04-25-2023 03:38 PM - edited 04-25-2023 11:42 PM
Deras
Good day
I am configuring a new palo alto PA -410 device, after configuring the devices I tried to test it with the test environment through connect my laptop to the trust zone and connecting the router to the untrust zone.
after deploying the connection and turning on the PA -410, I checked the firewall to get internet,
my laptop IP address is: static (192.168.2.151), and the trust zone interface IP address is static ( 192.168.2.1 )
untrust interface IP address is: DHCP (192.168.0.104) and the router IP address is 192.168.0.1
there is a ping from the laptop to the trust zone interface (192.168.2.1) and a ping from the firewall to the laptop ( 192.168.2.151 ).
but there isn't a ping from the firewall to the router ( ping host 192.168.0.1 )
could you please help me to identifying the misconfig if there is ?
I have attached all screenshots that are related to the firewall configuration
Many thanks
04-28-2023 01:36 PM
Hello,
Sorry I did not go through the screenshots. However it sounds as if there needs to be a security policy to allow the trust zone to ping the untrust zone. Then check the logs to see if/where its getting blocked.
Regards,
04-28-2023 01:38 PM
Hello,
I looked at the screen shots and looks like the default route in your virtual router is incorrect. It should point to 192.168.0.1 ?
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!