<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic internal routing being blocked in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232764#M66776</link>
    <description>&lt;P&gt;I'm having an issues with some internal routing I have two virtual router that have statics routes for an internal phone network on a different router in my trusted zone I can ping from computers in my lan but when i try and access any websites or management tools it doesn't work if I add a persistent route on the desktops it start to work but when i remove it it goes back to acting strange&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Drawing2.png" style="width: 786px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16824iB92353FB30537344/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Drawing2.png" alt="Drawing2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Sep 2018 17:10:26 GMT</pubDate>
    <dc:creator>kclarke6</dc:creator>
    <dc:date>2018-09-27T17:10:26Z</dc:date>
    <item>
      <title>internal routing being blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232764#M66776</link>
      <description>&lt;P&gt;I'm having an issues with some internal routing I have two virtual router that have statics routes for an internal phone network on a different router in my trusted zone I can ping from computers in my lan but when i try and access any websites or management tools it doesn't work if I add a persistent route on the desktops it start to work but when i remove it it goes back to acting strange&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Drawing2.png" style="width: 786px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16824iB92353FB30537344/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Drawing2.png" alt="Drawing2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 17:10:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232764#M66776</guid>
      <dc:creator>kclarke6</dc:creator>
      <dc:date>2018-09-27T17:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: internal routing being blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232829#M66792</link>
      <description>&lt;P&gt;It's sounds like asymetric routing but I'll need some clarification on things. ICMP will work asymmetric but traffic needing a three-way handshake won't. The firewall needs to see the entire flow or it will drop traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you reference the drawing you included to explain what does and doesn't work? I can't tell what's trying to access what.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 21:39:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232829#M66792</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-09-27T21:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: internal routing being blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232830#M66793</link>
      <description>&lt;P&gt;I'm trying to get clients from the 192.168.4.x network to access clients in the 192.168.10.x network but it only work when i add persistent routes to the client in the 192.168.4.x network&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 21:42:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232830#M66793</guid>
      <dc:creator>kclarke6</dc:creator>
      <dc:date>2018-09-27T21:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: internal routing being blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232831#M66794</link>
      <description>&lt;P&gt;So when you add the static route on the clients, you point 192.168.10.0 to 192.168.4.8?&lt;/P&gt;&lt;P&gt;Does the Palo Alto have a route for 192.168.10.0 that points to 192.168.4.8?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 21:48:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232831#M66794</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-09-27T21:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: internal routing being blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232838#M66795</link>
      <description>&lt;P&gt;yes my virtual router has a static route of 192.168.10.0/24 to 192.168.4.8&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 21:51:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232838#M66795</guid>
      <dc:creator>kclarke6</dc:creator>
      <dc:date>2018-09-27T21:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: internal routing being blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232839#M66796</link>
      <description>&lt;P&gt;Then the problem is asymmetry.&lt;/P&gt;&lt;P&gt;Here's an example of traffic flow without the static route on a client:&lt;/P&gt;&lt;P&gt;192.168.4.100 sends a syn to 192.168.10.100. This goes to the PA, which then sends it to the router at 192.168.4.8&lt;/P&gt;&lt;P&gt;192.168.10.100 sends a syn-ack to 192.168.4.100. This goes to the router at 192.168.10.1, which then sends this directly to the client without passing through the PA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;192.168.4.100 sends an ack to 192.168.10.100, which then goes to the PA. The PA did not see the syn-ack so it drops the traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When ICMP works but tcp traffic fails, it's generally asymmetric routing.&lt;/P&gt;&lt;P&gt;By adding&amp;nbsp;the static route, all traffic bypasses the PA so it will work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 22:02:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232839#M66796</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-09-27T22:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: internal routing being blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232840#M66797</link>
      <description>&lt;P&gt;now how would i go about fixing that generally its better to add routes the the default gateways if i'm not mistaken correct? I looked up asymetric routing and it seems that disabling the protection on the firewall is generally not recommended&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 22:10:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232840#M66797</guid>
      <dc:creator>kclarke6</dc:creator>
      <dc:date>2018-09-27T22:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: internal routing being blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232867#M66801</link>
      <description>&lt;P&gt;I would advise against disabling this behavior.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are&amp;nbsp;only a few&amp;nbsp;choices with what you can do.&lt;/P&gt;&lt;P&gt;- Put static routes on every machine on 192.168.4.0&lt;/P&gt;&lt;P&gt;- Make 192.168.4.8 the default gateway for that network, making sure that router has a default route to .1&lt;/P&gt;&lt;P&gt;- Move 192.168.10.0 to a spot where traffic has to cross the firewall to reach it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 23:20:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-routing-being-blocked/m-p/232867#M66801</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-09-27T23:20:30Z</dc:date>
    </item>
  </channel>
</rss>

