A connection issue between PA and SW

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

A connection issue between PA and SW

L2 Linker

Hi, PA port e1/2 is connected to switch port f1/5(L3). Both devices can see each other's ip and mac address. The Virtual router and Security zone and Magagement profile Ping are configured. but both devices cannot ping each other. Did I miss some step? Thank you

 

2 accepted solutions

Accepted Solutions

@DavidyPalo 

 

Make sure Ping is allowed to PA interface under Network and Interface MGMT.

 

Regards

MP

Help the community: Like helpful comments and mark solutions.

View solution in original post

Cyber Elite
Cyber Elite

Thank you for feedback @DavidyPalo

 

I am sorry, I would like to confirm one point. In your first post you mentioned: "The Virtual router and Security zone and Management profile Ping are configured." Since you mentioned it ping is working after creating new management profile, does it mean ping was not allowed in your previous management profile or it was not applied to interface from the beginning?

 

Regarding overriding, the intrazone-default rule, could you please click on in intrazone-default and navigate to the bottom of the page and click on overrride button?

 

PavelK_0-1640035637138.png

 

Thank you and Regards

Pavel

 

Help the community: Like helpful comments and mark solutions.

View solution in original post

10 REPLIES 10

Cyber Elite
Cyber Elite

Thank you for post @DavidyPalo 

 

By default Firewall is using management interface for ping. If you want to verify reachability of data plane interface you can change source: ping source <int 1/2 ip address> host <destination ip>

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

L2 Linker

Thank you for your reply! Now PA can ping SW, but the SW cannot ping PA. Maybe its default router configuration issue?

PA e1/2 10.200.255.1/24 ------------f1/5 SW 10.200.255.2/24

Below is virtual router vRTR-INET-Core:

DavidyPalo_0-1639955826500.png

 

Cyber Elite
Cyber Elite

Thank you for reply @DavidyPalo

 

Since you can ping Switch from Firewall and it is directly connected link, there should be no issue with routing. Have you checked Firewall's Traffic log to confirm ICMP arrives Firewall? Unless you have custom rule, this should hit by default: intrazone-default rule. Make sure that logging is enabled under: Actions > Log Setting > Log at session end, otherwise you will not see any logs hitting this rule.

Note: I can see that you have not configured Interface for static route. It is not mandatory if you have next hop, however if you want to make sure that next hop is reachable over certain interface you can hardcode it.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

L2 Linker

Hi PaveIK, where to enable Traffic Log? 

under: Actions > Log Setting > Log , it cannot be found.

DavidyPalo_0-1639967641444.png

 

 

Cyber Elite
Cyber Elite

Thank you for reply @DavidyPalo

 

it is under security rule:

PavelK_0-1639970304261.png

Kind Regards

Pavel

 

Help the community: Like helpful comments and mark solutions.

L2 Linker

Why my PA show read-only? I did not setup Panorama

DavidyPalo_0-1639973460318.png

 

Cyber Elite
Cyber Elite

Hello @DavidyPalo 

 

could you click on green gear icon and press override?

PavelK_0-1639974024459.png

then you will be able to edit and commit the change.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

@DavidyPalo 

 

Make sure Ping is allowed to PA interface under Network and Interface MGMT.

 

Regards

MP

Help the community: Like helpful comments and mark solutions.

Cyber Elite
Cyber Elite

Thank you for feedback @DavidyPalo

 

I am sorry, I would like to confirm one point. In your first post you mentioned: "The Virtual router and Security zone and Management profile Ping are configured." Since you mentioned it ping is working after creating new management profile, does it mean ping was not allowed in your previous management profile or it was not applied to interface from the beginning?

 

Regarding overriding, the intrazone-default rule, could you please click on in intrazone-default and navigate to the bottom of the page and click on overrride button?

 

PavelK_0-1640035637138.png

 

Thank you and Regards

Pavel

 

Help the community: Like helpful comments and mark solutions.

L2 Linker

Thank you!!

  • 2 accepted solutions
  • 3879 Views
  • 10 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!