<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VM100 Base config CLI only in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vm100-base-config-cli-only/m-p/359052#M87947</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160272"&gt;@RobC-AU&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have no idea what you've tested with support but I'll go for some of the obvious :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How are you pinging ? Are you pinging from the correct source IP or from your management IP and is a security policy required to allow the ping ? &lt;/P&gt;
&lt;P&gt;Do you see your ping egressing the correct interface ? Does the ping arrive at the destination ?&lt;/P&gt;
&lt;P&gt;Do you see specific global counters rising that could explain why it's failing ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Tue, 27 Oct 2020 13:02:21 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2020-10-27T13:02:21Z</dc:date>
    <item>
      <title>VM100 Base config CLI only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm100-base-config-cli-only/m-p/358948#M87938</link>
      <description>&lt;P&gt;HI all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope i can find someone amazing out there.&lt;/P&gt;&lt;P&gt;We have a VM100 that can only be configured from CLI as the provider that does not support any way to access a VM or webUI&lt;/P&gt;&lt;P&gt;I spent 4 hours on the phone with Palo Alto support and they could not help me.&lt;/P&gt;&lt;P&gt;Quick Break down.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobC-AU_0-1603774892727.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28373i268720847B022D97/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RobC-AU_0-1603774892727.png" alt="RobC-AU_0-1603774892727.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;simple /30 link using vlan 948&lt;/P&gt;&lt;P&gt;Palo Alto ip 172.20.0.82&amp;nbsp;&lt;/P&gt;&lt;P&gt;MPLS ip 172.20.0.81&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobC-AU_1-1603774967244.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28374i7748DAFCAAA65268/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RobC-AU_1-1603774967244.png" alt="RobC-AU_1-1603774967244.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the base config i set :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;set network profiles interface-management-profile Trusted http no https yes ping yes response-pages yes snmp yes ssh yes telnet no&lt;BR /&gt;set network profiles interface-management-profile Partner http no https no ping yes response-pages no snmp no ssh no telnet no&lt;BR /&gt;set network profiles interface-management-profile Untrusted http no https no ping no response-pages no snmp no ssh no telnet no&lt;BR /&gt;set network interface ethernet ethernet1/1 link-state auto link-duplex auto link-speed auto layer3 units ethernet1/1.948 tag 948 interface-management-profile Trusted ip 172.20.0.82/30&lt;BR /&gt;set network virutal-router VirutalRouter1 interface ethernet1/1.948&lt;BR /&gt;set zone MPLS network layer3 ethernet1/1.948&lt;BR /&gt;set deviceconfig system ip-address 10.120.100.254 netmask 255.255.255.0 default-gateway 10.120.100.1 dns-setting servers primary 8.8.8.8 secondary 4.4.4.4&lt;/P&gt;&lt;P&gt;Commit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No replies when i ping&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be great.&lt;/P&gt;&lt;P&gt;Just remmeber no webUi &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 05:14:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm100-base-config-cli-only/m-p/358948#M87938</guid>
      <dc:creator>RobC-AU</dc:creator>
      <dc:date>2020-10-27T05:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: VM100 Base config CLI only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm100-base-config-cli-only/m-p/359052#M87947</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160272"&gt;@RobC-AU&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have no idea what you've tested with support but I'll go for some of the obvious :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How are you pinging ? Are you pinging from the correct source IP or from your management IP and is a security policy required to allow the ping ? &lt;/P&gt;
&lt;P&gt;Do you see your ping egressing the correct interface ? Does the ping arrive at the destination ?&lt;/P&gt;
&lt;P&gt;Do you see specific global counters rising that could explain why it's failing ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 27 Oct 2020 13:02:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm100-base-config-cli-only/m-p/359052#M87947</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-10-27T13:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: VM100 Base config CLI only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm100-base-config-cli-only/m-p/359065#M87954</link>
      <description>&lt;P&gt;Hi Kiwi,&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;I tried pining from the conencted interface EG:&lt;/P&gt;&lt;P&gt;Ping source 172.20.0.82 host 172.20.0.81&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;That way no default interzone transfer rules will block the traffic.&lt;/P&gt;&lt;P&gt;If i do a show coutners i do get Total counter increasing&lt;/P&gt;&lt;P&gt;show counter global filter delta yes&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 732px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28383i4E651C1F81AC11BA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the managment interface&lt;/P&gt;&lt;P&gt;ping source 10.120.100.254 host 172.20.0.81&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 752px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28384iAB9103AAD8953ACA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get no counter increase from managment interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for seeing pings at&amp;nbsp; the other side that is inside the Service providers network and they said they cant tell me what traffic is arrive but they can see traffic increasing when i ping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently i have not configured any secuirty policys other then the 3 managment policys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be great most the time Palo Alto support knock this kinda of stuff out of the park.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 13:58:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm100-base-config-cli-only/m-p/359065#M87954</guid>
      <dc:creator>RobC-AU</dc:creator>
      <dc:date>2020-10-27T13:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: VM100 Base config CLI only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm100-base-config-cli-only/m-p/359171#M87974</link>
      <description>&lt;P&gt;Does the provider block icmp on their device?&lt;BR /&gt;Does the provider see an arp entry for your device?&amp;nbsp;If so, does it match the MPLS facing mac address?&lt;BR /&gt;Are you connected to the PA via some virtual console or direct SSH? If you're on a console, can you ping 10.120.100.1 from the management interface?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 21:20:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm100-base-config-cli-only/m-p/359171#M87974</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2020-10-27T21:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: VM100 Base config CLI only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm100-base-config-cli-only/m-p/359196#M87977</link>
      <description>&lt;P&gt;Connecting via a virtual console. And not a great one no copy and paste functions &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From inside the MPLS network i can ping 172.20.0.81 IP address.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobC-AU_0-1603839167344.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28392iDFE866B397F50339/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RobC-AU_0-1603839167344.png" alt="RobC-AU_0-1603839167344.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;but unable to ping 172.20.0.82&lt;/P&gt;&lt;P&gt;I have configured the network port as a managment port. so i wont be using the gateway of the managment interface.&lt;/P&gt;&lt;P&gt;I made sure that i have a management profile attached to the interface to allow ping and so on.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobC-AU_1-1603839656175.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28393i0992FDF603B72CD4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RobC-AU_1-1603839656175.png" alt="RobC-AU_1-1603839656175.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried tagged and untagged interfaces on the correct vlans. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 04:17:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm100-base-config-cli-only/m-p/359196#M87977</guid>
      <dc:creator>RobC-AU</dc:creator>
      <dc:date>2020-10-28T04:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: VM100 Base config CLI only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm100-base-config-cli-only/m-p/359213#M87978</link>
      <description>&lt;P&gt;Worked it out,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;set system setting dpdk-pkt-io off&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then reboot&lt;/P&gt;&lt;P&gt;All working now&lt;/P&gt;&lt;P&gt;Thank you all so much for your help&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 05:55:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm100-base-config-cli-only/m-p/359213#M87978</guid>
      <dc:creator>RobC-AU</dc:creator>
      <dc:date>2020-10-28T05:55:09Z</dc:date>
    </item>
  </channel>
</rss>

