- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-25-2021 11:07 AM
Hi
PA_VM installed in ESXi. PortGroup1 is connected to PA management interface. and Portgroup2 is connected to ethernet1/1. PC1 in Portgroup1 can ping the PA and visit it via GUI using management interface 10.0.10.16. Security zone is setup for ethernet1/1 with ip address 10.0.20.16. PC2 with ip address 10.0.20.10 is connected to Portgroup2, but the PC2 cannot ping ethernet1/1(10.0.20.16). Did I miss some steps? Thank you
04-26-2021 12:06 AM
Check if you have "promiscuous mode is enabled " for portgroup or you have configured the ESXi mac address (read the below article):
Also after that if there are still issues do policy trace to see if the policy trace to confirm that the security policy allows you:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClQSCA0
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cla1CAC
If the policy allows you and there are still issues, do pcap capture to see if the traffic reaches the firewall at all:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0
04-26-2021 03:42 AM
hi @PAFrank
Have you configured the management access profile .
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGdCAK
Thanks,
Ram
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!