<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Troubleshooting Slowness with Traffic, Management in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-slowness-with-traffic-management/m-p/174849#M54857</link>
    <description>&lt;P&gt;computer ip is 10.1.1.60&lt;/P&gt;&lt;P&gt;internal interface for paloalto is 10.1.1.254&lt;/P&gt;&lt;P&gt;external ip is 172.16.0.1&lt;/P&gt;&lt;P&gt;modem ip is 172.16.0.254&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from CLI: Ping using the external interface ip as source works&lt;/P&gt;&lt;P&gt;ping source 172.16.0.1 host yahoo.com&lt;BR /&gt;PING yahoo.com (98.138.253.109) from 172.16.0.1 : 56(84) bytes of data.&lt;BR /&gt;64 bytes from ir1.fp.vip.ne1.yahoo.com (98.138.253.109): icmp_seq=1 ttl=55 time=61.1 ms&lt;BR /&gt;64 bytes from ir1.fp.vip.ne1.yahoo.com (98.138.253.109): icmp_seq=2 ttl=55 time=59.9 ms&lt;BR /&gt;64 bytes from ir1.fp.vip.ne1.yahoo.com (98.138.253.109): icmp_seq=3 ttl=55 time=68.8 ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but ping using internal ip doesn't work&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Sep 2017 07:48:34 GMT</pubDate>
    <dc:creator>GWASSEF</dc:creator>
    <dc:date>2017-09-05T07:48:34Z</dc:date>
    <item>
      <title>Troubleshooting Slowness with Traffic, Management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-slowness-with-traffic-management/m-p/174822#M54852</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am reconfiguring my PA-100 VM, as i am changing the network design, but after i changed the interfaces IP, Router configuraattion, NAT policy, and security policy. I cannot get to internet and in monitroing end reason is "aged-out"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From CLI i can ping and traceroute using the management and external interface as source, but i cannot use my internal interface to ping or traceroute.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even i cannot ping the external interface using hte internal interface (after enabling management policy for the external interface)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cannot even ping between the Mgmt Interface and the internal Interface and they are in the same network (default intrazone traffice rule active as well)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would appreciate any direction in troubleshooting the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 05:47:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-slowness-with-traffic-management/m-p/174822#M54852</guid>
      <dc:creator>GWASSEF</dc:creator>
      <dc:date>2017-09-05T05:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting Slowness with Traffic, Management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-slowness-with-traffic-management/m-p/174844#M54854</link>
      <description>&lt;P&gt;For TCP traffic "aged-out" could indicate not completed 3-way handshake. &amp;nbsp;Few things&amp;nbsp;to confirm:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Can Palo access the internet over the External interface?&lt;/P&gt;&lt;P&gt;2) Make sure routing is correct&lt;/P&gt;&lt;P&gt;3) Remember, traffic generated by the firewall will not be a subject for policy inspection (unless you&amp;nbsp;source the packet from the interface which is assigned to the security zone).&lt;/P&gt;&lt;P&gt;4) Post the&amp;nbsp;detailed&amp;nbsp;log view of any aged-out session (magnifying glass view)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 07:31:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-slowness-with-traffic-management/m-p/174844#M54854</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-09-05T07:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting Slowness with Traffic, Management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-slowness-with-traffic-management/m-p/174847#M54855</link>
      <description>&lt;P&gt;- Palo alto can access internet via external interface and management interface, but not the internal interface.&lt;/P&gt;&lt;P&gt;- I have only one static route for 0.0.0.0/0 that goes to External Interface and the next hope is my modem ip address, metric is et to 10 and unicast is routing table.&lt;/P&gt;&lt;P&gt;- i am sourcing the traffice from the source zone, and&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;attached is the print screen from my details logs&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2017-09-05 at 1.39.00 AM.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11141i5D0C04564B0DB9B7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2017-09-05 at 1.39.00 AM.png" alt="Screen Shot 2017-09-05 at 1.39.00 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 07:39:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-slowness-with-traffic-management/m-p/174847#M54855</guid>
      <dc:creator>GWASSEF</dc:creator>
      <dc:date>2017-09-05T07:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting Slowness with Traffic, Management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-slowness-with-traffic-management/m-p/174848#M54856</link>
      <description>&lt;P&gt;&lt;SPAN&gt;You natting your traffic to the 10.1.1.254, from the source ip 10.1.1.60? Why?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What is your external ip address? You have modem/router, right. Does it know&amp;nbsp;how to get back to the networks behind the FW?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 07:45:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-slowness-with-traffic-management/m-p/174848#M54856</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-09-05T07:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting Slowness with Traffic, Management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-slowness-with-traffic-management/m-p/174849#M54857</link>
      <description>&lt;P&gt;computer ip is 10.1.1.60&lt;/P&gt;&lt;P&gt;internal interface for paloalto is 10.1.1.254&lt;/P&gt;&lt;P&gt;external ip is 172.16.0.1&lt;/P&gt;&lt;P&gt;modem ip is 172.16.0.254&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from CLI: Ping using the external interface ip as source works&lt;/P&gt;&lt;P&gt;ping source 172.16.0.1 host yahoo.com&lt;BR /&gt;PING yahoo.com (98.138.253.109) from 172.16.0.1 : 56(84) bytes of data.&lt;BR /&gt;64 bytes from ir1.fp.vip.ne1.yahoo.com (98.138.253.109): icmp_seq=1 ttl=55 time=61.1 ms&lt;BR /&gt;64 bytes from ir1.fp.vip.ne1.yahoo.com (98.138.253.109): icmp_seq=2 ttl=55 time=59.9 ms&lt;BR /&gt;64 bytes from ir1.fp.vip.ne1.yahoo.com (98.138.253.109): icmp_seq=3 ttl=55 time=68.8 ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but ping using internal ip doesn't work&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 07:48:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-slowness-with-traffic-management/m-p/174849#M54857</guid>
      <dc:creator>GWASSEF</dc:creator>
      <dc:date>2017-09-05T07:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting Slowness with Traffic, Management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-slowness-with-traffic-management/m-p/174850#M54858</link>
      <description>&lt;P&gt;Ok, thanks. You need to configure your Palo to NAT all internal traffic to its External IP&amp;nbsp;(&lt;SPAN&gt;172.16.0.1). In case you don't want to do that, then please add a static route on your router/modem pointing to the Palo external ip&amp;nbsp;address &amp;nbsp;(172.16.0.1) on how to reach &amp;nbsp;10.1.1.0/24 subnet.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 07:52:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-slowness-with-traffic-management/m-p/174850#M54858</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-09-05T07:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting Slowness with Traffic, Management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-slowness-with-traffic-management/m-p/174853#M54859</link>
      <description>&lt;P&gt;Thanks, this does make sense, i really missed it from the lots of changes i have been through. Thanks again.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 07:55:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-slowness-with-traffic-management/m-p/174853#M54859</guid>
      <dc:creator>GWASSEF</dc:creator>
      <dc:date>2017-09-05T07:55:45Z</dc:date>
    </item>
  </channel>
</rss>

