<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Names instead for IP address on routing table in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/names-instead-for-ip-address-on-routing-table/m-p/328105#M83423</link>
    <description>&lt;P&gt;I3 interface is created automatically not at the static route configuration time, but it is created with the virtual router. It is useful to route traffic from one virtual router to another virtual router internally.&lt;/P&gt;&lt;P&gt;It is also visible by "show routing interface".&lt;/P&gt;</description>
    <pubDate>Fri, 15 May 2020 02:48:24 GMT</pubDate>
    <dc:creator>jchen1</dc:creator>
    <dc:date>2020-05-15T02:48:24Z</dc:date>
    <item>
      <title>Names instead for IP address on routing table</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/names-instead-for-ip-address-on-routing-table/m-p/185555#M56759</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a PA with two Virtual Routers, Internal VR and DMZ-Internet VR. When I type show routing fib virtual-router "Internal VR" for example the forwarding table shows a name for next hop and interface, see the output below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;show routing fib virtual-router "Internal VR"&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;id destination nexthop flags interface mtu&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;--------------------------------------------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;51814 0.0.0.0/0 &lt;STRONG&gt;DMZ-Internet VR&lt;/STRONG&gt; u &lt;STRONG&gt;Internal VR/i3&lt;/STRONG&gt; 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I change the output to see the IP address of "DMZ-Internet VR" instead of the name? Which interface is that Internal VR/i3, there is not such interface on show interface all.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The same happens if I change the Virtual router on the command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;show routing fib virtual-router "DMZ-Internet VR"&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;id destination nexthop flags interface mtu&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;34049 0.0.0.0/0 210.10.200.193 ug ae4.32 1500&lt;BR /&gt;50428 10.0.0.0/24 &lt;STRONG&gt;Internal VR&lt;/STRONG&gt; u &lt;STRONG&gt;DMZ-Internet VR/i3&lt;/STRONG&gt; 0&lt;BR /&gt;50429 10.4.0.0/24 &lt;STRONG&gt;Internal VR&lt;/STRONG&gt; u &lt;STRONG&gt;DMZ-Internet VR/i3&lt;/STRONG&gt; 0&lt;BR /&gt;52354 10.5.0.0/24 &lt;STRONG&gt;Internal VR&lt;/STRONG&gt; u &lt;STRONG&gt;DMZ-Internet VR/i3&lt;/STRONG&gt; 0&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Cheers&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2017 06:12:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/names-instead-for-ip-address-on-routing-table/m-p/185555#M56759</guid>
      <dc:creator>DaniloBarbosa</dc:creator>
      <dc:date>2017-11-06T06:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: Names instead for IP address on routing table</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/names-instead-for-ip-address-on-routing-table/m-p/185562#M56760</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;To display route entries for any Virtual-Router that you have (for example Internal VR), run the following command:&lt;/FONT&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt; show routing route virtual-router &lt;EM&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;Internal VR&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for more details find blow Palo Alto Firewall CLI Cheat Sheet: Networking.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/cli-gsg/cli-cheat-sheets/cli-cheat-sheet-networking" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/cli-gsg/cli-cheat-sheets/cli-cheat-sheet-networking&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2017 06:29:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/names-instead-for-ip-address-on-routing-table/m-p/185562#M56760</guid>
      <dc:creator>Feldiasti</dc:creator>
      <dc:date>2017-11-06T06:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: Names instead for IP address on routing table</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/names-instead-for-ip-address-on-routing-table/m-p/185584#M56762</link>
      <description>&lt;P&gt;there is no IP address associated to these routes as&amp;nbsp;they are&amp;nbsp;'next-vr' internal routes.&amp;nbsp;They are not directed at an ip address but rather at another internal virtual router. once the packet is delivered to the next router, that router will take care of routing to the next hop&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;eg:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;a packet departing a host on your DMZ arrives on the firewall on the "Internal" router&lt;/P&gt;
&lt;P&gt;that router had a default route pointed at a different virtual router, so the "Internal" simply hands off the packet to the other VR:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;51814 0.0.0.0/0&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;DMZ-Internet VR&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;u&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Internal VR/i3&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;0&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;DMZ-internet is the next hop, there is an internal transaction so this is handled through the VR/i3 internal interface&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;then the&amp;nbsp;next router "DMZ-Internet" has it's default gateway go out to the next hop 210.10.200.193 going out of the ae4.32 subinterface&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;34049 0.0.0.0/0 210.10.200.193 ug ae4.32 1500&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;returning packets from the internet are received on "DMZ-Internet" and forwarded to the other VR through the VR/i3 interface, back to where the client has a physical connection&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;50428 10.0.0.0/24&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Internal VR&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;u&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;DMZ-Internet VR/i3&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;0&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;50429 10.4.0.0/24&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Internal VR&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;u&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;DMZ-Internet VR/i3&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;0&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;52354 10.5.0.0/24&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Internal VR&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;u&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;DMZ-Internet VR/i3&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;0&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;the VR config will look like this&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Route pointing to a different VR"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/5DE745A4213343D2E26844B0146B285E/responsive_peak/images/image_not_found.png" alt="Route pointing to a different VR" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;So, because you are directing packets at the VR, there will not be an IP&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;hope this helps&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2017 07:46:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/names-instead-for-ip-address-on-routing-table/m-p/185584#M56762</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-11-06T07:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Names instead for IP address on routing table</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/names-instead-for-ip-address-on-routing-table/m-p/185659#M56774</link>
      <description>&lt;P&gt;Hi Reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You gave the answer that I was looking for but I didn't find. Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then Palo Alto do not use IP addresses when there is a "directc" connection between two virtual routers, and this connection can be made internally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have seen different vendors&amp;nbsp;using an external device to route traffic between two virtual routers (VRF). This is the reason why I got confused when I saw the PA FIB.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have another question for you. The internal interface is created automatically when next-vr is selected on static route configuration. is it right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By the way, I am new at PA&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2017 21:42:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/names-instead-for-ip-address-on-routing-table/m-p/185659#M56774</guid>
      <dc:creator>DaniloBarbosa</dc:creator>
      <dc:date>2017-11-06T21:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: Names instead for IP address on routing table</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/names-instead-for-ip-address-on-routing-table/m-p/185700#M56782</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76701"&gt;@DaniloBarbosa&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's multiple options available and external routing is certainly an option if you do not wish to perform internal forwarding (just route out to a next hop like you would do normally), but as you noticed this is not mandatory (wait till you see &lt;A title="inter-vsys routing" href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Tips-amp-Tricks-Inter-VSYS-routing/ta-p/69699" target="_blank"&gt;inter-vsys routing&lt;/A&gt; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The internal interface is always there and gets used once internal forwarding is set up, no need to create it&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And welcome to the Community! Hope you like it here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2017 09:18:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/names-instead-for-ip-address-on-routing-table/m-p/185700#M56782</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-11-07T09:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Names instead for IP address on routing table</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/names-instead-for-ip-address-on-routing-table/m-p/328105#M83423</link>
      <description>&lt;P&gt;I3 interface is created automatically not at the static route configuration time, but it is created with the virtual router. It is useful to route traffic from one virtual router to another virtual router internally.&lt;/P&gt;&lt;P&gt;It is also visible by "show routing interface".&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2020 02:48:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/names-instead-for-ip-address-on-routing-table/m-p/328105#M83423</guid>
      <dc:creator>jchen1</dc:creator>
      <dc:date>2020-05-15T02:48:24Z</dc:date>
    </item>
  </channel>
</rss>

