<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Azure VM cannot access the Internet in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/azure-vm-cannot-access-the-internet/m-p/426812#M94545</link>
    <description>&lt;P&gt;Do you think NATTing in PA is causing the issue?&lt;/P&gt;</description>
    <pubDate>Fri, 13 Aug 2021 22:27:22 GMT</pubDate>
    <dc:creator>Connected123</dc:creator>
    <dc:date>2021-08-13T22:27:22Z</dc:date>
    <item>
      <title>Azure VM cannot access the Internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/azure-vm-cannot-access-the-internet/m-p/426333#M94476</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have deployed Hub and Spoke technology in Azure. All VM traffic is going through the FW. Settings of Spoke VM is same as Hub VM. NSG set to allow all traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW is configured with 3 VR static routes (one route to the internet, one from Hub to Trusted Interface of PA and another route from Spoke to Trusted interface of PA), SNAT and DNAT rule and one Allow All policy. Using 8.8.8.8 and 4.4.2.2 as Primary and secondary DNS servers. Service route Config is via Management interface. No drop seen in packet capture.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show counter global filter packet-filter yes delta yes&lt;/P&gt;&lt;P&gt;Global counters:&lt;BR /&gt;Elapsed time since last sampling: 15.265 seconds&lt;/P&gt;&lt;P&gt;name value rate severity category aspect description&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;pkt_recv 2 0 info packet pktproc Packets received&lt;BR /&gt;pkt_sent 18 1 info packet pktproc Packets transmitted&lt;BR /&gt;session_allocated 7 0 info session resource Sessions allocated&lt;BR /&gt;session_installed 7 0 info session resource Sessions installed&lt;BR /&gt;flow_host_pkt_xmt 72 4 info flow mgmt Packets transmitted to control plane&lt;BR /&gt;flow_host_vardata_rate_limit_ok 72 4 info flow mgmt Host vardata not sent: rate limit ok&lt;BR /&gt;flow_ip_cksm_sw_validation 15 0 info flow pktproc Packets for which IP checksum validation was done in software&lt;BR /&gt;appid_ident_by_icmp 3 0 info appid pktproc Application identified by icmp type&lt;BR /&gt;nat_dynamic_port_xlat 7 0 info nat resource The total number of dynamic_ip_port NAT translate called&lt;BR /&gt;dfa_sw 3 0 info dfa pktproc The total number of dfa match using software&lt;BR /&gt;ctd_pscan_sw 3 0 info ctd pktproc The total usage of software for pscan&lt;BR /&gt;ctd_process 3 0 info ctd pktproc session processed by ctd&lt;BR /&gt;ctd_pkt_slowpath 3 0 info ctd pktproc Packets processed by slowpath&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Total counters shown: 13&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;ping google.com&lt;/P&gt;&lt;P&gt;Pinging google.com [142.250.76.110] with 32 bytes of data:&lt;BR /&gt;Request timed out.&lt;BR /&gt;Request timed out.&lt;BR /&gt;Request timed out.&lt;BR /&gt;Request timed out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ping to 8.8.8.8 failed. Spoke VM cannot browse the Internet. Traffic log shows TCP-RST-SERVER. No log seen in the Threat log.&lt;/P&gt;&lt;P&gt;Disabled defender firewall but no luck. Please advise how to fix the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 08:24:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/azure-vm-cannot-access-the-internet/m-p/426333#M94476</guid>
      <dc:creator>Connected123</dc:creator>
      <dc:date>2021-08-23T08:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: Azure VM cannot access the Internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/azure-vm-cannot-access-the-internet/m-p/426453#M94494</link>
      <description>&lt;P&gt;All&amp;nbsp;VM's&amp;nbsp;without a public IP has connectivity to&amp;nbsp;internet, even when you haven't associated a NSG to subnet/NIC. Once you have associated it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 09:41:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/azure-vm-cannot-access-the-internet/m-p/426453#M94494</guid>
      <dc:creator>Perez15</dc:creator>
      <dc:date>2021-08-12T09:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Azure VM cannot access the Internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/azure-vm-cannot-access-the-internet/m-p/426495#M94501</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you don't mind helping me out with this post pls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;.4 is assigned to the three interfaces (mgmt, untrust and untrust) of PA.&lt;/P&gt;&lt;P&gt;VM from Hub side (DC Subnet shown in the screenshot) can access the Internet. VM from Spoke (Dev Subnet shown in the screenshot) cannot.&lt;/P&gt;&lt;P&gt;I tried adding the vnet subnets as well but no luck.&lt;/P&gt;&lt;P&gt;I have already checked this post below.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/azure-palo-alto-arp-not-found/m-p/336411/thread-id/84754/highlight/false#M84756" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/azure-palo-alto-arp-not-found/m-p/336411/thread-id/84754/highlight/false#M84756&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 08:24:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/azure-vm-cannot-access-the-internet/m-p/426495#M94501</guid>
      <dc:creator>Connected123</dc:creator>
      <dc:date>2021-08-23T08:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: Azure VM cannot access the Internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/azure-vm-cannot-access-the-internet/m-p/426812#M94545</link>
      <description>&lt;P&gt;Do you think NATTing in PA is causing the issue?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 22:27:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/azure-vm-cannot-access-the-internet/m-p/426812#M94545</guid>
      <dc:creator>Connected123</dc:creator>
      <dc:date>2021-08-13T22:27:22Z</dc:date>
    </item>
  </channel>
</rss>

