<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New VM-100 deployment, cannot ping or tracert to external websites in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/new-vm-100-deployment-cannot-ping-or-tracert-to-external/m-p/342298#M85809</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/148784"&gt;@RamprakashRT&lt;/a&gt;, thanks for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had actually just tried that before your post. I originally had a secondary IP address configured on the interface with a public IP address, but that didn't work. So, I scrapped that, and put the public IP address right on the interface. I can now ping, but tracert isn't working. Do I need to modify the NSG to allow all inbound internet traffic on the untrust interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;</description>
    <pubDate>Wed, 05 Aug 2020 20:33:21 GMT</pubDate>
    <dc:creator>rbottiglieri</dc:creator>
    <dc:date>2020-08-05T20:33:21Z</dc:date>
    <item>
      <title>New VM-100 deployment, cannot ping or tracert to external websites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-vm-100-deployment-cannot-ping-or-tracert-to-external/m-p/342098#M85777</link>
      <description>&lt;P&gt;Just setup a new VM-100 device in Azure. SSL decryption and security policies are in place. My test client PC can browse the web, and all of the policies seem to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I cannot ping or tracert to any public website (e.g., &lt;A href="http://www.apple.com" target="_blank"&gt;www.apple.com&lt;/A&gt;). The DNS resolution works, I see that the ping traffic is allowed in the monitor tab, and I disabled SSL decryption as a test, but it still didn't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm sure that it's something simple, but anyone have any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 22:04:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-vm-100-deployment-cannot-ping-or-tracert-to-external/m-p/342098#M85777</guid>
      <dc:creator>rbottiglieri</dc:creator>
      <dc:date>2020-08-04T22:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: New VM-100 deployment, cannot ping or tracert to external websites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-vm-100-deployment-cannot-ping-or-tracert-to-external/m-p/342297#M85808</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/151211"&gt;@rbottiglieri&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Please make sure you have a PublicIP assigned to your untrust interface . In Azure Ping and traceroute will not work if you didnnt have a public IP in the untrust interface. Please try and let me know,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ram&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 20:29:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-vm-100-deployment-cannot-ping-or-tracert-to-external/m-p/342297#M85808</guid>
      <dc:creator>RamprakashRT</dc:creator>
      <dc:date>2020-08-05T20:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: New VM-100 deployment, cannot ping or tracert to external websites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-vm-100-deployment-cannot-ping-or-tracert-to-external/m-p/342298#M85809</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/148784"&gt;@RamprakashRT&lt;/a&gt;, thanks for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had actually just tried that before your post. I originally had a secondary IP address configured on the interface with a public IP address, but that didn't work. So, I scrapped that, and put the public IP address right on the interface. I can now ping, but tracert isn't working. Do I need to modify the NSG to allow all inbound internet traffic on the untrust interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 20:33:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-vm-100-deployment-cannot-ping-or-tracert-to-external/m-p/342298#M85809</guid>
      <dc:creator>rbottiglieri</dc:creator>
      <dc:date>2020-08-05T20:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: New VM-100 deployment, cannot ping or tracert to external websites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-vm-100-deployment-cannot-ping-or-tracert-to-external/m-p/342301#M85810</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/151211"&gt;@rbottiglieri&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suspect the security policy in the firewall. Just to isolate , is it possible to create a plain firewall rule for the test machine by allowing all the traffic in the firewall.&amp;nbsp; Also untrust interface outbound NSG 'allow all' and trust interface inbound NSG 'allow all'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ram&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 20:48:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-vm-100-deployment-cannot-ping-or-tracert-to-external/m-p/342301#M85810</guid>
      <dc:creator>RamprakashRT</dc:creator>
      <dc:date>2020-08-05T20:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: New VM-100 deployment, cannot ping or tracert to external websites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-vm-100-deployment-cannot-ping-or-tracert-to-external/m-p/342322#M85817</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/148784"&gt;@RamprakashRT&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did some digging, and I think the issue is that Azure does not permit you to ping the default gateway in an Azure VNET. Check out this doc:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/virtual-network/virtual-networks-faq" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/virtual-network/virtual-networks-faq&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adding the public IP to the interface, I can now ping public internet addresses. However, traceroute does not work, and by the looks of things, it is not supposed to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 21:26:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-vm-100-deployment-cannot-ping-or-tracert-to-external/m-p/342322#M85817</guid>
      <dc:creator>rbottiglieri</dc:creator>
      <dc:date>2020-08-05T21:26:21Z</dc:date>
    </item>
  </channel>
</rss>

