<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Basic GP routing/NAT/policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/basic-gp-routing-nat-policy/m-p/257662#M73101</link>
    <description>&lt;P&gt;Buh.. it was a sec policy.. even though I had an implicit deny log start and end.&amp;nbsp; I never saw the traffic in monitor.&lt;/P&gt;&lt;P&gt;But adding a sec pol worked.. Go figure..&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Apr 2019 02:09:47 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2019-04-16T02:09:47Z</dc:date>
    <item>
      <title>Basic GP routing/NAT/policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/basic-gp-routing-nat-policy/m-p/257594#M73080</link>
      <description>&lt;P&gt;The Gateway/Portal of my setup works fine.&lt;/P&gt;&lt;P&gt;It's routing I think that's not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just want a client over GP to hit local networks off the PANOS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;IP Pool and access routes that been defined, work just fine .. I can see client has been bestowed these when it connects..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's the basic setup from a routing perspective ?&lt;/P&gt;&lt;P&gt;- I set up a tunnel.## interface, and default vr, and assign the GP gateway to it&lt;/P&gt;&lt;P&gt;- I add the tunnel.## to zone of 'untrust'&lt;/P&gt;&lt;P&gt;- I add a static route under vr's (even though I read an article that routes are automatically added for this ?&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CluKCAS" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CluKCAS&lt;/A&gt;) where the IP pool assigned in the Client Config of Gateway is pointed to tunnel.##.. no next hop IP defined.&lt;/P&gt;&lt;P&gt;- NAT perhaps is my issue ? I need an exempt ?&amp;nbsp; Where source zone is trust and destination zone is untrust and destination interface is tunnel.## ?&amp;nbsp; I did this.. still no go..&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2019 08:49:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/basic-gp-routing-nat-policy/m-p/257594#M73080</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2019-04-15T08:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: Basic GP routing/NAT/policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/basic-gp-routing-nat-policy/m-p/257606#M73082</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;@Retired Member&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I just want a client over GP to hit local networks off the PANOS.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Did you configure routes in your internal network that route the GP IP pool to the firewall? When you try ro reach something in your internal network what does the log show you - are there sessions with 0 byter received?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(I don't know if this does cause any problems but the static route that you configured for the IP pool with the tunnel interface as destination I would remove as it is really not necessary)&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2019 12:59:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/basic-gp-routing-nat-policy/m-p/257606#M73082</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-04-15T12:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Basic GP routing/NAT/policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/basic-gp-routing-nat-policy/m-p/257660#M73099</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see nothing in 'Monitor' -&amp;gt; 'Traffic'..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But going back to my list of steps.. seems right ?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2019 00:11:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/basic-gp-routing-nat-policy/m-p/257660#M73099</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2019-04-16T00:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: Basic GP routing/NAT/policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/basic-gp-routing-nat-policy/m-p/257661#M73100</link>
      <description>&lt;P&gt;UPDATE.. sourced from inside the networks attached to PANOS.. I can reach the VPN client.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the other way.. sourcing from PANGP client .. I can't get in.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which,&lt;/P&gt;&lt;P&gt;a. means routing is fine&lt;/P&gt;&lt;P&gt;b. I can see in a traceroute from PANGP client I get nothing from next hop of gateway.. and the 'Access Routes' are working/inplace so I should get to the CIDR via the PANGP gateway address assigned..&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2019 01:00:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/basic-gp-routing-nat-policy/m-p/257661#M73100</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2019-04-16T01:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: Basic GP routing/NAT/policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/basic-gp-routing-nat-policy/m-p/257662#M73101</link>
      <description>&lt;P&gt;Buh.. it was a sec policy.. even though I had an implicit deny log start and end.&amp;nbsp; I never saw the traffic in monitor.&lt;/P&gt;&lt;P&gt;But adding a sec pol worked.. Go figure..&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2019 02:09:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/basic-gp-routing-nat-policy/m-p/257662#M73101</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2019-04-16T02:09:47Z</dc:date>
    </item>
  </channel>
</rss>

