<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Routing driving me crazy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/routing-driving-me-crazy/m-p/305129#M79286</link>
    <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here's a weird issue!&lt;/P&gt;&lt;P&gt;We have one public IP lets say 1.2.3.4.&lt;/P&gt;&lt;P&gt;Our PA VM 300, can ping to any public IP address other than 1.2.3.4.&lt;/P&gt;&lt;P&gt;For all other public IP addresses, it sends traffic via default route out of external interface. But for 1.2.3.4, it sends the traffic to our management gateway. Following to be noted:&lt;/P&gt;&lt;P&gt;1. 1.2.3.4 is our other PA firewall external IP where we were trying to connect using IPSec S2S tunnel. I deleted all the tunnel config since I was afraid that it was somehow interfering with the routing. But that did not solve the problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. From all other devices we can ping 1.2.3.4 and ping is allowed on this interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Security Policies, NAT and static default route pointing out from external interface to next hop are all correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4. We can ping other public IP addresses like 8.8.8.8 and even FQDNs like &lt;A href="http://www.facebook.com" target="_blank"&gt;www.facebook.com&lt;/A&gt;&amp;nbsp;but only traffic to 1.2.3.4 is routed through management interface.,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas anyone?&lt;/P&gt;</description>
    <pubDate>Mon, 30 Dec 2019 03:42:21 GMT</pubDate>
    <dc:creator>rjdahav163</dc:creator>
    <dc:date>2019-12-30T03:42:21Z</dc:date>
    <item>
      <title>Routing driving me crazy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-driving-me-crazy/m-p/305129#M79286</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here's a weird issue!&lt;/P&gt;&lt;P&gt;We have one public IP lets say 1.2.3.4.&lt;/P&gt;&lt;P&gt;Our PA VM 300, can ping to any public IP address other than 1.2.3.4.&lt;/P&gt;&lt;P&gt;For all other public IP addresses, it sends traffic via default route out of external interface. But for 1.2.3.4, it sends the traffic to our management gateway. Following to be noted:&lt;/P&gt;&lt;P&gt;1. 1.2.3.4 is our other PA firewall external IP where we were trying to connect using IPSec S2S tunnel. I deleted all the tunnel config since I was afraid that it was somehow interfering with the routing. But that did not solve the problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. From all other devices we can ping 1.2.3.4 and ping is allowed on this interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Security Policies, NAT and static default route pointing out from external interface to next hop are all correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4. We can ping other public IP addresses like 8.8.8.8 and even FQDNs like &lt;A href="http://www.facebook.com" target="_blank"&gt;www.facebook.com&lt;/A&gt;&amp;nbsp;but only traffic to 1.2.3.4 is routed through management interface.,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas anyone?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 03:42:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-driving-me-crazy/m-p/305129#M79286</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2019-12-30T03:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Routing driving me crazy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-driving-me-crazy/m-p/305132#M79287</link>
      <description>&lt;P&gt;Also,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we tried using&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ping host 1.2.3.4&lt;/P&gt;&lt;P&gt;ping source &amp;lt;our_public_interface_addr&amp;gt; host 1.2.3.4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No luck using both!&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 03:47:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-driving-me-crazy/m-p/305132#M79287</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2019-12-30T03:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: Routing driving me crazy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-driving-me-crazy/m-p/305139#M79290</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Whenever you try to ping an IP from firewall, by default it will use your mgmt plane and then will forward traffic to gateway configured for mgmt plane. It wont look up firewalls routing table. If you specify source as specific data plane interface, then it will use that interface IP as source and will look into your routing table to forward the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;for ping host 1.2.3.4&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It is expected to go through mgmt plane as you have not defined any specific source. Validate&amp;nbsp;if anything is blocking this PING traffic on the gateway of your mgmt plane or on further hops.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;for ping source &amp;lt;our_public_interface_addr&amp;gt; host 1.2.3.4&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This sounds like intrazone traffic and will exit through your external interface. There is chance that you might not notice traffic log for this if log generation is not enabled on default intrazone rule. Also as peer device is PA, validate if you have applied any interface management profile on the external interface of peer firewall which is restricting&amp;nbsp;PING to only certain IP's.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 04:19:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-driving-me-crazy/m-p/305139#M79290</guid>
      <dc:creator>Rajesh12</dc:creator>
      <dc:date>2019-12-30T04:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: Routing driving me crazy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-driving-me-crazy/m-p/305253#M79316</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/100390"&gt;@Rajesh12&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything was configured correctly.&lt;/P&gt;&lt;P&gt;You know what solved the problem?? - Firewall Restart &lt;span class="lia-unicode-emoji" title=":neutral_face:"&gt;😐&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 21:34:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-driving-me-crazy/m-p/305253#M79316</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2019-12-30T21:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: Routing driving me crazy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-driving-me-crazy/m-p/305278#M79323</link>
      <description>&lt;P&gt;Mighty restart to the rescue. Glad your issue is resolved &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2019 01:15:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-driving-me-crazy/m-p/305278#M79323</guid>
      <dc:creator>Rajesh12</dc:creator>
      <dc:date>2019-12-31T01:15:10Z</dc:date>
    </item>
  </channel>
</rss>

