AWS Totally Noob Question - Routing

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

AWS Totally Noob Question - Routing

L5 Sessionator

Hi All,

 

I've just deployed my first VM series firewall in the AWS Public Cloud. I've made the security groups, attached ENIs to Network Interfaces, I can get to the GUI and I can see my traffic coming into my untrust interface just fine.

 

On that untrust interface, I'm hosting a GlobalProtect Portal but can't access it. The traffic shows no return bytes. If I look at the packet counters it's being dropped because of no route. My main question, what is the next hop of my default route supposed to be (in the PA VR) so the traffic can leave and go back to the VPC?

 

With Azure, this was a little easier for me to understand because you'd just give it the .1 address in the same subnet to point it back to the Azure Fabric.

 

Again, very sorry for the noob question!

 

Thanks,

Luke.

 

 

1 accepted solution

Accepted Solutions

L2 Linker
Luke:
 
As with Azure, the first IP in the subnet (after the subnet address) is the VPC router in AWS. See
 
 
In particular, the bottom of the section titled “VPC and Subnet Sizing for IPv4” where it lists the reserved addresses in the subnet.
 
If you have the interface set to DHCP, you can click on “Dynamic-DHCP Client” for the  interface and see the gateway IP as well as a number of other items (DHCP options, DNS, etc).
 
Regards,
 
Patrick

View solution in original post

2 REPLIES 2

L2 Linker
Luke:
 
As with Azure, the first IP in the subnet (after the subnet address) is the VPC router in AWS. See
 
 
In particular, the bottom of the section titled “VPC and Subnet Sizing for IPv4” where it lists the reserved addresses in the subnet.
 
If you have the interface set to DHCP, you can click on “Dynamic-DHCP Client” for the  interface and see the gateway IP as well as a number of other items (DHCP options, DNS, etc).
 
Regards,
 
Patrick

Hey @glynn 

 

Absolute legend, that fixed it. Really don't know why I didn't think of grabbing the IP from the DHCP Client Info.

  • 1 accepted solution
  • 5853 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!