<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PXE boot not working through FW in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pxe-boot-not-working-through-fw/m-p/406324#M92091</link>
    <description>&lt;P&gt;After further investigation with wireshark on the Windows Deployment Server it seems like the TTL of TFTP is being lowered on the second read bootfile request.&lt;/P&gt;&lt;P&gt;So the traffic doesn't even reach the WDS anymore...&lt;/P&gt;&lt;P&gt;TTL is lowered with 48 less than the first packet and the "distance" is too far away so the udp traffic is dropped on a router a few hops before.&lt;/P&gt;&lt;P&gt;Not an issue with palo&lt;/P&gt;</description>
    <pubDate>Wed, 12 May 2021 11:03:45 GMT</pubDate>
    <dc:creator>AlexanderMahmuzic</dc:creator>
    <dc:date>2021-05-12T11:03:45Z</dc:date>
    <item>
      <title>PXE boot not working through FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pxe-boot-not-working-through-fw/m-p/405175#M91977</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have a FW with PanOS 9.1.7 that is causing PXE boot issues with TFTP protocol.&lt;/P&gt;&lt;P&gt;When traffic is not routed through the firewall it all works and I have seen several threads about this problem but no solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DHCP server: Windows Server 2012 R2 172.18.76.23&lt;/P&gt;&lt;P&gt;WDS server: 172.18.76.20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DHCP option 66: 172.18.76.20&lt;/P&gt;&lt;P&gt;DHCP option 67: \boot\x64\wdsnbp.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface VLAN 10&lt;/P&gt;&lt;P&gt;ip address 172.28.76.1 255.255.255.0&lt;BR /&gt;ip helper-address 172.18.76.23&lt;BR /&gt;ip helper-address 172.18.76.20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When traffic is not routed through the firewall it works, but when its routed through the firewall I can see packets being accepted and packets sent but no packets received&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have a solution for this?&lt;/P&gt;&lt;P&gt;Uploaded a picture of the TFTP problem&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2021 09:55:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pxe-boot-not-working-through-fw/m-p/405175#M91977</guid>
      <dc:creator>AlexanderMahmuzic</dc:creator>
      <dc:date>2021-05-06T09:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: PXE boot not working through FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pxe-boot-not-working-through-fw/m-p/405676#M92031</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/180812"&gt;@AlexanderMahmuzic&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I'm not seeing any image that you may have attached, but it appears that you did attempt to attach one. Have you verified that the firewall isn't dropping any traffic between these clients and your 172.18.76.20 host?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I current have this setup at quite a few sites and we have to have 4011/udp open to our SCCM host with the app-id set to unknown-udp or you need to create a custom app-id or an application-override entry. That's really the only "weird" thing to get this working however.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 May 2021 05:14:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pxe-boot-not-working-through-fw/m-p/405676#M92031</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-05-09T05:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: PXE boot not working through FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pxe-boot-not-working-through-fw/m-p/406324#M92091</link>
      <description>&lt;P&gt;After further investigation with wireshark on the Windows Deployment Server it seems like the TTL of TFTP is being lowered on the second read bootfile request.&lt;/P&gt;&lt;P&gt;So the traffic doesn't even reach the WDS anymore...&lt;/P&gt;&lt;P&gt;TTL is lowered with 48 less than the first packet and the "distance" is too far away so the udp traffic is dropped on a router a few hops before.&lt;/P&gt;&lt;P&gt;Not an issue with palo&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 11:03:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pxe-boot-not-working-through-fw/m-p/406324#M92091</guid>
      <dc:creator>AlexanderMahmuzic</dc:creator>
      <dc:date>2021-05-12T11:03:45Z</dc:date>
    </item>
  </channel>
</rss>

