so, how to turn it off?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/146503#M49213</link>
      <description>&lt;P&gt;Just follow the article in the&amp;nbsp;"PCAP" link so you can do PCAP on the&amp;nbsp;mgmt interface. You cannot do it from the GUI unfortunately. This problem can be fixed if any other interfaces on PA got an lnternet access using service route option:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="serv rt.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8023i867421D09F1F7BE2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="serv rt.PNG" alt="serv rt.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But we want to understand what is going on here :0&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 21:08:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/146503#M49213</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-07T21:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: Weird routing problem from mgmt interface. Icmp-redirects? If so, how to turn it off?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/146520#M49220</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noservice.JPG" style="width: 624px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8025i89F16F762D4192FF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="noservice.JPG" alt="noservice.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 21:03:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/146520#M49220</guid>
      <dc:creator>Ken_Cornetet</dc:creator>
      <dc:date>2017-03-07T21:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Weird routing problem from mgmt interface. Icmp-redirects? If so, how to turn it off?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/146532#M49222</link>
      <description>&lt;P&gt;I have the packet capture. Looking at it in wireshark shows the same as the vwire capture. The ping requests are going to the right IP adress, but the wrong MAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the Palo's ARP table:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Address HWtype HWaddress Flags Mask Iface&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.160.0.3 ether 00:19:07:70:9c:00 C eth0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.160.0.4 ether a4:6c:2a:08:68:82 C eth0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;EM&gt;(This is the ASA)&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.160.0.6 ether bc:f1:f2:96:d0:42 C eth0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.160.0.2 ether 00:19:07:28:c8:40 C eth0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.160.0.1 ether 00:a2:ee:73:51:80 C eth0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;EM&gt;(This is the Palo's default gateway)&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Here's the outbound ping packet as shown in wireshark&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture1.JPG" style="width: 767px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8028i641935412BF7CE02/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture1.JPG" alt="Capture1.JPG" /&gt;&lt;/span&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Notice the destination MAC address is not the MAC address of the default gateway. It is the MAC address of the ASA.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 21:37:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/146532#M49222</guid>
      <dc:creator>Ken_Cornetet</dc:creator>
      <dc:date>2017-03-07T21:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Weird routing problem from mgmt interface. Icmp-redirects? If so, how to turn it off?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/147941#M49489</link>
      <description>Hi Ken,&lt;BR /&gt;&lt;BR /&gt;Is there proxy arp enabled on the ASA?</description>
      <pubDate>Thu, 16 Mar 2017 01:00:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/147941#M49489</guid>
      <dc:creator>ansharma</dc:creator>
      <dc:date>2017-03-16T01:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: Weird routing problem from mgmt interface. Icmp-redirects? If so, how to turn it off?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/147984#M49495</link>
      <description>&lt;P&gt;From the CLI you can use the 'tcpdump' command to packetcapture directly on the management interface&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you make sure to use the 'show arp management' command (so no dataplane arp information is included)&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2017 09:32:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/147984#M49495</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-03-16T09:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: Weird routing problem from mgmt interface. Icmp-redirects? If so, how to turn it off?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/147985#M49496</link>
      <description>&lt;P&gt;This is very interesting one l am really curious to know what is causing this :0&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2017 09:35:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/147985#M49496</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-16T09:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: Weird routing problem from mgmt interface. Icmp-redirects? If so, how to turn it off?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/149006#M49710</link>
      <description>&lt;P&gt;AFAIK, A Cisco ASA will only proxy arp for a NAT address. Obviously, the IP address of my router isn't a NAT address in the ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Besides, doing a "show arp management dns no" give the following table&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Address HWtype HWaddress Flags Mask Iface&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.160.0.3 ether 00:19:07:70:9c:00 C eth0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.160.0.4 ether a4:6c:2a:08:68:82 C eth0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.160.0.6 ether bc:f1:f2:96:d0:42 C eth0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.160.0.2 ether 00:19:07:28:c8:40 C eth0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.160.0.11 ether 00:b0:e1:29:90:08 C eth0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.160.0.1 ether 00:a2:ee:73:51:80 C &lt;/FONT&gt;&lt;FONT face="courier new,courier"&gt;eth0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Notice that the ARP entry for 10.160.0.1 (the Palo's default gateway) is the router's MAC address.&lt;/FONT&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;The ASA shows up as the correct IP/MAC address (10.160.0.4)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 20:24:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/149006#M49710</guid>
      <dc:creator>Ken_Cornetet</dc:creator>
      <dc:date>2017-03-22T20:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: Weird routing problem from mgmt interface. Icmp-redirects? If so, how to turn it off?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/149007#M49711</link>
      <description>&lt;P&gt;So is Palo tech support &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 20:24:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weird-routing-problem-from-mgmt-interface-icmp-redirects-if-so/m-p/149007#M49711</guid>
      <dc:creator>Ken_Cornetet</dc:creator>
      <dc:date>2017-03-22T20:24:53Z</dc:date>
    </item>
  </channel>
</rss>

