<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ping to internet from 2nd interface IP is not working&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ping-to-internet-from-2nd-interface-ip-is-not-working-quot/m-p/333956#M84291</link>
    <description>&lt;P&gt;Yes. there is no ruleset...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The interface 1/2 and 1/3 has a default route 0.0.0.0 /0 with different metric value to their respective ISP's next hope.&lt;/P&gt;&lt;P&gt;Interface 1/2 attached to the HE security zone and Interface 1/3 attached to the Untrust zone.&lt;/P&gt;&lt;P&gt;Default route of Interface 1/2 metric value 11 and Interface 1/3 metric value 5.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but when interface 1/3 untrust zone reaches the internet with his own interface and interface 1/2 HE zone tries to reach internet it goes with untrust interface...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so I am looking for anything y to do that it can reach the internet with his own interface...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jun 2020 21:29:57 GMT</pubDate>
    <dc:creator>Mohammed_Yasin</dc:creator>
    <dc:date>2020-06-17T21:29:57Z</dc:date>
    <item>
      <title>Ping to internet from 2nd interface IP is not working"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-to-internet-from-2nd-interface-ip-is-not-working-quot/m-p/333803#M84257</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;I have 2 outside interfaces configured with the below IP’s.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;When I try to ping 4.2.2.2 using source as 94.56.143.XX interface 1/1 , ping is successful ( Untrust Zone )&amp;nbsp;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;But if I try ping to 4.2.2.2 &amp;amp; using source as 94.56.202.XXX interface 1/2, ping is unsuccessful. ( HE Zone )&lt;/FONT&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;When I try from HE zone , it should go through HE zone but it is going to untrust zone and getting deny&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;I mean&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;ISP 1 connected interface 1/3 with default route o.o.o.o of metric 5&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;ISP 2 Connected interface 1/2 with default route&amp;nbsp;o.o.o.o metric 11&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;From ISP 1 interface 1/3 is pinging to 4.2.2.2 and we able to see the traffic log which allowed by intra-zone policy.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;From ISP 2 interface 1/2 is not pinging to 4.2.2.2 and getting denied by Inter zone policy.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;Its possible to ping from 1/2 interface itself toward Internet.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2020 10:59:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-to-internet-from-2nd-interface-ip-is-not-working-quot/m-p/333803#M84257</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-06-17T10:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Ping to internet from 2nd interface IP is not working"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-to-internet-from-2nd-interface-ip-is-not-working-quot/m-p/333951#M84287</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131110"&gt;@Mohammed_Yasin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Sounds like you don't have a security rulebase entry that actually allows the traffic; you'll still need to allow the traffic.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2020 21:15:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-to-internet-from-2nd-interface-ip-is-not-working-quot/m-p/333951#M84287</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-06-17T21:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: Ping to internet from 2nd interface IP is not working"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-to-internet-from-2nd-interface-ip-is-not-working-quot/m-p/333956#M84291</link>
      <description>&lt;P&gt;Yes. there is no ruleset...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The interface 1/2 and 1/3 has a default route 0.0.0.0 /0 with different metric value to their respective ISP's next hope.&lt;/P&gt;&lt;P&gt;Interface 1/2 attached to the HE security zone and Interface 1/3 attached to the Untrust zone.&lt;/P&gt;&lt;P&gt;Default route of Interface 1/2 metric value 11 and Interface 1/3 metric value 5.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but when interface 1/3 untrust zone reaches the internet with his own interface and interface 1/2 HE zone tries to reach internet it goes with untrust interface...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so I am looking for anything y to do that it can reach the internet with his own interface...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2020 21:29:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-to-internet-from-2nd-interface-ip-is-not-working-quot/m-p/333956#M84291</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-06-17T21:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Ping to internet from 2nd interface IP is not working"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-to-internet-from-2nd-interface-ip-is-not-working-quot/m-p/333967#M84294</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131110"&gt;@Mohammed_Yasin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So some things to keep in mind:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) The firewall is routing your traffic as you've specified with your routes. ISP1 has the lowest metric and is always going to be selected unless you utilize path-monitoring on the route so the route can be removed from the RIB and FIB, which would make your secondary route take over. This is why you are seeing the traffic as you are, the traffic is going to utilize ISP1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) IF you are using PBF to attempt to route some of the traffic through ISP2, traffic has to&amp;nbsp;&lt;STRONG&gt;ingress&amp;nbsp;&lt;/STRONG&gt;a firewall interface to be evaluated for PBF. Traffic sourced directly from the firewall isn't going to hit any PBF you have configured. So while a PBF for traffic routing will work for clients behind the firewall, it won't work for anything terminating on the firewall itself or sourced from the firewall itself.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2020 22:01:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-to-internet-from-2nd-interface-ip-is-not-working-quot/m-p/333967#M84294</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-06-17T22:01:17Z</dc:date>
    </item>
  </channel>
</rss>

