<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ping: sendmsg: Permission denied to connected router - but can reach destinations beyond that ro in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ping-sendmsg-permission-denied-to-connected-router-but-can-reach/m-p/305852#M79491</link>
    <description>&lt;P&gt;Apparently this feature is implemented but with a twist. As per&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/configure-interfaces/layer-3-interfaces/configure-layer-3-interfaces" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/configure-interfaces/layer-3-interfaces/configure-layer-3-interfaces&lt;/A&gt;&amp;nbsp;you can set /31 subnet now but&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you have a subnet e.g 192.168.1.34/31 you have to give the higher address i.e 192.168.1.35 to PAN&amp;nbsp; and 192.168.1.34 to&amp;nbsp;&lt;/P&gt;&lt;P&gt;the directly connected device otherwise ping doesn't work.&lt;/P&gt;&lt;P&gt;Documentation is so vague about this detail.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jan 2020 10:31:49 GMT</pubDate>
    <dc:creator>GencoYilmaz</dc:creator>
    <dc:date>2020-01-07T10:31:49Z</dc:date>
    <item>
      <title>ping: sendmsg: Permission denied to connected router - but can reach destinations beyond that router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-sendmsg-permission-denied-to-connected-router-but-can-reach/m-p/68314#M39864</link>
      <description>&lt;P&gt;Any help is appreciated...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a PA interface connected to a router using a /31.&amp;nbsp; I have static routes with that router as the next hop.&amp;nbsp; From the firewall interface on the /31 interconnect, I can reach all of the destinations I have static routes for.&amp;nbsp; I can't, however reach the router's IP on the directly connected /31.&amp;nbsp; When I try to ping from the PA sourcing its /32 interconnect address, it gives me:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ping: sendmsg: Permission denied&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I ping from the router to the PA from one end of the /31 to the other, I see the incoming ping in the capture, but the PA doesn't reply (capturing receive, transmit, and firewall).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I ping the PA /31 interface sourcing something beyond the /31 interconnect, I get replies.&amp;nbsp; If I ping from the PA to anything beyond the /31 interconnect, it is successful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I run "test routing", I see that the connected route is what is installed in the FIB table for the neighbor's IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;result:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; interface ethernet1/22&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have no NAT or security policy yet configured, so the policy being hit is the default intrazone allow any.&amp;nbsp; I can see that in the traffic logs and it shows as allowed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My interface management profile also allows ping (and other protocols) - but that is evidenced by the fact that I can ping and SSH to the interface from hosts beyond the /31 interconnect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know that /31's work fine because I'm using them on other interfaces and have no issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ARP table is also correctly populated on both ends of the connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help.&amp;nbsp; Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 01:31:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-sendmsg-permission-denied-to-connected-router-but-can-reach/m-p/68314#M39864</guid>
      <dc:creator>Michael_Martin</dc:creator>
      <dc:date>2015-11-18T01:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: ping: sendmsg: Permission denied to connected router - but can reach destinations beyond that ro</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-sendmsg-permission-denied-to-connected-router-but-can-reach/m-p/68315#M39865</link>
      <description>&lt;P&gt;Weird - switched the interconnect to a /30 and it works now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is an L3 interface.&amp;nbsp; I have /31's working fine on tunnel.x interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the second inconsistent and/or buggy behavior I've found today.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 01:48:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-sendmsg-permission-denied-to-connected-router-but-can-reach/m-p/68315#M39865</guid>
      <dc:creator>Michael_Martin</dc:creator>
      <dc:date>2015-11-18T01:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: ping: sendmsg: Permission denied to connected router - but can reach destinations beyond that ro</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-sendmsg-permission-denied-to-connected-router-but-can-reach/m-p/68327#M39868</link>
      <description>&lt;P&gt;Using /31 was a discussion a while ago&amp;nbsp;:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/RFC-3021/m-p/42320/highlight/true#M31095" target="_blank"&gt;Using 31-Bit Prefixes on IPv4 Point-to-Point Links&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/31 is not supported and a feature request was created. &amp;nbsp;As far as I can see this was not yet introduced.&lt;/P&gt;
&lt;P&gt;Please reach out to your local SE so he can add more weight to this request.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 09:19:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-sendmsg-permission-denied-to-connected-router-but-can-reach/m-p/68327#M39868</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2015-11-18T09:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: ping: sendmsg: Permission denied to connected router - but can reach destinations beyond that ro</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-sendmsg-permission-denied-to-connected-router-but-can-reach/m-p/305852#M79491</link>
      <description>&lt;P&gt;Apparently this feature is implemented but with a twist. As per&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/configure-interfaces/layer-3-interfaces/configure-layer-3-interfaces" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/configure-interfaces/layer-3-interfaces/configure-layer-3-interfaces&lt;/A&gt;&amp;nbsp;you can set /31 subnet now but&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you have a subnet e.g 192.168.1.34/31 you have to give the higher address i.e 192.168.1.35 to PAN&amp;nbsp; and 192.168.1.34 to&amp;nbsp;&lt;/P&gt;&lt;P&gt;the directly connected device otherwise ping doesn't work.&lt;/P&gt;&lt;P&gt;Documentation is so vague about this detail.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 10:31:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-sendmsg-permission-denied-to-connected-router-but-can-reach/m-p/305852#M79491</guid>
      <dc:creator>GencoYilmaz</dc:creator>
      <dc:date>2020-01-07T10:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: ping: sendmsg: Permission denied to connected router - but can reach destinations beyond that ro</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-sendmsg-permission-denied-to-connected-router-but-can-reach/m-p/512435#M106484</link>
      <description>&lt;P&gt;It works. Just todat 20th-August-2022 i configured it on one of ther Interface on PA-3220.&lt;/P&gt;
&lt;P&gt;Initially it was not working as there was two layer2 switches, inline. Even it was not working on tagged sub-interface.&lt;/P&gt;
&lt;P&gt;I connected Router and Firewall directly. Manually set the firewall's port speed to 100mbps as Router port speed was 100mbps, not 1Gbps and it worked for me.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Aug 2022 16:52:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-sendmsg-permission-denied-to-connected-router-but-can-reach/m-p/512435#M106484</guid>
      <dc:creator>PradeepKumarMall</dc:creator>
      <dc:date>2022-08-20T16:52:49Z</dc:date>
    </item>
  </channel>
</rss>

