<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pinning Palo sub-interface reply goes to  00:70:76:69:66:00 as a destination MAC. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/193385#M57981</link>
    <description>&lt;P&gt;I'm seeing this Mac in a PCAP I did on the firewall receive filter while debugging a IP Frag issue where in the ISAKMP packets are being fragmented while performing certificate auth on the IKE gateway. Its causing the IP Frag option to be hit in the Zone protection setting and the IKE v2 setup to fail. Should I assume this is the expected dst mac since this is hitting the zone protection and being forwarded to an internal MAC to be dropped?&lt;/P&gt;</description>
    <pubDate>Fri, 29 Dec 2017 06:43:06 GMT</pubDate>
    <dc:creator>LCMember4723</dc:creator>
    <dc:date>2017-12-29T06:43:06Z</dc:date>
    <item>
      <title>Pinging Palo sub-interface reply goes to  00:70:76:69:66:00 as a destination MAC.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/162889#M52786</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;l was thinking that this might be an interesting one. Any comments more than welcome &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN-OS 7.1.10 PA-5060&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;635&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 66.604593&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.13.178.246&amp;nbsp;&amp;nbsp; 10.13.128.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ICMP&amp;nbsp;&amp;nbsp;&amp;nbsp; 394&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Echo (ping) request&amp;nbsp; id=0x0029, seq=0/0, ttl=64 (reply in 636)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Ethernet II, Src: Apple_7e:b6:ff &lt;FONT color="#FF0000"&gt;(38:ca:da:7e:b6:ff)&lt;/FONT&gt;, Dst: PaloAlto_00:01:27 (00:1b:17:yy:yy:yy)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination: PaloAlto_00:01:27 (00:1b:17:yy:yy:yy)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source: Apple_7e:b6:ff &lt;FONT color="#FF0000"&gt;(38:ca:da:7e:b6:ff)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type: 802.1Q Virtual LAN (0x8100)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;636&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 66.604754&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.13.128.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.13.178.246&amp;nbsp;&amp;nbsp; ICMP&amp;nbsp;&amp;nbsp;&amp;nbsp; 394&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Echo (ping) reply&amp;nbsp;&amp;nbsp;&amp;nbsp; id=0x0029, seq=0/0, ttl=64 (request in 635)&lt;BR /&gt;&lt;BR /&gt;Ethernet II, Src: PaloAlto_00:01:27 (00:1b:17:00:01:27), Dst: &lt;FONT color="#FF0000"&gt;00:70:76:69:66:00 (00:70:76:69:66:00)&lt;/FONT&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination: &lt;FONT color="#FF0000"&gt;00:70:76:69:66:00 (00:70:76:69:66:00)&lt;/FONT&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source: PaloAlto_00:01:27 (00:1b:17:yy:yy:yy)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type: 802.1Q Virtual LAN (0x8100)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; debug dataplane internal vif address&lt;BR /&gt;&lt;BR /&gt;1: lo: &amp;lt;LOOPBACK,UP,10000&amp;gt; mtu 16436 qdisc noqueue&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet 127.0.0.1/24 scope host lo&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet6 ::1/128 scope host&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; valid_lft forever preferred_lft forever&lt;BR /&gt;2: eth4: &amp;lt;BROADCAST,MULTICAST&amp;gt; mtu 1500 qdisc noop qlen 1000&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link/ether y:fe brd ff:ff:ff:ff:ff:ff&lt;BR /&gt;3: eth5: &amp;lt;BROADCAST,MULTICAST&amp;gt; mtu 1500 qdisc noop qlen 1000&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link/ether y:ff brd ff:ff:ff:ff:ff:ff&lt;BR /&gt;4: eth3: &amp;lt;BROADCAST,MULTICAST,UP,10000&amp;gt; mtu 1500 qdisc mq qlen 1000&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link/ether y:ff brd ff:ff:ff:ff:ff:ff&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet6 fe80::270:76ff:fe69:66ff/64 scope link&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; valid_lft forever preferred_lft forever&lt;BR /&gt;5: eth2: &amp;lt;BROADCAST,MULTICAST,UP,10000&amp;gt; mtu 1500 qdisc mq qlen 1000&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link/ether y:fd brd ff:ff:ff:ff:ff:ff&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet 127.1.1.1/24 brd 127.1.1.255 scope host eth2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet6 fe80::290:bff:fe2d:1fd/64 scope link&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; valid_lft forever preferred_lft forever&lt;BR /&gt;6: eth1: &amp;lt;BROADCAST,MULTICAST,UP,10000&amp;gt; mtu 1500 qdisc pfifo_fast qlen 1000&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link/ether y:fb brd ff:ff:ff:ff:ff:ff&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet 192.168.xx.x/29 brd 192.168.xx.xscope global eth1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet6 fe80::290:bff:fe2d:1fb/64 scope link&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; valid_lft forever preferred_lft forever&lt;BR /&gt;7: eth0: &amp;lt;BROADCAST,MULTICAST,UP,10000&amp;gt; mtu 1500 qdisc pfifo_fast qlen 1000&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link/ether y:fa brd ff:ff:ff:ff:ff:ff&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet 172.27.xx.x/24 brd 172.27.xx.x scope global eth0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet6 fe80::290:bff:fe2d:1fa/64 scope link&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; valid_lft forever preferred_lft forever&lt;BR /&gt;8: eth3.251@eth3: &amp;lt;BROADCAST,MULTICAST,UP,10000&amp;gt; mtu 1500 qdisc noqueue&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link/ether y:ff brd ff:ff:ff:ff:ff:ff&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet 127.131.1.1/16 scope host eth3.251&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet 127.132.1.1/16 scope host eth3.251&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet6 ::ffff:127.131.1.1/112 scope global&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; valid_lft forever preferred_lft forever&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet6 fe80::270:76ff:fe69:66ff/64 scope link&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; valid_lft forever preferred_lft forever&lt;BR /&gt;9: eth3.1@eth3: &amp;lt;BROADCAST,MULTICAST,UP,10000&amp;gt; mtu 1500 qdisc noqueue&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link/ether y:ff brd ff:ff:ff:ff:ff:ff&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet 127.130.1.1/16 scope host eth3.1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet 10.13.0.1/17 scope global eth3.1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet 10.13.128.1/18 scope global eth3.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thx,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Myky&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 08:08:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/162889#M52786</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-23T08:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: Pinning Palo sub-interface reply goes to  00:70:76:69:66:00 as a destination MAC.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/162903#M52787</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;00:70:76:69:66:00 is the Palo Alto Firewall&amp;nbsp;internal MAC address.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Only as root you can find it like this example (note that only support can enter as root) :&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;root@PA--5020 /]# arp -a&amp;nbsp;&lt;BR /&gt;? (192.168.11.110) at 00:70:76:69:66:00 [ether] on eth3.1&amp;nbsp;&lt;BR /&gt;? (127.9.1.240) at 00:70:76:69:66:00 [ether] PERM on eth3.1&amp;nbsp;&lt;BR /&gt;? (127.11.1.240) at 00:70:76:69:66:00 [ether] PERM on eth3.251&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It is not unexpected behavior that the internal MAC address shows up&amp;nbsp;in debugs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers !&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 08:06:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/162903#M52787</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-06-23T08:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: Pinning Palo sub-interface reply goes to  00:70:76:69:66:00 as a destination MAC.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/162904#M52788</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response. So in the debug it is expected behaviour to see this MAC?&lt;/P&gt;&lt;P&gt;Should l run just simple PCAP on FW to confirm correct MAC address mapping or PCAP will also show the same output?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 08:11:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/162904#M52788</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-23T08:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: Pinning Palo sub-interface reply goes to  00:70:76:69:66:00 as a destination MAC.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/162945#M52798</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt; wrote:&lt;BR /&gt;&amp;nbsp;&lt;P&gt;&lt;SPAN&gt;It is not unexpected behavior that the internal MAC address shows up&amp;nbsp;in debugs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers !&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-Kiwi&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;No it wouldn't be expected to see that MAC show up on anything that you have access to without root access, which you wouldn't have access to unless you were running some very old early releases of PANos where this password sometimes got out into the wild.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The MAC that you recieve should be the MAC Address that you can view right on the GUI in your interfaces tab, the internal firewall MAC shouldn't come up on anything.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 13:18:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/162945#M52798</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-23T13:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: Pinning Palo sub-interface reply goes to  00:70:76:69:66:00 as a destination MAC.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/162972#M52809</link>
      <description>&lt;P&gt;Thanks all. Still looking into this&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 15:19:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/162972#M52809</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-23T15:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: Pinning Palo sub-interface reply goes to  00:70:76:69:66:00 as a destination MAC.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/167919#M53577</link>
      <description>&lt;P&gt;Hi Folks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I stumbled upon this article, as while analysing a PCAP for a download issue, I see the next-hop MAC as 00:70:76:69:66:00....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You've mentioned its an internal MAC; in my case we have a service route configured, but the source IP is still that of the managment interface, so I'm guessing I'm seeing it as its the managment interface (and its MAC), passing to the internal MAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The return path in my case (Receive PCAP) I see coming from a Checkpoint appliance &amp;nbsp;to the MAC of the Data-Plane interface used in the service route.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just though I'd share in the hope it helps explain why you might be seeing &lt;SPAN&gt;0:70:76:69:66:00.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alex&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2017 09:00:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/167919#M53577</guid>
      <dc:creator>OneAmongMany</dc:creator>
      <dc:date>2017-07-24T09:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Pinning Palo sub-interface reply goes to  00:70:76:69:66:00 as a destination MAC.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/193385#M57981</link>
      <description>&lt;P&gt;I'm seeing this Mac in a PCAP I did on the firewall receive filter while debugging a IP Frag issue where in the ISAKMP packets are being fragmented while performing certificate auth on the IKE gateway. Its causing the IP Frag option to be hit in the Zone protection setting and the IKE v2 setup to fail. Should I assume this is the expected dst mac since this is hitting the zone protection and being forwarded to an internal MAC to be dropped?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2017 06:43:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/193385#M57981</guid>
      <dc:creator>LCMember4723</dc:creator>
      <dc:date>2017-12-29T06:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: Pinging Palo sub-interface reply goes to  00:70:76:69:66:00 as a destination MAC.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/262223#M74311</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The explanantion makes sense. I ran into the same question regarding this destination MAC Address&amp;nbsp;00:70:76:69:66:00 when I did a packet capture in Firewall Stage. However, when I check the Transmit Stage of the packet capture, I see the correct destination MAC Address.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2019 18:34:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pinging-palo-sub-interface-reply-goes-to-00-70-76-69-66-00-as-a/m-p/262223#M74311</guid>
      <dc:creator>RM7000</dc:creator>
      <dc:date>2019-05-24T18:34:35Z</dc:date>
    </item>
  </channel>
</rss>

