- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
08-17-2021 09:20 AM
Hi
I appreciate this is an odd one but I have a little bit of an issue with my home setup, I have a pa-220 behind a sky router, the issue is that if I am coming from the inside network i.e mgmt interface that traverses the inside zone to make it out then I can ping anything I want, however if I am trying to source the ping from the external interface then it fails, this is causing the issue above where I cannot get a vpn up between me and aws as there is never a reply received.
Any help would be greatly appreciated.
08-24-2021 09:35 AM
Hello there
I have a PA220 and pings do work for me. You would need to confirm you have a rule that allows ping FROM the outside interface as shown in my screenshot below:
You should look in your traffic logs and see your pings failing, due to hitting a rule.
If you do not see your traffic, then perhaps you are not logging your traffic on the Intrazone rule at the bottom of your configuration.
What other questions can we answer for you?
08-24-2021 09:35 AM
Hello there
I have a PA220 and pings do work for me. You would need to confirm you have a rule that allows ping FROM the outside interface as shown in my screenshot below:
You should look in your traffic logs and see your pings failing, due to hitting a rule.
If you do not see your traffic, then perhaps you are not logging your traffic on the Intrazone rule at the bottom of your configuration.
What other questions can we answer for you?
08-25-2021 02:23 AM
Hi @S.Cantwell
The problem, unfortunately seems to go much deeper than I feared, there is an issue where traffic originating from the external interface of the firewall cannot it seems make it to the Gateway, although traffic from the inside zone can, I am talking it through with TAC as well as the upstream provider as this did work previously.
Thank you for your reply though and you are, of course, right that I should check there for the logs and make sure the traffic is allowed.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!