<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I enable ping to a non-mgmt IP address? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-enable-ping-to-a-non-mgmt-ip-address/m-p/10054#M7359</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Security Rule ::&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Source Zone [Untrust IP]&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Destination Zone [Trust]&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Source IP [any]&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Destination IP&amp;nbsp; [Untrust IP - Original destination Ip/Non_translated IP]&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Application [ping]&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Action [Allow]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;N.B:Please make sure this specific rule is above other generic rules with context -Source Zone[Trust]&amp;nbsp; -Destination Zone [Trust].&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Refer ::&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;https://live.paloaltonetworks.com/docs/DOC-1517&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Jun 2012 15:39:48 GMT</pubDate>
    <dc:creator>UhMayYeah</dc:creator>
    <dc:date>2012-06-06T15:39:48Z</dc:date>
    <item>
      <title>How do I enable ping to a non-mgmt IP address?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-enable-ping-to-a-non-mgmt-ip-address/m-p/10049#M7354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to enable ping to an external address that is not assigned to an interface? Is this possible? This address is used for NAT'ing purposes or to access an internal server.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I've done the following but I'm still not able to ping the address/server:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. allow application ping from internet to my external ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing anything?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jun 2012 22:16:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-enable-ping-to-a-non-mgmt-ip-address/m-p/10049#M7354</guid>
      <dc:creator>x</dc:creator>
      <dc:date>2012-06-04T22:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable ping to a non-mgmt IP address?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-enable-ping-to-a-non-mgmt-ip-address/m-p/10050#M7355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have setup DNAT then enabling ping towards the (in your case) server should be the same way as when you enable other types of traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want a physical interface of your PA box to reply to ping you need to setup a management profile where you only select "ping" and then attach this profile to that particular physical interface. Im not sure if you need a security rule aswell or not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jun 2012 07:57:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-enable-ping-to-a-non-mgmt-ip-address/m-p/10050#M7355</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-06-05T07:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable ping to a non-mgmt IP address?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-enable-ping-to-a-non-mgmt-ip-address/m-p/10051#M7356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To add to mikand, this traffic needs intra-zone security rule typically Untrust-to-Untrust which is permitted by the firewall by default,unless we have a any-any deny-all rule configured.&lt;/P&gt;&lt;P&gt;Interface will proxy-arp for all the addresses lying in it's subnet.So adding an interface-management profile allowing ping service should take care of things .&lt;/P&gt;&lt;P&gt;Please refer&amp;nbsp; :&lt;SPAN style="font-size:11.0pt;font-family:&amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-ascii-theme-font:minor-latin;mso-fareast-font-family:Calibri;mso-fareast-theme-font: minor-latin;mso-hansi-theme-font:minor-latin;mso-bidi-font-family:&amp;amp;quot;Times New Roman&amp;amp;quot;; mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language: EN-US;mso-bidi-language:AR-SA"&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2998#cf"&gt;https://live.paloaltonetworks.com/docs/DOC-2998#cf&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jun 2012 18:34:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-enable-ping-to-a-non-mgmt-ip-address/m-p/10051#M7356</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2012-06-05T18:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable ping to a non-mgmt IP address?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-enable-ping-to-a-non-mgmt-ip-address/m-p/10052#M7357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys. Let me try these out and get back to you with results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate the help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jun 2012 18:38:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-enable-ping-to-a-non-mgmt-ip-address/m-p/10052#M7357</guid>
      <dc:creator>x</dc:creator>
      <dc:date>2012-06-05T18:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable ping to a non-mgmt IP address?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-enable-ping-to-a-non-mgmt-ip-address/m-p/10053#M7358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys, it seems like it is working. Thank you for that. The only concern that I have is I'd have to have a NAT rule that has the service any for this to work. How do I further restrict this so that only ping is allowed on the NAT rule? Is this possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NAT Rule looks like this:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Source [Untrust IP]&lt;/P&gt;&lt;P&gt;Destination [Untrust IP]&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Service [Any]&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Translated Address: [Internal Server IP]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Security Rule looks like this:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Source [Untrust IP]&lt;/P&gt;&lt;P&gt;Destination [Untrust IP]&lt;/P&gt;&lt;P&gt;Application [ping]&lt;/P&gt;&lt;P&gt;Action [Allow]&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2012 14:52:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-enable-ping-to-a-non-mgmt-ip-address/m-p/10053#M7358</guid>
      <dc:creator>x</dc:creator>
      <dc:date>2012-06-06T14:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable ping to a non-mgmt IP address?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-enable-ping-to-a-non-mgmt-ip-address/m-p/10054#M7359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Security Rule ::&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Source Zone [Untrust IP]&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Destination Zone [Trust]&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Source IP [any]&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Destination IP&amp;nbsp; [Untrust IP - Original destination Ip/Non_translated IP]&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Application [ping]&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Action [Allow]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;N.B:Please make sure this specific rule is above other generic rules with context -Source Zone[Trust]&amp;nbsp; -Destination Zone [Trust].&lt;/P&gt;&lt;P style="color:#000000;font-family:Arial, Helvetica, sans-serif;font-size:12px;background-color:#ffffff"&gt;Refer ::&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;https://live.paloaltonetworks.com/docs/DOC-1517&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2012 15:39:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-enable-ping-to-a-non-mgmt-ip-address/m-p/10054#M7359</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2012-06-06T15:39:48Z</dc:date>
    </item>
  </channel>
</rss>

