<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: routing between 2 virtual router in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/routing-between-2-virtual-router/m-p/310280#M80343</link>
    <description>&lt;P&gt;If ping is working, but everything else doesn't, then it's very likely that you have asynchronous routing. Ping request is sent via the firewall, but the reply is taking a different path (bypassing the firewall).&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 09 Feb 2020 13:15:41 GMT</pubDate>
    <dc:creator>JoergSchuetter</dc:creator>
    <dc:date>2020-02-09T13:15:41Z</dc:date>
    <item>
      <title>routing between 2 virtual router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-between-2-virtual-router/m-p/310272#M80342</link>
      <description>&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;i have a setup like the image below.&lt;/P&gt;&lt;P&gt;my goal is to allow internet throught interfaces 3 and 4 (i have a virtual router with these 2 interfaces, vr_l3) : this is working&lt;/P&gt;&lt;P&gt;i have an IPSEC tunnel on interface 1 (with another virtual router, vr1) to route 172.22.0.0/20 : this is working&lt;/P&gt;&lt;P&gt;i have a dhcp server on interface 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if i put a route directly on the workstation, this is working (route add 172.22.0.0 mask 255.255.240.0 172.22.54.245)&lt;/P&gt;&lt;P&gt;next i would like to have the firewall doing this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1/ first i tried to make a static route in vr_l3 to 172.22.54.245&lt;/P&gt;&lt;P&gt;strangely, i have ping which is working but web-browsing is not&lt;/P&gt;&lt;P&gt;2/ secondly, i tried to route to the next vr, vr1&lt;/P&gt;&lt;P&gt;but i have nothing working&lt;/P&gt;&lt;P&gt;3/ third, i try to put a static route in dhcp server&lt;/P&gt;&lt;P&gt;option 249, 14AC16AC1636F5&lt;/P&gt;&lt;P&gt;but this is working on a PA220 and not on a PA200 7.0.19 : i can't obtain an ip address when option 249 is set&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i don't think it's a policy problem because i currently have a any-any rule to allow traffic&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="xxx.jpg" style="width: 748px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23880i18E7D54E8C19BE51/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="xxx.jpg" alt="xxx.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 12:24:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-between-2-virtual-router/m-p/310272#M80342</guid>
      <dc:creator>gilles007</dc:creator>
      <dc:date>2020-02-09T12:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: routing between 2 virtual router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-between-2-virtual-router/m-p/310280#M80343</link>
      <description>&lt;P&gt;If ping is working, but everything else doesn't, then it's very likely that you have asynchronous routing. Ping request is sent via the firewall, but the reply is taking a different path (bypassing the firewall).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 13:15:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-between-2-virtual-router/m-p/310280#M80343</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2020-02-09T13:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: routing between 2 virtual router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-between-2-virtual-router/m-p/310292#M80344</link>
      <description>&lt;P&gt;yes, this command :&lt;/P&gt;&lt;P&gt;set deviceconfig setting tcp asymmetric-path bypass&lt;/P&gt;&lt;P&gt;did the trick&lt;/P&gt;&lt;P&gt;but what will be the aftermath ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 14:25:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-between-2-virtual-router/m-p/310292#M80344</guid>
      <dc:creator>gilles007</dc:creator>
      <dc:date>2020-02-09T14:25:59Z</dc:date>
    </item>
  </channel>
</rss>

