<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Path Monitor... source IP must be within the same subnet as destination? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/path-monitor-source-ip-must-be-within-the-same-subnet-as/m-p/294479#M77689</link>
    <description>&lt;P&gt;The interesting thing about that graphic... which seems to reflect exactly what I want to do.... is that the Eth ports of the firewall don't disclose the mask, and the destinations being monitored are all within a class C.&amp;nbsp; 192.0.2.xx&amp;nbsp; So I can't say that others i the LIVEcommunity are incorrect when they've written that they must be in a single subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My reality is that when I try to enter a SOURCE IP in the dialog box, it only accepts two things:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The DHCP option in the Dropdown,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; OR create a NEW X VARIABLE&lt;BR /&gt;I could create multiple VARIABLES all pointing to a single loopback as a source... but that seems like one wrong on top of another wrong. It would not let me create one VARIABLE with the FWs loopback and re-use that in multiple monitors. It refused to allow me to use the same variable twice.&amp;nbsp; (Frankly, I've never used variables, so my understanding there is weak.)&lt;BR /&gt;&lt;BR /&gt;The documentation for removing static routes with Path Monitoring says enter an IP or name an Interface.&amp;nbsp; It won't accept any IPs or any interfaces. Even an IP within the Route isn't accepted.&amp;nbsp; Destination IP I can put any IP. 1.1.1.1 or 20.200.200.200 doesn't matter what it is. But source I can't get it to accept anything that makes sense.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Oct 2019 18:18:55 GMT</pubDate>
    <dc:creator>Royalfr</dc:creator>
    <dc:date>2019-10-25T18:18:55Z</dc:date>
    <item>
      <title>Path Monitor... source IP must be within the same subnet as destination?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/path-monitor-source-ip-must-be-within-the-same-subnet-as/m-p/294390#M77678</link>
      <description>&lt;P&gt;I'm trying to monitor the availability of one tunnel, to re-route the same destination traffic into a second tunnel. The other side can't do routing protocols right now--which would solve this easily.&amp;nbsp; I hoped to find a non-manual way to fail over.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read in a discussion that the SOURCE IP and destination IP have to be in a single network. The documentation didn't mention this.&amp;nbsp; If that is true, essentially this is designed to test a basic /30 circuit or a "can I see my default gateway?" test.&amp;nbsp; And really nothing more.&amp;nbsp; Calling a zero-hop distance (same broadcast domain) a "path" monitor is stretching the word path. Routing Gateway Monitor is more appropriate.&amp;nbsp; Also the documentation (copied below) says you can have eight destinations.&amp;nbsp; Having that many without being able to go beyond the gateway... really limits this to ... testing my two ISPs, or three ISPs and there are so many other ways that gets accomplished in the real world.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously none of the REMOTE IPs of a typical VPN between corporations are going to be in the same local subnet as any IP I can assign to my firewall. Cisco's DMVPN is structured to simulate a subnet between all the ipsec endpoints.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;So I'm not sure if there is anything in the PA's features that would let me manipulate routes without a routing protocol.&amp;nbsp; I have a second route with a lower admin cost.&amp;nbsp; But it doesn't work like Cisco where a route pointed to an interface(the tunnel) becomes invalid when the interface is down.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;&lt;FONT color="#800000"&gt;Add&amp;nbsp;&lt;SPAN&gt;a monitored destination by&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Name.&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/DIV&gt;&lt;FONT color="#800000"&gt;You can add up to eight monitored destinations per static route.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;FONT color="#800000"&gt;For&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Source IP&lt;/SPAN&gt;, select the IP address that the firewall uses in the ICMP ping to the monitored destination:&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV class="itemgroup info"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;&lt;FONT color="#800000"&gt;If you select an interface, the firewall uses the first IP address assigned to the interface by default.&amp;nbsp;If the interface has multiple IP addresses, select one. &amp;nbsp;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT color="#800000"&gt;If you select&lt;SPAN&gt;&amp;nbsp;D&lt;/SPAN&gt;&lt;SPAN&gt;HCP (Use DHCP Client address)&lt;/SPAN&gt;, the firewall uses the address that DHCP assigned to the interface.&lt;SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;DIV class="itemgroup info"&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 25 Oct 2019 13:50:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/path-monitor-source-ip-must-be-within-the-same-subnet-as/m-p/294390#M77678</guid>
      <dc:creator>Royalfr</dc:creator>
      <dc:date>2019-10-25T13:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Path Monitor... source IP must be within the same subnet as destination?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/path-monitor-source-ip-must-be-within-the-same-subnet-as/m-p/294435#M77684</link>
      <description>&lt;P&gt;Looking at the Admin guide, it talks about Static Route Removal using Path Monitoring, and the IP address does not appear to be in the same network.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/static-routes/static-route-removal-based-on-path-monitoring.html#id8e1a8449-a208-4631-b3d3-34457d03f8cb" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/static-routes/static-route-removal-based-on-path-monitoring.html#id8e1a8449-a208-4631-b3d3-34457d03f8cb&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternatively, if you monitor the tunnel IP,&amp;nbsp; then that IP can be whatever you want it to be.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 16:39:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/path-monitor-source-ip-must-be-within-the-same-subnet-as/m-p/294435#M77684</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2019-10-25T16:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: Path Monitor... source IP must be within the same subnet as destination?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/path-monitor-source-ip-must-be-within-the-same-subnet-as/m-p/294479#M77689</link>
      <description>&lt;P&gt;The interesting thing about that graphic... which seems to reflect exactly what I want to do.... is that the Eth ports of the firewall don't disclose the mask, and the destinations being monitored are all within a class C.&amp;nbsp; 192.0.2.xx&amp;nbsp; So I can't say that others i the LIVEcommunity are incorrect when they've written that they must be in a single subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My reality is that when I try to enter a SOURCE IP in the dialog box, it only accepts two things:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The DHCP option in the Dropdown,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; OR create a NEW X VARIABLE&lt;BR /&gt;I could create multiple VARIABLES all pointing to a single loopback as a source... but that seems like one wrong on top of another wrong. It would not let me create one VARIABLE with the FWs loopback and re-use that in multiple monitors. It refused to allow me to use the same variable twice.&amp;nbsp; (Frankly, I've never used variables, so my understanding there is weak.)&lt;BR /&gt;&lt;BR /&gt;The documentation for removing static routes with Path Monitoring says enter an IP or name an Interface.&amp;nbsp; It won't accept any IPs or any interfaces. Even an IP within the Route isn't accepted.&amp;nbsp; Destination IP I can put any IP. 1.1.1.1 or 20.200.200.200 doesn't matter what it is. But source I can't get it to accept anything that makes sense.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 18:18:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/path-monitor-source-ip-must-be-within-the-same-subnet-as/m-p/294479#M77689</guid>
      <dc:creator>Royalfr</dc:creator>
      <dc:date>2019-10-25T18:18:55Z</dc:date>
    </item>
  </channel>
</rss>

