<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Duplicate IP issue on dual WAN config in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/duplicate-ip-issue-on-dual-wan-config/m-p/169317#M53813</link>
    <description>&lt;P&gt;I hope I'm in the correct forum and someone can help me. &amp;nbsp;I suspect this is an easier problem than I'm making it out to be but here's the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We used to have two physically segregated networks. &amp;nbsp;Let's call them Network A and Network B. &amp;nbsp;Each have statically assigned Public IPs, dedicated gateways, etc. &amp;nbsp;I recently moved both A and B to our new&amp;nbsp;Palo Alto and segregated them via Production and Guest Zones so&amp;nbsp;their interfaces pass Internet traffic only on the Network segment to which they are assigned. &amp;nbsp;For example: A -- Eth1/2 Private NAT to Eth1/1 Public WAN and B -- Eth1/9 Private NAT to Eth1/13 WAN Public. &amp;nbsp;It's a pretty simple and straight-forward config and there are no rules in place that allow the interfaces of network A and B to talk to one another. &amp;nbsp;Both networks are within a block of assigned IPs from our ISP with the following mask bits.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network A = x.x.x.18/28 (x.x.x.17 through x.x.x.30) Eth1/1&lt;/P&gt;&lt;P&gt;Network B = x.x.x.91/29 (x.x.x.89 through x.x.x.94) Eth1/13&lt;/P&gt;&lt;P&gt;As you can see, there is no way either of these networks can cross paths. &amp;nbsp;However, I'm getting numerous IP conflicts on Eth1/1 that every Pulically assigned IP within my /29 network is conflicting with an IP from destination Eth1/13. &amp;nbsp;&lt;/P&gt;&lt;P&gt;log:&lt;/P&gt;&lt;P&gt;Received conflicting ARP on Interface ethernet1/1 indicating duplicate IP x.x.x.21, sender mac 00:1b:..... (eth1/13 mac)&lt;/P&gt;&lt;P&gt;and it repeats for every used IP from x.x.x.19 through 30 from the "A" network.&lt;/P&gt;&lt;P&gt;I know I've got something whacked up in my configs somewhere but I can't seem to locate this animal. &amp;nbsp;NAT rule looks right. &amp;nbsp;I come from a Sonicwall background so I'm pretty new to PA so I'm thinking I missed something somewhere. &amp;nbsp;Any input would be helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Aug 2017 15:55:24 GMT</pubDate>
    <dc:creator>Vincent.Dice</dc:creator>
    <dc:date>2017-08-01T15:55:24Z</dc:date>
    <item>
      <title>Duplicate IP issue on dual WAN config</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/duplicate-ip-issue-on-dual-wan-config/m-p/169317#M53813</link>
      <description>&lt;P&gt;I hope I'm in the correct forum and someone can help me. &amp;nbsp;I suspect this is an easier problem than I'm making it out to be but here's the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We used to have two physically segregated networks. &amp;nbsp;Let's call them Network A and Network B. &amp;nbsp;Each have statically assigned Public IPs, dedicated gateways, etc. &amp;nbsp;I recently moved both A and B to our new&amp;nbsp;Palo Alto and segregated them via Production and Guest Zones so&amp;nbsp;their interfaces pass Internet traffic only on the Network segment to which they are assigned. &amp;nbsp;For example: A -- Eth1/2 Private NAT to Eth1/1 Public WAN and B -- Eth1/9 Private NAT to Eth1/13 WAN Public. &amp;nbsp;It's a pretty simple and straight-forward config and there are no rules in place that allow the interfaces of network A and B to talk to one another. &amp;nbsp;Both networks are within a block of assigned IPs from our ISP with the following mask bits.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network A = x.x.x.18/28 (x.x.x.17 through x.x.x.30) Eth1/1&lt;/P&gt;&lt;P&gt;Network B = x.x.x.91/29 (x.x.x.89 through x.x.x.94) Eth1/13&lt;/P&gt;&lt;P&gt;As you can see, there is no way either of these networks can cross paths. &amp;nbsp;However, I'm getting numerous IP conflicts on Eth1/1 that every Pulically assigned IP within my /29 network is conflicting with an IP from destination Eth1/13. &amp;nbsp;&lt;/P&gt;&lt;P&gt;log:&lt;/P&gt;&lt;P&gt;Received conflicting ARP on Interface ethernet1/1 indicating duplicate IP x.x.x.21, sender mac 00:1b:..... (eth1/13 mac)&lt;/P&gt;&lt;P&gt;and it repeats for every used IP from x.x.x.19 through 30 from the "A" network.&lt;/P&gt;&lt;P&gt;I know I've got something whacked up in my configs somewhere but I can't seem to locate this animal. &amp;nbsp;NAT rule looks right. &amp;nbsp;I come from a Sonicwall background so I'm pretty new to PA so I'm thinking I missed something somewhere. &amp;nbsp;Any input would be helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 15:55:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/duplicate-ip-issue-on-dual-wan-config/m-p/169317#M53813</guid>
      <dc:creator>Vincent.Dice</dc:creator>
      <dc:date>2017-08-01T15:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate IP issue on dual WAN config</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/duplicate-ip-issue-on-dual-wan-config/m-p/169326#M53814</link>
      <description>&lt;P&gt;There are two issues going on right now:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Layer 2 Issue&lt;/P&gt;&lt;P&gt;* Layer 3 Issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your design should be fine. &amp;nbsp;The networks do not overlap or coflict with each other. &amp;nbsp;I'm going to throw out a ficticious subnet to talk through the issue further&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;= = = = = = = = = = = = = = = = = =&lt;/P&gt;&lt;P&gt;Eth1/1 IP: &amp;nbsp;10.0.0.18/28&lt;/P&gt;&lt;P&gt;Mask:&amp;nbsp; /28 = 255.255.255.240&lt;/P&gt;&lt;P&gt;Subnet IP: 10.00.0.16&lt;/P&gt;&lt;P&gt;Broadcast IP: 10.0.0.31&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;= = = = = = = = = = = = = = = = = =&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Eth1/13 IP: &amp;nbsp;10.0.0.91/29&lt;/P&gt;&lt;P&gt;Mask:&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;/28 = 255.255.255.248&lt;/P&gt;&lt;P&gt;Subnet IP: 10.00.0.88&lt;/P&gt;&lt;P&gt;Broadcast IP: 10.0.0.95&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;= = = = = = = = = = = = = = = = = =&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Layer3 Issue:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;These two IP ranges do not overlap as one goes from .16 to .31 and the next from .88 to .95. &amp;nbsp;They cannot have an overlap of IP address. &amp;nbsp;This is the Layer3 issue. &amp;nbsp;I suspect your subnet mask is wrong one or both of the interfaces. &amp;nbsp;That is the only way they can have an overlapping range of addresses&amp;nbsp;(if you have the proper IP on each interface). &amp;nbsp;The other possibility is that you don't have .91 on eth1/13 and it has an incorrect IP in the original range.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Layer2 Issue:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I suspect you have both interfaces Eth1/1 and Eth1/13 connected to the same switch. &amp;nbsp;If you do, they should be in two different VLANs (Virutal LANs). &amp;nbsp;If your switch does not have a management address (unmanaged) you won't be able to setup multiple VLANs and are "multi-netting" the setup (running two mis-matching networks on the same vlan). &amp;nbsp;This "could" work but is not a good idea or best practice from any switching vendor. &amp;nbsp;Separating the networks into their own VLAN or connecting the interfaces to separate swithes if VLANning is not possible will keep the interfaces from talking to each other. &amp;nbsp;Traffic from Eth1/1 should never be able to communicate to Eth1/13 directly as they should be on separate networks.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 16:09:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/duplicate-ip-issue-on-dual-wan-config/m-p/169326#M53814</guid>
      <dc:creator>davanderson</dc:creator>
      <dc:date>2017-08-01T16:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate IP issue on dual WAN config</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/duplicate-ip-issue-on-dual-wan-config/m-p/169602#M53857</link>
      <description>&lt;P&gt;Thank you for the quick reply d.anderson. &amp;nbsp;&lt;/P&gt;&lt;P&gt;I've re-confirmed its not a layer 3 issue. &amp;nbsp;IPs are good, masks are good as well as GW. &amp;nbsp;For now, I want to put a checkmark on that to-do.&lt;/P&gt;&lt;P&gt;Layer 2 solution makes the most sense for my particular setup. &amp;nbsp;You are correct that both 1/13 and 1/1 WAN ports go back to a switch in our rack. &amp;nbsp;However this switch is property of and managed by our ISP so I have no access to it. &amp;nbsp;It serves as our DMARC and serves out three different Networks. &amp;nbsp;The two I speak of (A and B) are the only two "close" in range so a misconfig of mask bits would easily cause an overlap although it's not on my end. &amp;nbsp;Additionally, we have a Network C from the ISP Switch too but it's a completely different network, subnet, set as DHCP, and causes no issue in the PA so this all makes sense. &amp;nbsp;Expanding on&amp;nbsp;your example of the ficticious networks, Network C would be like this, respectively:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;= = = = = = = = = = = = = = = = = =&lt;/P&gt;&lt;P&gt;Eth1/1 IP: &amp;nbsp;10.10.10.18/28&lt;/P&gt;&lt;P&gt;Mask:&amp;nbsp; /28 = 255.255.255.240&lt;/P&gt;&lt;P&gt;Subnet IP: 10.10.10.16&lt;/P&gt;&lt;P&gt;Broadcast IP: 101.10.10.31&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;= = = = = = = = = = = = = = = = = =&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;At this point, I'll contact my ISP for a resolution and let you know the final result. &amp;nbsp;Thank you so much for taking the time to help me. &amp;nbsp;I'll mark your post as the resolution once I've confirmed.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 13:38:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/duplicate-ip-issue-on-dual-wan-config/m-p/169602#M53857</guid>
      <dc:creator>Vincent.Dice</dc:creator>
      <dc:date>2017-08-02T13:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate IP issue on dual WAN config</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/duplicate-ip-issue-on-dual-wan-config/m-p/174130#M54745</link>
      <description>&lt;P&gt;Thank you for your help!&lt;/P&gt;&lt;P&gt;My ISP was a bit slow on their response but it was in fact on their end and on their switch as d.anderson suggested.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 13:44:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/duplicate-ip-issue-on-dual-wan-config/m-p/174130#M54745</guid>
      <dc:creator>Vincent.Dice</dc:creator>
      <dc:date>2017-08-31T13:44:50Z</dc:date>
    </item>
  </channel>
</rss>

