<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Troubleshoot VM Panorama with multiple interfaces in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshoot-vm-panorama-with-multiple-interfaces/m-p/310768#M80473</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have few virtual Panoramas running 8.1 that are needs to managed firewalls into two different zones with no connection between them. For that reason we have configured the &lt;A href="https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/set-up-panorama/set-up-the-m-series-appliance/configure-panorama-to-use-multiple-interfaces.html" target="_self"&gt;Panorama with multiple interface.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- The mgmt interface in used for access to the Panorama as well as managing some if the firewalls&lt;/P&gt;&lt;P&gt;- Eth1/1 interface is used for managing the rest of the firewalls in the second zone&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We already have few similar setups and everything is working fine. During the last setup we had few typos in the panorama config (the default gw for the eth1/1 was wrong and the fw ip was not in the permitted IPs)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My real problem is that there is no way you can troubleshoot the connectivity between the firewall and the panorama &lt;STRONG&gt;on the second interface.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- The tcpdump command on the panorama is listening only on the mgmt interface and it seems there is no way you can see what is hitting the second interface.&lt;/P&gt;&lt;P&gt;- It seems panorama doesn't support the "packet capture" similar to the firewalls.&lt;/P&gt;&lt;P&gt;- It seems you cannot "show interface" for status and statistics any non-management interface on the panorama&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my point of view there is no way you can confirm if traffic from the firewall is reaching the panorama and if yes, does it reply - &lt;STRONG&gt;if&lt;/STRONG&gt; the firewall is connecting to non-management interface on the panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was hoping if any of you have find some any commands that can help troubleshoot connectivity over non-management interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Feb 2020 11:55:52 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2020-02-12T11:55:52Z</dc:date>
    <item>
      <title>Troubleshoot VM Panorama with multiple interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshoot-vm-panorama-with-multiple-interfaces/m-p/310768#M80473</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have few virtual Panoramas running 8.1 that are needs to managed firewalls into two different zones with no connection between them. For that reason we have configured the &lt;A href="https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/set-up-panorama/set-up-the-m-series-appliance/configure-panorama-to-use-multiple-interfaces.html" target="_self"&gt;Panorama with multiple interface.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- The mgmt interface in used for access to the Panorama as well as managing some if the firewalls&lt;/P&gt;&lt;P&gt;- Eth1/1 interface is used for managing the rest of the firewalls in the second zone&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We already have few similar setups and everything is working fine. During the last setup we had few typos in the panorama config (the default gw for the eth1/1 was wrong and the fw ip was not in the permitted IPs)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My real problem is that there is no way you can troubleshoot the connectivity between the firewall and the panorama &lt;STRONG&gt;on the second interface.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- The tcpdump command on the panorama is listening only on the mgmt interface and it seems there is no way you can see what is hitting the second interface.&lt;/P&gt;&lt;P&gt;- It seems panorama doesn't support the "packet capture" similar to the firewalls.&lt;/P&gt;&lt;P&gt;- It seems you cannot "show interface" for status and statistics any non-management interface on the panorama&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my point of view there is no way you can confirm if traffic from the firewall is reaching the panorama and if yes, does it reply - &lt;STRONG&gt;if&lt;/STRONG&gt; the firewall is connecting to non-management interface on the panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was hoping if any of you have find some any commands that can help troubleshoot connectivity over non-management interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 11:55:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshoot-vm-panorama-with-multiple-interfaces/m-p/310768#M80473</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2020-02-12T11:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshoot VM Panorama with multiple interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshoot-vm-panorama-with-multiple-interfaces/m-p/312234#M80760</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;I am not sure what Panorama model and PanOS version you have, but we have physical M applience on 8.1 and the interface troubleshooting commands are there, e.g."&amp;gt; show interface ethernet1/2",&amp;nbsp; "&amp;gt; tcpdump interface ethernet1/2" .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2020 15:21:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshoot-vm-panorama-with-multiple-interfaces/m-p/312234#M80760</guid>
      <dc:creator>batd2</dc:creator>
      <dc:date>2020-02-20T15:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshoot VM Panorama with multiple interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshoot-vm-panorama-with-multiple-interfaces/m-p/312989#M80860</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/130874"&gt;@batd2&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All of our Panoramas are &lt;STRONG&gt;virtual. &lt;/STRONG&gt;All of them are running on 8.1 and none of them support the command you have:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;user@panorama&amp;gt; show interface 
  management   Show management interface information

user@panorama&amp;gt; show interface ethernet1/1
ethernet1/1 is not one of &amp;lt;management&amp;gt;

Invalid syntax.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems that the physical devices are supporting these commands, but the virtual don't. Which is weird...&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 07:23:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshoot-vm-panorama-with-multiple-interfaces/m-p/312989#M80860</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2020-02-26T07:23:19Z</dc:date>
    </item>
  </channel>
</rss>

