<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/256093#M72645</link>
    <description>&lt;P&gt;Did the test as you recomended, disabled LACP and did a direct L3 on the Palo Alto to my laptop. No client packets or pings from source 67.107.166.142 made it outbound. Its like the firewall isnt routing or has some setting blocking it from talking.&lt;/P&gt;</description>
    <pubDate>Thu, 04 Apr 2019 15:14:20 GMT</pubDate>
    <dc:creator>lschs-s</dc:creator>
    <dc:date>2019-04-04T15:14:20Z</dc:date>
    <item>
      <title>PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255836#M72560</link>
      <description>&lt;P&gt;I have tried a lot, and at this point I think I just must be missing something obvious that for whatever reason wont come to mind. From the PA3050 I can not ping outbound from the public IP. When I run captures, all outbound traffic is in dropped stage. There is no network functionality at all, and I am unable to find the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Security Config" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19374i8F6E6F2F10759635/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="tmp.PNG" alt="Security Config" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Security Config&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT Config" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19373i3622395C0F940933/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="tmp2.PNG" alt="NAT Config" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;NAT Config&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 02:57:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255836#M72560</guid>
      <dc:creator>lschs-s</dc:creator>
      <dc:date>2019-04-03T02:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255900#M72575</link>
      <description>&lt;P&gt;Assuming that your public IP is 1.2.3.4&lt;/P&gt;&lt;P&gt;If you want to ping Google DNS then command would be:&lt;/P&gt;&lt;P&gt;&amp;gt; ping source 1.2.3.4 host 8.8.8.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you don't have External zone to External zone rule this traffic will match intrazone-default policy.&lt;/P&gt;&lt;P&gt;By default those policies don't log.&lt;/P&gt;&lt;P&gt;Click on intrazone-default and then override at the bottom.&lt;/P&gt;&lt;P&gt;Open intrazone-default policy and check "Log at Session End" on Actions tab to gain visibility.&lt;/P&gt;&lt;P&gt;Do the same with interzone-default.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you now see blocked sessions in Traffic log?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 14:24:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255900#M72575</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-04-03T14:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255957#M72599</link>
      <description>&lt;P&gt;I am aware of how to ping, but its just not working. I enabled logging oneven more of the security policies and saw what I have seen before in the traffic tab. Connections seem to never complete and they always age out and application is left incomplete. I am unsure of where to go from here as this issue has left me quite confused. Whether it is an issue with NAT, Security, or some other rule, I need some help sorting this out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: Removed network's public IP and replaced it with a red square.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="private.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19388iEB8D94F84ABA648D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="private.png" alt="private.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 18:22:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255957#M72599</guid>
      <dc:creator>lschs-s</dc:creator>
      <dc:date>2019-04-03T18:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255963#M72602</link>
      <description>&lt;P&gt;Last screenshot shows only sessions from internet towards your public IP.&lt;/P&gt;&lt;P&gt;No log of you initiating sessions from inside to internet or ping from firewall public ip to internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also none of those incoming sessions match to your NAT policies.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 18:20:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255963#M72602</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-04-03T18:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255966#M72603</link>
      <description>&lt;P&gt;They dont match mine, but they match intrazone which should let them through, right? Or due to intrazone being intra would it block it from finishing session with the external host? Also sorry, but the results are the same internally as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-04-03 at 2.24.52 PM.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19389iDAFD48F38EB344A9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-04-03 at 2.24.52 PM.png" alt="Screen Shot 2019-04-03 at 2.24.52 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 18:26:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255966#M72603</guid>
      <dc:creator>lschs-s</dc:creator>
      <dc:date>2019-04-03T18:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255967#M72604</link>
      <description>&lt;P&gt;Can you add "packets sent" and "packets received" columns to the view?&lt;/P&gt;&lt;P&gt;Ping and DNS can be identified from first packet that is sent to client to server so from screenshot it is unclear if you receive any traffic back.&lt;/P&gt;&lt;P&gt;Also add "NAT Source IP" and verify if SNAT is applied to outgoing traffic and that you see your public IP in this column.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 18:34:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255967#M72604</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-04-03T18:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255970#M72606</link>
      <description>&lt;P&gt;Src Internal&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-04-03 at 3.32.37 PM.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19391iB63B573710A7A3DD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-04-03 at 3.32.37 PM.png" alt="Screen Shot 2019-04-03 at 3.32.37 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Src External&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-04-03 at 2.47.54 PM.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19390i92EAE5D40D81F0EF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-04-03 at 2.47.54 PM.png" alt="Screen Shot 2019-04-03 at 2.47.54 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 19:34:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255970#M72606</guid>
      <dc:creator>lschs-s</dc:creator>
      <dc:date>2019-04-03T19:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255974#M72608</link>
      <description>&lt;P&gt;Weird. SNAT is applied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: Do you have correct Next Hop IP in virtual router? Can you ping next hop from fw external IP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you click on magnifying glass or add egress interface column to verify that traffic is sent towards correct interface?&lt;/P&gt;&lt;P&gt;Under Network &amp;gt; Zones check how if only one outside interface is in External-Zone zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In cli add filter:&lt;/P&gt;&lt;P&gt;&amp;gt; debug dataplane packet-diag set filter off&lt;BR /&gt;&amp;gt; debug dataplane packet-diag clear filter all&lt;/P&gt;&lt;P&gt;&amp;gt; debug dataplane packet-diag set filter match source 8.8.8.8&lt;/P&gt;&lt;P&gt;&amp;gt; debug dataplane packet-diag set filter match destination 8.8.8.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Run following command few times and check if severity is drop anywhere.&lt;/P&gt;&lt;P&gt;It will show what happened to traffic to and from 8.8.8.8 between periods you ran the command (filter delta yes)&lt;/P&gt;&lt;P&gt;&amp;gt; show counter global filter delta yes packet-filter yes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Clean up filter&lt;/P&gt;&lt;P&gt;&amp;gt; debug dataplane packet-diag set filter off&lt;BR /&gt;&amp;gt; debug dataplane packet-diag clear filter all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Last step would be to go with flow basic&lt;/P&gt;&lt;P&gt;&lt;A title="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClS9CAK" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClS9CAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClS9CAK&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 20:14:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255974#M72608</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-04-03T20:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255975#M72609</link>
      <description>&lt;P&gt;Ill hold off on the CLI commands just so I can confirm with you, next hop is &lt;STRONG&gt;not&lt;/STRONG&gt; reachable from the palo alto even when running "ping source &amp;lt;pub ip on extern zone&amp;gt; host &amp;lt;next hop ip&amp;gt;"&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 20:34:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255975#M72609</guid>
      <dc:creator>lschs-s</dc:creator>
      <dc:date>2019-04-03T20:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255976#M72610</link>
      <description>&lt;P&gt;&amp;gt; ping source &amp;lt;external ip&amp;gt; host &amp;lt;next hop&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;gt; show arp ethernet1/1 (assuming 1/1 is your external interface).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Next hop might have ping disabled but IP to mac resolution should still work.&lt;/P&gt;&lt;P&gt;If mac is not there then ask what is correct next hop from your ISP.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 20:37:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255976#M72610</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-04-03T20:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255978#M72611</link>
      <description>&lt;P&gt;Also, yes, egress is correct.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 20:40:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255978#M72611</guid>
      <dc:creator>lschs-s</dc:creator>
      <dc:date>2019-04-03T20:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255980#M72613</link>
      <description>&lt;P&gt;Ping is not disabled, and ARP is incomplete on resolving. I recall seeing in either recieve or drop packet captures, ARP packets defining what the next hop's MAC was. Also another thing to note is my interface is a eth channel, but this issue was happening before as well.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 20:44:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255980#M72613</guid>
      <dc:creator>lschs-s</dc:creator>
      <dc:date>2019-04-03T20:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255981#M72614</link>
      <description>&lt;P&gt;If you disconnect Palo, connect cable to laptop, configure same IP and default gw IP to laptop can you ping next hop and get connectivity to internet?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 20:50:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255981#M72614</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-04-03T20:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255982#M72615</link>
      <description>&lt;P&gt;So you have more than 1 cable to ISP and you have configured aggregated interface?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 20:53:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255982#M72615</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-04-03T20:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255998#M72618</link>
      <description>&lt;P&gt;In regards to the dual link, in simplest terms, yes. However, in reality we own a /28 range and have a central router for just this range. From that router we have 2 links to a firewall plugged in for production networks, and another 2 links to the palo alto. Both of these firewalls have different public IPs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for the laptop, I will try that tommorow as currently I am out of the office. I have remote access to test other ideas, but as for physcial changes, I can not work on those now.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 21:49:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/255998#M72618</guid>
      <dc:creator>lschs-s</dc:creator>
      <dc:date>2019-04-03T21:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/256005#M72619</link>
      <description>&lt;P&gt;Have you enabled LACP on ae.x interface in Palo?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 22:24:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/256005#M72619</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-04-03T22:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/256009#M72620</link>
      <description>&lt;P&gt;Yes and on both routers both links are active and LACP established the bond. Like I said, the issue was happening before the AE, so I doubt it has any influence on my issues here.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 23:07:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/256009#M72620</guid>
      <dc:creator>lschs-s</dc:creator>
      <dc:date>2019-04-03T23:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/256093#M72645</link>
      <description>&lt;P&gt;Did the test as you recomended, disabled LACP and did a direct L3 on the Palo Alto to my laptop. No client packets or pings from source 67.107.166.142 made it outbound. Its like the firewall isnt routing or has some setting blocking it from talking.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 15:14:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/256093#M72645</guid>
      <dc:creator>lschs-s</dc:creator>
      <dc:date>2019-04-04T15:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/256099#M72647</link>
      <description>&lt;P&gt;debug dataplane packet-diag set filter off&lt;BR /&gt;debug dataplane packet-diag clear filter all&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set filter match source 67.107.166.142&lt;BR /&gt;debug dataplane packet-diag set filter match destination 67.107.166.142&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set filter on&lt;/P&gt;&lt;P&gt;show counter global filter delta yes packet-filter yes&lt;/P&gt;&lt;P&gt;ping source 67.107.166.142 host &amp;lt;ip of your laptop&amp;gt;&lt;/P&gt;&lt;P&gt;show counter global filter delta yes packet-filter yes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now post here output of the last show counter global result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And then to clean up:&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set filter off&lt;BR /&gt;debug dataplane packet-diag clear filter all&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 16:06:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/256099#M72647</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-04-04T16:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: PA3050 cant ping next hop and has dropped all client traffic heading outbound.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/256147#M72666</link>
      <description>&lt;P&gt;Thank you so much for the help, but I fixed it all! It was some issues with subnetting and a few with routing, but worked them all out. I would go in detail, but it was in no way related to nat or security.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 18:29:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3050-cant-ping-next-hop-and-has-dropped-all-client-traffic/m-p/256147#M72666</guid>
      <dc:creator>lschs-s</dc:creator>
      <dc:date>2019-04-04T18:29:01Z</dc:date>
    </item>
  </channel>
</rss>

