<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I've bought 1 more public IP range but cannot use it in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-bought-1-more-public-ip-range-but-cannot-use-it/m-p/207347#M60790</link>
    <description>&lt;P&gt;id you add the IP to your ISP-1 external interface?&lt;/P&gt;
&lt;P&gt;you'll want to do that to ensure NAT and routing are using the appropriate interface to send packets out of and perform proxy arp&lt;/P&gt;</description>
    <pubDate>Mon, 26 Mar 2018 08:52:52 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2018-03-26T08:52:52Z</dc:date>
    <item>
      <title>I've bought 1 more public IP range but cannot use it</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-bought-1-more-public-ip-range-but-cannot-use-it/m-p/207237#M60770</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;I've 2 internet lines connected to 2 different ISP: ISP-1 and ISP-2. Default route to internet is the connection to ISP-2&lt;/P&gt;&lt;P&gt;I just bought 1 more public IP range from ISP-1 that belong to a different subnet with my current ISP-1 public IP range.&lt;/P&gt;&lt;P&gt;Now I want to NAT my server using an IP in the new public IP range, but server cannot connect to internet. I've checked logs and see no problem (NAT is successfull, securitiy rules is allowed).&lt;/P&gt;&lt;P&gt;I've no problem if I NAT using current old public IP range. So is there any configuration I have to do before using the new IP range for NAT?&lt;/P&gt;</description>
      <pubDate>Sun, 25 Mar 2018 02:09:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-bought-1-more-public-ip-range-but-cannot-use-it/m-p/207237#M60770</guid>
      <dc:creator>Hongson</dc:creator>
      <dc:date>2018-03-25T02:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: I've bought 1 more public IP range but cannot use it</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-bought-1-more-public-ip-range-but-cannot-use-it/m-p/207251#M60771</link>
      <description>&lt;P&gt;Do you have only default gateway in your virtual router or have also configured policy based forwarding policies?&lt;/P&gt;</description>
      <pubDate>Sat, 24 Mar 2018 23:17:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-bought-1-more-public-ip-range-but-cannot-use-it/m-p/207251#M60771</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-03-24T23:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: I've bought 1 more public IP range but cannot use it</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-bought-1-more-public-ip-range-but-cannot-use-it/m-p/207253#M60772</link>
      <description>&lt;P&gt;Thank you Raido for your reply.&lt;/P&gt;&lt;P&gt;I use pbf also, because by default traffics from my server go outside via ISP-2 so I created a pbf rule redirect traffic to ISP-1.&lt;/P&gt;&lt;P&gt;I also add an IP in the new IP range to ISP-1 interface.&lt;/P&gt;&lt;P&gt;I've no ploblem when NAT using the old IP range, but when using the new IP range, connection failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Mar 2018 01:46:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-bought-1-more-public-ip-range-but-cannot-use-it/m-p/207253#M60772</guid>
      <dc:creator>Hongson</dc:creator>
      <dc:date>2018-03-25T01:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: I've bought 1 more public IP range but cannot use it</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-bought-1-more-public-ip-range-but-cannot-use-it/m-p/207294#M60778</link>
      <description>&lt;P&gt;If you traceroute and look at the associated session, can you see it egressing on the ISP1 interface, with the SNAT address of your new IP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If so, I think it sounds like the Internet does not have a route back to your new IP. Either your ISP will need to advertise this on your behalf, or you are using BGP. If the latter, have you added the new IP into your export statements for BGP and can you confirm it is being advertised (you can see this from the BGP RIP under network &amp;gt; routers)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Shannon&lt;/P&gt;</description>
      <pubDate>Sun, 25 Mar 2018 20:43:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-bought-1-more-public-ip-range-but-cannot-use-it/m-p/207294#M60778</guid>
      <dc:creator>SARowe_NZ</dc:creator>
      <dc:date>2018-03-25T20:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: I've bought 1 more public IP range but cannot use it</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-bought-1-more-public-ip-range-but-cannot-use-it/m-p/207347#M60790</link>
      <description>&lt;P&gt;id you add the IP to your ISP-1 external interface?&lt;/P&gt;
&lt;P&gt;you'll want to do that to ensure NAT and routing are using the appropriate interface to send packets out of and perform proxy arp&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 08:52:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-bought-1-more-public-ip-range-but-cannot-use-it/m-p/207347#M60790</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-26T08:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: I've bought 1 more public IP range but cannot use it</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-bought-1-more-public-ip-range-but-cannot-use-it/m-p/207592#M60830</link>
      <description>&lt;P&gt;Thank you all for your help,&lt;/P&gt;&lt;P&gt;'Cause the default route is connection to ISP-2 so I've to create a pbf rule redict it to ISP-1. And found out that my pbf rule configuration missed Next hop IP ( I thought that only Egress interface is enough).&lt;/P&gt;&lt;P&gt;Problem has been solved now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2018 05:39:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-bought-1-more-public-ip-range-but-cannot-use-it/m-p/207592#M60830</guid>
      <dc:creator>Hongson</dc:creator>
      <dc:date>2018-03-27T05:39:46Z</dc:date>
    </item>
  </channel>
</rss>

