We connect two firewalls (PA-200 and PA-500) with a VPN tunnel
and want to initiate a WakeOnLan command from one side of the VPN to an pc on the other side.
From what I underastand of WOL, very basic, its a layer 2 operation so it wont route outside of a vlan or subnet. I think its in the way you send the WOL packet rather than the VPN tunnel config.
I found some stuff doing google searchs with the string 'wake on lan over vpn'.
Hope this helps!
probably its a solution like for Juniper:
but I cannot recognize a similar one in my PA
Another keyword for my problem: "Broadcast forwarding"
I know this is an old thread, but since I got the same problem, I just wanted to add: the juniper solution is working. I had the same issue: WoL packets allowed by policy, but droped by the firewall (PA-3020 in my case). I can see it when doing a packet capture on the firewall (stage drop).
On the Palo Alto, you can go on Network -> Interfaces -> (outgoing interface) -> Advanced -> ARP Entries
You add the broadcast address (192.168.1.255 for exemple), and the mac FF:FF:FF:FF:FF:FF. And the magic packet goes magic!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!