- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-17-2023 02:43 AM
I m setting up a small office network where the endpoints are connecting to a switch that is in turn trunked to a PA220 Firewall . The firewall external interface is configured with a static IP address within the same range as the ISP IP router .
However it appears that neither the ISP router or the Palo can receive arp entries off each other let alone ping each other
The ISP provider has also confirmed the internet connectivity is working fine .
Can anyone please advise ?
Thanks
01-20-2023 06:04 AM
Hi @HassanThiam ,
I am glad the Internet is working now. If my answer helped you get the ping working, please accept it as the solution.
With regard to the VPN, we would be glad to help on this thread, but technically it is a different topic.
A good place to start with IPsec is the green lights under Network > IPSec Tunnels, and Monitor > Logs > System. As @Raido_Rattameister mentioned, NO_PROPOSAL_CHOSEN means the crypto settings do not match and the tunnel is not up.
Thanks,
Tom
01-17-2023 05:15 AM - edited 01-17-2023 05:15 AM
If you configure same public IP and gateway on your laptop and connect ISP cable directly to laptop can you get to internet or see arp from ISP?
If yes we can help you troubleshoot Palo.
If not then ISP needs to check their config.
01-17-2023 07:00 AM
Hi
Thanks for the feedback . Unfortunately at the time, I was unable to configure my laptop IP address and Gateway because of admin restrictions ( working to get elevated privileges at the moment ) . The ISP sent an engineer onsite to check internet reachability and he confirmed connectivity to the ISP default gateway by plugging a device directly into the router .What are the sort of config that could prevent the firewall from seeing the router ?
Thanks
01-17-2023 07:37 AM
ISP provides connectivity over access port right (not tagged/trunk port)?
Ask ISP if speed/duplex is set to auto/auto or if they have hardcoded those settings.
If second option you need to match your side.
01-17-2023 09:49 AM
Hi
I will enquire with the ISP about the speed/duplex settings , I would have thought they will be set to auto
Yes the connectivity is provided through an access port . As per the attached topology the firewall connect to an Onsite router that only function in bridge mode with so layer 3 communication is between the firewall and the aggregate router .
The ISP engineer that visited the site confirmed the Internet was working by plugging a portable device into the Onsite router ( LAN 1) and could get to the ISP Aggregate Router using IP addresses within the same range .
Let me know if you have any further suggestions
Thanks in advance
01-19-2023 02:31 AM
Good Morning ,
I can now confirm I have Internet connectivity but I have set up a VPN with an ASA that s not coming up . The outside interface of the Palo is up and can ping the ASA outside interface .
Any advice will be greatly appreciated
Thanks
01-19-2023 04:12 AM
Hi @HassanThiam ,
Thanks,
Tom
01-20-2023 01:45 AM
Hi Tom
Thanks for the feedback .
As per the topology I can t get the tunnel to the ASA working although the IKE parameters seem to match . The outside interface of the Palo can ping the ASA though . From an ASA perspective I can t see nothing on the logs .
This s the message I get from the NGFW .
Any help will be greatly appreciated
Thanks
01-20-2023 05:21 AM
Crypto settings don't match.
Do you manage ASA side as well to check config?
"show vpn-sessiondb detailed l2l" is helpful to use on ASA side.
If you can't get this info then next step is to turn Palo side to passive mode and figure out what ASA is negotiating with using packet capture.
01-20-2023 06:04 AM
Hi @HassanThiam ,
I am glad the Internet is working now. If my answer helped you get the ping working, please accept it as the solution.
With regard to the VPN, we would be glad to help on this thread, but technically it is a different topic.
A good place to start with IPsec is the green lights under Network > IPSec Tunnels, and Monitor > Logs > System. As @Raido_Rattameister mentioned, NO_PROPOSAL_CHOSEN means the crypto settings do not match and the tunnel is not up.
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!