01-17-2023 02:43 AM
I m setting up a small office network where the endpoints are connecting to a switch that is in turn trunked to a PA220 Firewall . The firewall external interface is configured with a static IP address within the same range as the ISP IP router .
However it appears that neither the ISP router or the Palo can receive arp entries off each other let alone ping each other
The ISP provider has also confirmed the internet connectivity is working fine .
Can anyone please advise ?
Thanks
01-17-2023 05:15 AM - edited 01-17-2023 05:15 AM
If you configure same public IP and gateway on your laptop and connect ISP cable directly to laptop can you get to internet or see arp from ISP?
If yes we can help you troubleshoot Palo.
If not then ISP needs to check their config.
01-17-2023 07:00 AM
Hi
Thanks for the feedback . Unfortunately at the time, I was unable to configure my laptop IP address and Gateway because of admin restrictions ( working to get elevated privileges at the moment ) . The ISP sent an engineer onsite to check internet reachability and he confirmed connectivity to the ISP default gateway by plugging a device directly into the router .What are the sort of config that could prevent the firewall from seeing the router ?
Thanks
01-17-2023 07:37 AM
ISP provides connectivity over access port right (not tagged/trunk port)?
Ask ISP if speed/duplex is set to auto/auto or if they have hardcoded those settings.
If second option you need to match your side.
01-17-2023 09:49 AM
Hi
I will enquire with the ISP about the speed/duplex settings , I would have thought they will be set to auto
Yes the connectivity is provided through an access port . As per the attached topology the firewall connect to an Onsite router that only function in bridge mode with so layer 3 communication is between the firewall and the aggregate router .
The ISP engineer that visited the site confirmed the Internet was working by plugging a portable device into the Onsite router ( LAN 1) and could get to the ISP Aggregate Router using IP addresses within the same range .
Let me know if you have any further suggestions
Thanks in advance
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!