<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PA220 routing issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa220-routing-issue/m-p/224673#M64487</link>
    <description>&lt;P&gt;I have three PA220s, let's call them&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA220-A&lt;/P&gt;&lt;P&gt;PA220-B&lt;/P&gt;&lt;P&gt;PA220-C&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They are connected in the following manner:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA220-A ---- PA220-B ----- PA220-C&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All three have an Inside and Outside Interface. All the Outside interfaces are connected via a Layer2 network. My IP addressing, let's say it's the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA220-A - Outisde - 172.16.10.1&lt;/P&gt;&lt;P&gt;PA220-A - Inside 192.168.0.0/24 (192.168.0.1/24)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA220-B - Outside - 172.16.10.2&lt;/P&gt;&lt;P&gt;PA220-B - Inside - 192.168.1.0/24 (192.168.1.1/24)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA220-C - Outside - 192.168.1.0/24 (192.168.1.2/24)&lt;/P&gt;&lt;P&gt;PA220-C - Inside - 192.168.2.0/24 (192.168.2.1/24)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I'm pinging from the outside interface of PA220-C, I can traverse the entire network into PA220-A, and vice versa. But when I try to ping from PA220-C inside network, I get a timeout. But I can ping between the Inside and Outside interface of PA220-C. I belive it's a routing issue, but I'm banging my head against the wall trying to figure this one out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;If anyone has any suggestions on areas to look at, that would be helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's also noted that I have deleted all firewall rules on all three PA220, just to test connectivity first. I have also changed the default rules to allow all traffic regardless.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Aug 2018 00:30:34 GMT</pubDate>
    <dc:creator>VinceChan</dc:creator>
    <dc:date>2018-08-03T00:30:34Z</dc:date>
    <item>
      <title>PA220 routing issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa220-routing-issue/m-p/224673#M64487</link>
      <description>&lt;P&gt;I have three PA220s, let's call them&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA220-A&lt;/P&gt;&lt;P&gt;PA220-B&lt;/P&gt;&lt;P&gt;PA220-C&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They are connected in the following manner:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA220-A ---- PA220-B ----- PA220-C&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All three have an Inside and Outside Interface. All the Outside interfaces are connected via a Layer2 network. My IP addressing, let's say it's the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA220-A - Outisde - 172.16.10.1&lt;/P&gt;&lt;P&gt;PA220-A - Inside 192.168.0.0/24 (192.168.0.1/24)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA220-B - Outside - 172.16.10.2&lt;/P&gt;&lt;P&gt;PA220-B - Inside - 192.168.1.0/24 (192.168.1.1/24)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA220-C - Outside - 192.168.1.0/24 (192.168.1.2/24)&lt;/P&gt;&lt;P&gt;PA220-C - Inside - 192.168.2.0/24 (192.168.2.1/24)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I'm pinging from the outside interface of PA220-C, I can traverse the entire network into PA220-A, and vice versa. But when I try to ping from PA220-C inside network, I get a timeout. But I can ping between the Inside and Outside interface of PA220-C. I belive it's a routing issue, but I'm banging my head against the wall trying to figure this one out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;If anyone has any suggestions on areas to look at, that would be helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's also noted that I have deleted all firewall rules on all three PA220, just to test connectivity first. I have also changed the default rules to allow all traffic regardless.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 00:30:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa220-routing-issue/m-p/224673#M64487</guid>
      <dc:creator>VinceChan</dc:creator>
      <dc:date>2018-08-03T00:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: PA220 routing issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa220-routing-issue/m-p/224747#M64503</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Make sure you are allowing ping via the management profile for hte interfce and allowing ping via the policies. The traffic logs should tell you where they are getting blocked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 15:33:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa220-routing-issue/m-p/224747#M64503</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-08-03T15:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: PA220 routing issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa220-routing-issue/m-p/226734#M65279</link>
      <description>&lt;P&gt;After stepping away from the issue for a day, I was able to to logically map out my issue. The problem was I didn't have a route back from PA220-B to PA220-C. I had routes that would get me to PA220-A and PA220-B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 15:31:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa220-routing-issue/m-p/226734#M65279</guid>
      <dc:creator>VinceChan</dc:creator>
      <dc:date>2018-08-10T15:31:13Z</dc:date>
    </item>
  </channel>
</rss>

