<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ubuntu connected with PA firewall (AWS instance) trusted network can't ping untrusted network in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ubuntu-connected-with-pa-firewall-aws-instance-trusted-network/m-p/374747#M89109</link>
    <description>&lt;P&gt;Thanks, Laurence64.&lt;/P&gt;&lt;P&gt;Following is the information.&lt;/P&gt;&lt;P&gt;PA-VM side:&lt;/P&gt;&lt;P&gt;routing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;min@PA-VM&amp;gt; show routing route&lt;BR /&gt;VIRTUAL ROUTER: vr1 (id 1)&lt;BR /&gt;==========ive, ?:loose, C:connect, H:host, S:static, ~:internal, R:rip, O:ospf, B:bgp,&lt;BR /&gt;destination nexthop metric flags age interface next-AS&lt;BR /&gt;0.0.0.0/0 10.20.10.1 10 A S ethernet1/1&lt;BR /&gt;10.20.0.0/16 10.20.61.61 10 A S ethernet1/2&lt;BR /&gt;10.20.10.0/24 10.20.10.50 0 A C ethernet1/1&lt;BR /&gt;10.20.10.50/32 0.0.0.0 0 A H&lt;BR /&gt;10.20.61.0/24 10.20.61.61 0 A C ethernet1/2&lt;BR /&gt;10.20.61.61/32 0.0.0.0 0 A H&lt;BR /&gt;10.60.0.0/24 0.0.0.0 10 A S tunnel.1&lt;BR /&gt;total routes shown: 7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rule: I have permitall&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Susan_Avxt_0-1608140769769.png" style="width: 894px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29161iC2591631945FE49E/image-dimensions/894x76/is-moderation-mode/true?v=v2" width="894" height="76" role="button" title="Susan_Avxt_0-1608140769769.png" alt="Susan_Avxt_0-1608140769769.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Zone:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Susan_Avxt_1-1608140839934.png" style="width: 938px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29162i05B3348ABCF02222/image-dimensions/938x204/is-moderation-mode/true?v=v2" width="938" height="204" role="button" title="Susan_Avxt_1-1608140839934.png" alt="Susan_Avxt_1-1608140839934.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ubuntu side&lt;/P&gt;&lt;P&gt;routing&lt;/P&gt;&lt;P&gt;ubuntu@ip-10-20-61-81:~$ ip route&lt;BR /&gt;default via 10.20.61.1 dev eth0 proto dhcp src 10.20.61.81 metric 100&lt;BR /&gt;10.20.61.0/24 dev eth0 proto kernel scope link src 10.20.61.81&lt;BR /&gt;10.20.61.1 dev eth0 proto dhcp scope link src 10.20.61.81 metric 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ubuntu@ip-10-20-61-81:~$ sudo iptables -L -v -n&lt;BR /&gt;Chain INPUT (policy ACCEPT 102 packets, 8410 bytes)&lt;BR /&gt;pkts bytes target prot opt in out source destination&lt;/P&gt;&lt;P&gt;Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)&lt;BR /&gt;pkts bytes target prot opt in out source destination&lt;/P&gt;&lt;P&gt;Chain OUTPUT (policy ACCEPT 95 packets, 8894 bytes)&lt;BR /&gt;pkts bytes target prot opt in out source destination&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Dec 2020 17:54:24 GMT</pubDate>
    <dc:creator>Susan_Avxt</dc:creator>
    <dc:date>2020-12-16T17:54:24Z</dc:date>
    <item>
      <title>Ubuntu connected with PA firewall (AWS instance) trusted network can't ping untrusted network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ubuntu-connected-with-pa-firewall-aws-instance-trusted-network/m-p/374630#M89080</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Susan_Avxt_1-1608101823548.png" style="width: 915px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29155i4A1725EF9578DCA6/image-dimensions/915x135/is-moderation-mode/true?v=v2" width="915" height="135" role="button" title="Susan_Avxt_1-1608101823548.png" alt="Susan_Avxt_1-1608101823548.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My PA-VM is AWS EC2 instance using software version 10.0.2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;10.20.10/24 is VPC's public subnet, 10.20.61/24 is VPC's private subnet. Ubuntu10.20.61.81 can ping 10.20.61.61, but can't ping 10.20.10.0/24 network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ubuntu 10.60.0.100 can ping 10.20.61.61, but can't ping 10.20.61.81. I have allow 10.60.0.0/24 in the ubuntu10_20_61_81 Security Group.&lt;/P&gt;&lt;P&gt;What do I miss for the configuration?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 07:09:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ubuntu-connected-with-pa-firewall-aws-instance-trusted-network/m-p/374630#M89080</guid>
      <dc:creator>Susan_Avxt</dc:creator>
      <dc:date>2020-12-16T07:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: Ubuntu connected with PA firewall (AWS instance) trusted network can't ping untrusted network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ubuntu-connected-with-pa-firewall-aws-instance-trusted-network/m-p/374661#M89084</link>
      <description>&lt;P&gt;Difficult one to see without looking at the configurations, firstly I would check.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;routing (both sides)&lt;/LI&gt;&lt;LI&gt;Rules (both sides)&lt;/LI&gt;&lt;LI&gt;zone configuration&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am happy to help should you need any further assistance.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 09:09:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ubuntu-connected-with-pa-firewall-aws-instance-trusted-network/m-p/374661#M89084</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2020-12-16T09:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Ubuntu connected with PA firewall (AWS instance) trusted network can't ping untrusted network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ubuntu-connected-with-pa-firewall-aws-instance-trusted-network/m-p/374747#M89109</link>
      <description>&lt;P&gt;Thanks, Laurence64.&lt;/P&gt;&lt;P&gt;Following is the information.&lt;/P&gt;&lt;P&gt;PA-VM side:&lt;/P&gt;&lt;P&gt;routing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;min@PA-VM&amp;gt; show routing route&lt;BR /&gt;VIRTUAL ROUTER: vr1 (id 1)&lt;BR /&gt;==========ive, ?:loose, C:connect, H:host, S:static, ~:internal, R:rip, O:ospf, B:bgp,&lt;BR /&gt;destination nexthop metric flags age interface next-AS&lt;BR /&gt;0.0.0.0/0 10.20.10.1 10 A S ethernet1/1&lt;BR /&gt;10.20.0.0/16 10.20.61.61 10 A S ethernet1/2&lt;BR /&gt;10.20.10.0/24 10.20.10.50 0 A C ethernet1/1&lt;BR /&gt;10.20.10.50/32 0.0.0.0 0 A H&lt;BR /&gt;10.20.61.0/24 10.20.61.61 0 A C ethernet1/2&lt;BR /&gt;10.20.61.61/32 0.0.0.0 0 A H&lt;BR /&gt;10.60.0.0/24 0.0.0.0 10 A S tunnel.1&lt;BR /&gt;total routes shown: 7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rule: I have permitall&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Susan_Avxt_0-1608140769769.png" style="width: 894px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29161iC2591631945FE49E/image-dimensions/894x76/is-moderation-mode/true?v=v2" width="894" height="76" role="button" title="Susan_Avxt_0-1608140769769.png" alt="Susan_Avxt_0-1608140769769.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Zone:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Susan_Avxt_1-1608140839934.png" style="width: 938px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29162i05B3348ABCF02222/image-dimensions/938x204/is-moderation-mode/true?v=v2" width="938" height="204" role="button" title="Susan_Avxt_1-1608140839934.png" alt="Susan_Avxt_1-1608140839934.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ubuntu side&lt;/P&gt;&lt;P&gt;routing&lt;/P&gt;&lt;P&gt;ubuntu@ip-10-20-61-81:~$ ip route&lt;BR /&gt;default via 10.20.61.1 dev eth0 proto dhcp src 10.20.61.81 metric 100&lt;BR /&gt;10.20.61.0/24 dev eth0 proto kernel scope link src 10.20.61.81&lt;BR /&gt;10.20.61.1 dev eth0 proto dhcp scope link src 10.20.61.81 metric 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ubuntu@ip-10-20-61-81:~$ sudo iptables -L -v -n&lt;BR /&gt;Chain INPUT (policy ACCEPT 102 packets, 8410 bytes)&lt;BR /&gt;pkts bytes target prot opt in out source destination&lt;/P&gt;&lt;P&gt;Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)&lt;BR /&gt;pkts bytes target prot opt in out source destination&lt;/P&gt;&lt;P&gt;Chain OUTPUT (policy ACCEPT 95 packets, 8894 bytes)&lt;BR /&gt;pkts bytes target prot opt in out source destination&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 17:54:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ubuntu-connected-with-pa-firewall-aws-instance-trusted-network/m-p/374747#M89109</guid>
      <dc:creator>Susan_Avxt</dc:creator>
      <dc:date>2020-12-16T17:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: Ubuntu connected with PA firewall (AWS instance) trusted network can't ping untrusted network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ubuntu-connected-with-pa-firewall-aws-instance-trusted-network/m-p/374807#M89118</link>
      <description>&lt;P&gt;I found the issue. I need to set "change Sourece/Dest. Check" disable on the Network Interfaces.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 05:49:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ubuntu-connected-with-pa-firewall-aws-instance-trusted-network/m-p/374807#M89118</guid>
      <dc:creator>Susan_Avxt</dc:creator>
      <dc:date>2020-12-17T05:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: Ubuntu connected with PA firewall (AWS instance) trusted network can't ping untrusted network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ubuntu-connected-with-pa-firewall-aws-instance-trusted-network/m-p/378003#M89426</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many apologies for the massive delay in getting back to you over this, indeed yes you have to remove the src/dest check in AWS, glad you found the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 20:34:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ubuntu-connected-with-pa-firewall-aws-instance-trusted-network/m-p/378003#M89426</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2021-01-05T20:34:35Z</dc:date>
    </item>
  </channel>
</rss>

