Cannot ping connected adsl modem.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Cannot ping connected adsl modem.

L1 Bithead

Hi all,

 

i've connected a adsl modem to our 3020 to redirect some clients to,  configured the interface as dhcp client, the port successfully gets an ip address from the modem but i can not ping the modem interface from firewall's cli. I might be missing a simple step but i'm fairly new with PA, any help appreciated, thank you

 

 

pa2.pngpa1.pngpa5.pngpa6.pngpa3.pngpa4.png

pa7.png

 

 

1 accepted solution

Accepted Solutions

L6 Presenter

Hi,

 

MGMT profiles will work but only for traffic directed to the Palo interface. If you are initiating the traffic from the Palo ping should work (so no MGMT profiles required). ADSL modem simply might not reply for pings. Are you able to access the internet over that link? You can test with this command:

 

> ping source 192.168.2.10 host 8.8.8.8

View solution in original post

8 REPLIES 8

L4 Transporter

Hi Oseberg,

 

Welcome to the community forums!

 

Create an interface management profile, tick the 'Ping' box and add it to the interface eth 1/5.

 

Hopefully that should take care of it. 

 

Regards,

Anurag

================================================================
ACE 7.0, 8.0, PCNSE 7

Sorry for not mentioning but i've already created a management profile with ping, ssh, telnet and http, and attached it to eth5

 

pa8.png

L6 Presenter

Hi,

 

MGMT profiles will work but only for traffic directed to the Palo interface. If you are initiating the traffic from the Palo ping should work (so no MGMT profiles required). ADSL modem simply might not reply for pings. Are you able to access the internet over that link? You can test with this command:

 

> ping source 192.168.2.10 host 8.8.8.8

L4 Transporter

Exactly @TranceforLife,

 

As tranceforlife told you.. When you ping via CLI from a PA firewall you have to type "ping source <ip related to the interface> host <ip dst>" . If you don't put the keyword "source" you will start ping (by default) from the management interface!

 

BR

D!Z

 

Thank you for the advice.

i cannot ping from source 192.168.2.1 i get an "bind: cannot assign requested address" error

But i can ping google dns from source 192.168.2.10

So is it working as it should ?

 

Sorry l had a typo. You need to source from your assigned ip address by ADSL modem 192.168.2.10


@Oseberg wrote:

Sorry for not mentioning but i've already created a management profile with ping, ssh, telnet and http, and attached it to eth5

 

pa8.png


 

First off: please don't attach this profile to your WAN interface, especially telnet and http are bad ideas to expose to the internet (they expose your management interface to the whole wide internet, unless you set strict security profiles)

I'd recommend setting up GlobalProtect for management tasks

 

You may need to create a specific NAT rule at the top of your NAT policy to not apply nat for any traffic from trust to untrust destined to your external IP as this may create a LAND attack

Typically your default NAT rule will hide trust ip subnet behind the untrust interface IP, for any internet bound traffic this is perfect. but when connecting directly to your external interface, your source ip (natted) wil match your destination ip (interface) exactly. This is called a LAND attack (typically an attacker will use source spoofing to force your interface to reply to itself, potentially causing a loop). Hence, any packets destined to an interface sourced from the same IP address will be dropped

for your ping this will mean it will be discarded as well

 

For a dynamic interface this could pose a challenge as you won't know what your IP will be in advance: you could create a policy on the spot or use a dynamic dns and set an FQDN

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

thanks reaper, but i was just doing couple of tests from this wan, only ping will be open after all,

Thanks all, for the advices

  • 1 accepted solution
  • 6936 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!