<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Adding additional public IP range in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/adding-additional-public-ip-range/m-p/243892#M69672</link>
    <description>&lt;P&gt;Hi all - I've been having a bit of trouble getting this to work - I've done it on Cisco &amp;amp; Sonicwall boxes before, but this is my first PA 3020.&amp;nbsp; We were just assigned additional public IP addresses by our ISP. The existing block is 206.x.x.x/29 and the new block is 165.x.x.x/29, so they're note contiguous.&amp;nbsp; I went into the Ethernet Interface settings and added the new block to the same port as the existing block but that did not seem to have any effect.&amp;nbsp; Is there another place I need to add this information?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Dec 2018 18:12:23 GMT</pubDate>
    <dc:creator>bwade</dc:creator>
    <dc:date>2018-12-19T18:12:23Z</dc:date>
    <item>
      <title>Adding additional public IP range</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-additional-public-ip-range/m-p/243892#M69672</link>
      <description>&lt;P&gt;Hi all - I've been having a bit of trouble getting this to work - I've done it on Cisco &amp;amp; Sonicwall boxes before, but this is my first PA 3020.&amp;nbsp; We were just assigned additional public IP addresses by our ISP. The existing block is 206.x.x.x/29 and the new block is 165.x.x.x/29, so they're note contiguous.&amp;nbsp; I went into the Ethernet Interface settings and added the new block to the same port as the existing block but that did not seem to have any effect.&amp;nbsp; Is there another place I need to add this information?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Dec 2018 18:12:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-additional-public-ip-range/m-p/243892#M69672</guid>
      <dc:creator>bwade</dc:creator>
      <dc:date>2018-12-19T18:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: Adding additional public IP range</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-additional-public-ip-range/m-p/243997#M69681</link>
      <description>&lt;P&gt;Have you added in routing on your virtual router to the next hop?&lt;/P&gt;&lt;P&gt;Have you created any NAT Rules to actualy use the IP's?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 11:05:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-additional-public-ip-range/m-p/243997#M69681</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-12-20T11:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: Adding additional public IP range</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-additional-public-ip-range/m-p/244031#M69687</link>
      <description>&lt;P&gt;The existing IP range is not represented at all inthe virtual router settings (I did not set up this PA, so I can't speak to the whys of the existing config). I tried adding it anyway, but commit failed - I believe the error was that the route was not unique.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I copied the NAT rule for the original IP range and modified it to represent the additional range and also created a 1:1 translation rule for an IP in the new range.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This process just seems much more difficult than it is on other platforms.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 14:24:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-additional-public-ip-range/m-p/244031#M69687</guid>
      <dc:creator>bwade</dc:creator>
      <dc:date>2018-12-20T14:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: Adding additional public IP range</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-additional-public-ip-range/m-p/244170#M69704</link>
      <description>&lt;P&gt;So you're adding a new IP block to your environment, not replacing your existing subnet, correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is an order of operations that the PA does when it receives traffic. One of the things that happens is the evaluation of a route to the destination. If this route doesn't exist, then the packet is dropped. So if you don't have a specific entry in your VR or an interface in that IP range, then the traffic will be dropped.&lt;/P&gt;&lt;P&gt;There are a couple of ways to get around this. In the past, I've created a route to the other subnet with a next-hop of none. I believe you have to also specify an interface in the route.&amp;nbsp; This gets the new subnet into the routing table so the packet can pass to the next evaluation stage. You could also create a loopback on this subnet. You don't need to add another IP address on the ISP facing interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What NAT rule did you copy from old to new? What's the reason for doing this?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 21:21:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-additional-public-ip-range/m-p/244170#M69704</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-12-20T21:21:53Z</dc:date>
    </item>
  </channel>
</rss>

