<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot ping server but monitor sees the ping traffic as allow in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-ping-server-but-monitor-sees-the-ping-traffic-as-allow/m-p/231585#M66495</link>
    <description>&lt;P&gt;the source and destination subnet of your security policy do not match your source and destination zones&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- policy allow&amp;nbsp;source-address ZONE-ROUTER-A source-address 172.16.1.0/24&amp;nbsp;&amp;nbsp;destination-zone ZONE-ROUTER-B destination-address 192.168.1.100 with any apps and services,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;router A hosts 192.168.1.0/24 and router B hosts 172.16.1.100&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to be able to ping 192.168.1.100 from 10.10.20.2 you will need additional security policy (from zone-router-B to zone-router-A)&lt;/P&gt;
&lt;P&gt;to be able to ping 172.16.1.100 from 10.10.10.1 you will need additonal policy/expand the existing policy as the source subnet is not accounted for in your existing policy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Sep 2018 08:27:27 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2018-09-20T08:27:27Z</dc:date>
    <item>
      <title>Cannot ping server but monitor sees the ping traffic as allow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-ping-server-but-monitor-sees-the-ping-traffic-as-allow/m-p/231322#M66415</link>
      <description>&lt;P&gt;My Palo Alto PA200 e1/1 (10.10.10.1/30) is connected to router A and e1/2 (10.10.20.2/30) is connected to router B.&lt;/P&gt;&lt;P&gt;The server 192.168.1.100/24 is behind router A (10.10.10.2)&amp;nbsp;which has a static router to destination 172.16.1.0/24 with next hop 10.10.10.1.&lt;/P&gt;&lt;P&gt;The user 172.16.1.100/24 is behind router B&amp;nbsp;(10.10.20.1) which has a static router to destination 192.168.1.0/24 with next hop 10.10.20.2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On my PA, I have static routes and policy below:&lt;/P&gt;&lt;P&gt;- destination 172.16.1.0/24 next hop 10.10.20.1 (Router B) via interface e1/2&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- destination 192.168.1.0/24 next hop 10.10.10.2 (Router A) via interface e1/1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- policy allow&amp;nbsp;source-address ZONE-ROUTER-A source-address 172.16.1.0/24&amp;nbsp;&amp;nbsp;destination-zone ZONE-ROUTER-B destination-address 192.168.1.100 with any apps and services,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like I have a routing between the 2 subnets from my PA FW.&lt;/P&gt;&lt;P&gt;My FW can ping 192.168.1.100 sourcing 10.10.10.1 and 172.16.1.100 sourcing 10.10.20.2.&lt;/P&gt;&lt;P&gt;But I cannot ping&amp;nbsp;&lt;SPAN&gt;192.168.1.100 sourcing 10.10.20.2 and 172.16.1.100 sourcing 10.10.10.1. The strange thing is I can see the pings going through from the MONITOR on my PA200 when 172.16.1.100 tries to ping 192.168.1.100. But the ping from the user says failed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any inputs will be greatly appreciated. Thx&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Am I missing a policy?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 21:08:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-ping-server-but-monitor-sees-the-ping-traffic-as-allow/m-p/231322#M66415</guid>
      <dc:creator>jac101</dc:creator>
      <dc:date>2018-09-18T21:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping server but monitor sees the ping traffic as allow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-ping-server-but-monitor-sees-the-ping-traffic-as-allow/m-p/231585#M66495</link>
      <description>&lt;P&gt;the source and destination subnet of your security policy do not match your source and destination zones&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- policy allow&amp;nbsp;source-address ZONE-ROUTER-A source-address 172.16.1.0/24&amp;nbsp;&amp;nbsp;destination-zone ZONE-ROUTER-B destination-address 192.168.1.100 with any apps and services,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;router A hosts 192.168.1.0/24 and router B hosts 172.16.1.100&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to be able to ping 192.168.1.100 from 10.10.20.2 you will need additional security policy (from zone-router-B to zone-router-A)&lt;/P&gt;
&lt;P&gt;to be able to ping 172.16.1.100 from 10.10.10.1 you will need additonal policy/expand the existing policy as the source subnet is not accounted for in your existing policy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 08:27:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-ping-server-but-monitor-sees-the-ping-traffic-as-allow/m-p/231585#M66495</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-09-20T08:27:27Z</dc:date>
    </item>
  </channel>
</rss>

