<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic showing from wrong zone in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211893#M61785</link>
    <description>&lt;P&gt;Thanks for the quick reply rmfalconer!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, the subinterface on the PA has a 172.16.0.251/21 assigned to it. The subinterface is assigned to the DMZ zone.&lt;/P&gt;&lt;P&gt;Mot sure if this matters, but the actual interface itself the subinterfaces belong to is assigned to the trust zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the traffic log, it's hitting a trust zone to untrust zone policy, it shows it's sourcing from the subinterface assigned to the trust zone rather than the DMZ to untrust policy.&lt;/P&gt;</description>
    <pubDate>Thu, 26 Apr 2018 15:21:02 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2018-04-26T15:21:02Z</dc:date>
    <item>
      <title>Traffic showing from wrong zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211884#M61782</link>
      <description>&lt;P&gt;Hello all,&amp;nbsp;I have&amp;nbsp;a (hopefully) simple problem I can't seem to figure out.&lt;/P&gt;&lt;P&gt;I have&amp;nbsp;recently created a new DMZ zone on my PA for guest users, but when a guest tries to access the internet, the traffic is showing as sourcing from the trust zone instead of the DMZ zone. A trace from the guest user makes it to the PA, then dies.&amp;nbsp;I have the policy from DMZ to untrust configured, but it never hits it, it's always using the trust to untrust policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a feeling I am missing something easy...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help will be much appreciated!&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 14:53:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211884#M61782</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-04-26T14:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic showing from wrong zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211892#M61784</link>
      <description>&lt;P&gt;Is the subnet with the guest traffic assigned to an interface on the PA? Is that interface set with the guest zone?&lt;/P&gt;&lt;P&gt;In the traffic log, what rule is it hitting?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 15:09:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211892#M61784</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-04-26T15:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic showing from wrong zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211893#M61785</link>
      <description>&lt;P&gt;Thanks for the quick reply rmfalconer!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, the subinterface on the PA has a 172.16.0.251/21 assigned to it. The subinterface is assigned to the DMZ zone.&lt;/P&gt;&lt;P&gt;Mot sure if this matters, but the actual interface itself the subinterfaces belong to is assigned to the trust zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the traffic log, it's hitting a trust zone to untrust zone policy, it shows it's sourcing from the subinterface assigned to the trust zone rather than the DMZ to untrust policy.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 15:21:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211893#M61785</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-04-26T15:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic showing from wrong zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211894#M61786</link>
      <description>&lt;P&gt;Is the switchport connected to the PA a dot1q tagging interface?&lt;/P&gt;&lt;P&gt;Do you have the tag definition set correctly on the PA subinterface?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 15:25:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211894#M61786</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-04-26T15:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic showing from wrong zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211895#M61787</link>
      <description>&lt;P&gt;what is the ip/mask of the actual interface&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 15:26:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211895#M61787</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-04-26T15:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic showing from wrong zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211896#M61788</link>
      <description>&lt;P&gt;The actual interface doesnt have an IP address assigned, the subinterface for the guest users has an IP of 172.16.0.251/21.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 15:30:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211896#M61788</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-04-26T15:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic showing from wrong zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211914#M61795</link>
      <description>&lt;P&gt;Yep, the switchport is configured and tagged correctly, and the tagging is set on the PA as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From a guest laptop, my trace hits the gateway (172.16.0.250) IP assigned to my gateway router, then the next hop is the 10.x.x.x trust IP on the PA.&lt;/P&gt;&lt;P&gt;From the PA, I can ping my guest laptop sourcing from the DMZ subinterface.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 16:17:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211914#M61795</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-04-26T16:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic showing from wrong zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211917#M61796</link>
      <description>&lt;P&gt;Just trying to get a picture for the traffic flow.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How is the routing set on your gateway? Is there a default that points to the trust interface of the PA?&lt;/P&gt;&lt;P&gt;Is 172.16.0.250 a subinterface on the gateway router or a separate physical interface? Does this interface connect to the same switch where the PA connects?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would the flow look something like this:&lt;/P&gt;&lt;P&gt;Client--[guest vlan]--&amp;gt;Switch1--[dot1q]--&amp;gt;Gateway--[dot1q]--&amp;gt;Switch1--[dot1q]--&amp;gt;PA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 16:31:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211917#M61796</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-04-26T16:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic showing from wrong zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211918#M61797</link>
      <description>&lt;P&gt;You are right, I have a layer 3 Brocade switch as my gateway router, it's default route is pointing to the trust subinterface on the PA.&lt;/P&gt;&lt;P&gt;The 172.16.0.250 is the IP of the VE on the gateway router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your flow looks correct, so the guest&amp;nbsp;laptop on vlan 172, hits the ve172 on the gateway router, then takes the default route to the PA.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 16:42:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211918#M61797</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-04-26T16:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic showing from wrong zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211923#M61798</link>
      <description>&lt;P&gt;Once the traffic hits that L3 boundary and routes with the default, it will lose the vlan tagging info so it won't get to the correct subinterface on the PA.&lt;/P&gt;&lt;P&gt;I think the easiest solution to this is to move the gateway for the guest vlan off the router and&amp;nbsp;onto the PA. The PA can provide DHCP so the guest network would be self-contained, with the PA controlling all access.&lt;/P&gt;&lt;P&gt;Another option that might work is to move the guest vlan to a separate vrf on the router and control the next hop through the separate routing table.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 17:00:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/211923#M61798</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-04-26T17:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic showing from wrong zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/212015#M61818</link>
      <description>&lt;P&gt;Thanks for the info rmfalconer! I moved the gateway up to the PA and all is working well now.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 12:22:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-showing-from-wrong-zone/m-p/212015#M61818</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-04-27T12:22:45Z</dc:date>
    </item>
  </channel>
</rss>

