<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: interface to interface connevtivity not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151298#M50114</link>
    <description>&lt;P&gt;Ok if the FW is doing a routing for these&amp;nbsp;VLANs (subinterfaces) &amp;nbsp;we should see the session created&amp;nbsp;by palo&amp;nbsp;(we should see anyway even :0) and the traffic logs for these sessions. What pan-os&amp;nbsp;are you on? Is it hardware or VM appliance? Just in case you can override the&amp;nbsp;default policy to "allow" and log session in the start&amp;amp;end and initiate any traffic between the&amp;nbsp;VLANs and then check the logs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="INT-DF.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8641i26F39598C917F8B4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="INT-DF.PNG" alt="INT-DF.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am pretty&amp;nbsp;sure answer is there&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 05 Apr 2017 20:51:52 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-04-05T20:51:52Z</dc:date>
    <item>
      <title>interface to interface connevtivity not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151261#M50110</link>
      <description>&lt;P&gt;hello - apologies in advance but im a newbie on Palo Altos - come from working on Check Points and Junipers and am now here tasked to set up a palo alto.&amp;nbsp; I've got my network working to where all the vlans hanging off of the PAN can ping it and it can ping them however anything from interface to interface (vlan to vlan) isnt working.&amp;nbsp; I've got an any/any/any allow rule on the palo alto right now for the moment but am i missing a setting or a configuration item to make the PAN aware of the other networks? I didnt think i needed a route if everything was directly connected?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 16:52:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151261#M50110</guid>
      <dc:creator>bwfreas</dc:creator>
      <dc:date>2017-04-05T16:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: interface to interface connevtivity not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151289#M50111</link>
      <description>&lt;P&gt;Heys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;l guess you got all your subinterfaces in the different zones. How do you have your security policies configured? Do you allow the traffic between the VLANs? Can you post a screen shot of the policies? And yes if all subinterfaces (networks) terminates on palo no need routing as it is directly connected networks:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Layer-3-Subinterfaces/ta-p/67395" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Layer-3-Subinterfaces/ta-p/67395&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 18:26:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151289#M50111</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-05T18:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: interface to interface connevtivity not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151296#M50113</link>
      <description>&lt;P&gt;hello! they are about 5 interfaces configured and yes all different zones.&amp;nbsp; right now i just have 1 security rule installed for testing purposes that allows any source to any destination and any port accept.....so i didnt think i had a security policy issue? unless im not understanding the way to do PAFW policies exactly correct?&amp;nbsp; i can post a screenshot but ive since left the office will have to do when i return.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so im not starting to think/wonder that its not a routing issue as i figured it wasnt but maybe i dont have the right rules in place?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 20:31:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151296#M50113</guid>
      <dc:creator>bwfreas</dc:creator>
      <dc:date>2017-04-05T20:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: interface to interface connevtivity not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151298#M50114</link>
      <description>&lt;P&gt;Ok if the FW is doing a routing for these&amp;nbsp;VLANs (subinterfaces) &amp;nbsp;we should see the session created&amp;nbsp;by palo&amp;nbsp;(we should see anyway even :0) and the traffic logs for these sessions. What pan-os&amp;nbsp;are you on? Is it hardware or VM appliance? Just in case you can override the&amp;nbsp;default policy to "allow" and log session in the start&amp;amp;end and initiate any traffic between the&amp;nbsp;VLANs and then check the logs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="INT-DF.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8641i26F39598C917F8B4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="INT-DF.PNG" alt="INT-DF.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am pretty&amp;nbsp;sure answer is there&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 20:51:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151298#M50114</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-05T20:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: interface to interface connevtivity not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151328#M50119</link>
      <description>&lt;P&gt;thank you for the help so far it is greatly appreciated! these are hadrware appliances 3020's in a cluster - i have to get the OS version tomorrow can you tell me what timezone you are in so I can have an idea how far apart we are?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you tell me how to do a tcpdump on the PAFW?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also - the logs...for some reason i am not seeing any traffic logs appearing? it looks liek there were logs from several weeks ago but nothing since...so i was trying to determine if this traffic was reaching the PAFW first.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 23:01:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151328#M50119</guid>
      <dc:creator>bwfreas</dc:creator>
      <dc:date>2017-04-05T23:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: interface to interface connevtivity not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151333#M50121</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Run-a-Packet-Capture/ta-p/62390" target="_self"&gt;PCAP&lt;/A&gt;&amp;nbsp;here. Check the GUI option as it is easier than using cli. UK GMT time zone. Ok, let's do a step back then. Fist attach a &lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Allow-Ping-and-ICMP-on-Layer-3-Interface-of-Your-Palo/ta-p/58932" target="_self"&gt;mgmt&lt;/A&gt; profile with "ping" option ticked&amp;nbsp;to every subinterface and confirm you can reach all of them from the client side (from the every VLAN) and after we will go from there.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 23:14:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151333#M50121</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-05T23:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: interface to interface connevtivity not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151376#M50129</link>
      <description>&lt;P&gt;perfect - I am on UK as well at the moment&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i can confirm i have a mgmt profile with ping enabled on each interface and i can ping a device on each interface from the PAFW itself but I cannot ping from one device on one interface to another device behind another interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i will try the PCAP here this morning and will look at your other suggestion for the rule override.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 05:58:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151376#M50129</guid>
      <dc:creator>bwfreas</dc:creator>
      <dc:date>2017-04-06T05:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: interface to interface connevtivity not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151407#M50131</link>
      <description>&lt;P&gt;hello! good news i think i was able to resolve this particular issue - its a result of my lack of experience with palo alto rules - looks like i had an intrazone-default rule but i needed an interzone-default rule as well.&amp;nbsp; once i created that i have connectivity across the interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 09:36:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151407#M50131</guid>
      <dc:creator>bwfreas</dc:creator>
      <dc:date>2017-04-06T09:36:41Z</dc:date>
    </item>
    <item>
      <title>Re: interface to interface connevtivity not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151411#M50132</link>
      <description>&lt;P&gt;i do also have a bit of a more serious question regarding the configuration of a NAT rule and how to do all that is involved with that&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 08:24:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151411#M50132</guid>
      <dc:creator>bwfreas</dc:creator>
      <dc:date>2017-04-06T08:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: interface to interface connevtivity not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151415#M50133</link>
      <description>&lt;P&gt;hi there&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd like to request if you would mind asking your questions on the forum, as this will quite possibly help other novice users find their way around obstacles you are currently facing, think of the youngn's ! &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In regards to your NAT question, have you looked at this article: &lt;A title=" Getting Started: Network Address Translation (NAT)" href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Network-Address-Translation-NAT/ta-p/116340" target="_blank"&gt;Getting Started: Network Address Translation (NAT) ?&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;this should be a good start to provide an answer to most of your NAT questions, feel free to ask any and all followup questions (preferably on the forum so other people may benefit)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also, there's this series of articles that could help you set up: &lt;A title="Getting Started: The Series" href="https://live.paloaltonetworks.com/t5/Community-Blog/Getting-Started-The-Series/ba-p/67707" target="_blank"&gt;Getting Started: The Series&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 08:57:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151415#M50133</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-04-06T08:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: interface to interface connevtivity not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151424#M50140</link>
      <description>&lt;P&gt;Hey Brian,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think forum is a better way as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;has mentioned already. But just in case l also have sent a PM&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 09:26:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151424#M50140</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-06T09:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: interface to interface connevtivity not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151427#M50142</link>
      <description>&lt;P&gt;hi all yes thank you i agree it would be best to keep here for future reference so will do that&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 10:17:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151427#M50142</guid>
      <dc:creator>bwfreas</dc:creator>
      <dc:date>2017-04-06T10:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: interface to interface connevtivity not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151434#M50145</link>
      <description>&lt;P&gt;Palo has a Virtual Router concept:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/networking/configure-a-virtual-router.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/networking/configure-a-virtual-router.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It has to be attached to the interface&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 09:48:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151434#M50145</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-06T09:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: interface to interface connevtivity not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151439#M50147</link>
      <description>&lt;P&gt;you would configure the assigned virtual router to have a static entry of 0.0.0.0/0 and point it to the outside/untrust interface and assign the next hop&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8660iF0AC15612579DC32/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 09:54:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151439#M50147</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-04-06T09:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: interface to interface connevtivity not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151449#M50151</link>
      <description>&lt;P&gt;thank&amp;nbsp; you on that i think ive found it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 10:33:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-to-interface-connevtivity-not-working/m-p/151449#M50151</guid>
      <dc:creator>bwfreas</dc:creator>
      <dc:date>2017-04-06T10:33:57Z</dc:date>
    </item>
  </channel>
</rss>

