<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Rules for BFD, OSPF , DHCP and DHCP relay in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policy-rules-for-bfd-ospf-dhcp-and-dhcp-relay/m-p/203304#M59909</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'll do my best here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So do I have to setup policy rules to allow OSPF, I have OSPF on the PA . But when i don't have the rules in place OSPF fails, when i have them it doesn't log anything&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have logging enabled on the policy?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 547px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14096i6F23E374B8DC7382/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DHCP, do I need it if the PA is running DHCP. what is the source and destination ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are using the builtin 'Intrazone' policy, then no. If you are like some and have a DENY ALL policy above those predefined policies, then possibly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DHCP-relay, source is the input zone and the destination is the dhcp server I am relaying to.&amp;nbsp; But it looks like I have to have 2 polies 1 for request and 1 for replies&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Correct, this is how DHCP works since its not a tcp conection and the traffic gets generated both ways. ie the Clients send traffic to request and IP, the DHCP server then sends traffic with the IP info. This should not be required if the client and server are in the same zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
    <pubDate>Fri, 02 Mar 2018 16:36:23 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-03-02T16:36:23Z</dc:date>
    <item>
      <title>Policy Rules for BFD, OSPF , DHCP and DHCP relay</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-rules-for-bfd-ospf-dhcp-and-dhcp-relay/m-p/203203#M59884</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So do I have to setup policy rules to allow OSPF, I have OSPF on the PA . But when i don't have the rules in place OSPF fails, when i have them it doesn't log anything&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DHCP, do I need it if the PA is running DHCP. what is the source and destination ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DHCP-relay, source is the input zone and the destination is the dhcp server I am relaying to.&amp;nbsp; But it looks like I have to have 2 polies 1 for request and 1 for replies&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BGP, is it the same i policy rules in place even if its that PA ?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 05:46:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-rules-for-bfd-ospf-dhcp-and-dhcp-relay/m-p/203203#M59884</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2018-03-02T05:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Rules for BFD, OSPF , DHCP and DHCP relay</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-rules-for-bfd-ospf-dhcp-and-dhcp-relay/m-p/203304#M59909</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'll do my best here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So do I have to setup policy rules to allow OSPF, I have OSPF on the PA . But when i don't have the rules in place OSPF fails, when i have them it doesn't log anything&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have logging enabled on the policy?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 547px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14096i6F23E374B8DC7382/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DHCP, do I need it if the PA is running DHCP. what is the source and destination ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are using the builtin 'Intrazone' policy, then no. If you are like some and have a DENY ALL policy above those predefined policies, then possibly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DHCP-relay, source is the input zone and the destination is the dhcp server I am relaying to.&amp;nbsp; But it looks like I have to have 2 polies 1 for request and 1 for replies&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Correct, this is how DHCP works since its not a tcp conection and the traffic gets generated both ways. ie the Clients send traffic to request and IP, the DHCP server then sends traffic with the IP info. This should not be required if the client and server are in the same zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 16:36:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-rules-for-bfd-ospf-dhcp-and-dhcp-relay/m-p/203304#M59909</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-02T16:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Rules for BFD, OSPF , DHCP and DHCP relay</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-rules-for-bfd-ospf-dhcp-and-dhcp-relay/m-p/203383#M59921</link>
      <description>&lt;P&gt;Yep I have my own intrazone drop rule&lt;/P&gt;&lt;P&gt;Yes I have logging on OSPF policy start and end&lt;/P&gt;&lt;P&gt;I don't see anything nor in monitor session&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;dhcp/dhcprelay .... so my issue with this is ... it supposed to be a new firewall with smarts. it should be expecting a reply..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I know on my old cisco's once for example once I turned on snmp service i didn't need to allow access via acl it just worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 03 Mar 2018 01:51:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-rules-for-bfd-ospf-dhcp-and-dhcp-relay/m-p/203383#M59921</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2018-03-03T01:51:06Z</dc:date>
    </item>
  </channel>
</rss>

