<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Interface issue - see traffic but no arp entry for gateway in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/interface-issue-see-traffic-but-no-arp-entry-for-gateway/m-p/284856#M76358</link>
    <description>&lt;P&gt;We have an issue with an interface that is talking weirdly.&amp;nbsp; We have changed ports to rule out hardware, and I can work ok with a laptop in the same switchport.&amp;nbsp; The line comes from Verizon's media converter to a switch that is connected to the pair of HA firewalls and an HA pair of load balancers that use different addresses in the subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The interface is assigned a public address from a pool of static addresses.&amp;nbsp; We can see inbound traffic in captures and we can see the interface arp the next hop, but there's no entry in the arp table and outbound traffic goes nowhere.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the line comes from a media converter, Verizon says there's nothing to troubleshoot on their end, the switch shows the port up and normal and like I mentioned, I can plug in my laptop and get in and out without issue.&amp;nbsp; Pulling may hair out, any assistance is appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;</description>
    <pubDate>Fri, 23 Aug 2019 19:35:03 GMT</pubDate>
    <dc:creator>Nathaniel.piper</dc:creator>
    <dc:date>2019-08-23T19:35:03Z</dc:date>
    <item>
      <title>Interface issue - see traffic but no arp entry for gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-issue-see-traffic-but-no-arp-entry-for-gateway/m-p/284856#M76358</link>
      <description>&lt;P&gt;We have an issue with an interface that is talking weirdly.&amp;nbsp; We have changed ports to rule out hardware, and I can work ok with a laptop in the same switchport.&amp;nbsp; The line comes from Verizon's media converter to a switch that is connected to the pair of HA firewalls and an HA pair of load balancers that use different addresses in the subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The interface is assigned a public address from a pool of static addresses.&amp;nbsp; We can see inbound traffic in captures and we can see the interface arp the next hop, but there's no entry in the arp table and outbound traffic goes nowhere.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the line comes from a media converter, Verizon says there's nothing to troubleshoot on their end, the switch shows the port up and normal and like I mentioned, I can plug in my laptop and get in and out without issue.&amp;nbsp; Pulling may hair out, any assistance is appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 19:35:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-issue-see-traffic-but-no-arp-entry-for-gateway/m-p/284856#M76358</guid>
      <dc:creator>Nathaniel.piper</dc:creator>
      <dc:date>2019-08-23T19:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: Interface issue - see traffic but no arp entry for gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-issue-see-traffic-but-no-arp-entry-for-gateway/m-p/284877#M76360</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First, let me laugh/smirk at the comments from the telecos.&amp;nbsp; Always saying "not our problem!".&lt;/P&gt;&lt;P&gt;I have seen this time and again from ISPs, and I tend to engineer my own solution......&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As VZ is not planning to help, the best/fastest suggestion I have is to create a static arp entry for the IP/mac of the gateway.&lt;/P&gt;&lt;P&gt;You can modify the interface on the FW, go to the Advance tab, and enter in the static arp entry.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, your FW has the mac address to be used, and you do not need to pull your hair out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Definitely NOT a PANW FW issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 22:06:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-issue-see-traffic-but-no-arp-entry-for-gateway/m-p/284877#M76360</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-08-23T22:06:03Z</dc:date>
    </item>
  </channel>
</rss>

