MGMT routing issue

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

MGMT routing issue

L2 Linker

Hello,

 

How can I get MGMT to ping to the LAN port?

young19918_0-1676551196675.png

 

Any help is appreciated.

 

1 ACCEPTED SOLUTION

Accepted Solutions

L7 Applicator

Traffic can only take blue path.

There is no interconnection or routing between management module and dataplane (LAN on your diagram) inside Palo.

Packets from sourcing from management interface physically leave management interface to get to the destination.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

View solution in original post

20 REPLIES 20

Community Team Member

Hi @young19918 ,

 

Using the command ping host <IP address> and you will automatically ping from your mgmt interface:

 

kiwi_0-1676556448324.png

 

Kind regards,

-Kiwi.

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Don't forget to hit that Like button if a post is helpful to you!

Hi @kiwi ,

Thanks for your reply.

 

I've tried this before, but had some problems ...... (as shown in the picture below)

These two red boxes show the source should be the same (mgmt), but one works and the other doesn't ......

young19918_0-1676557380425.png

 

And it can also ping the LAN port of the PA, why can't ping a server with port docking? (192.168.30.1)

young19918_1-1676557658635.png

 

Any help is appreciated.

 

Cyber Elite
Cyber Elite

Hello,

Is what you are attempting to ping in a different vlan or security zone? Could be the PAN blocking you?

Regards,

L5 Sessionator

In addition to what @OtakarKlier suggested, do you have ping enabled on the Data interface? Every interface has a Management Profile which lists the services that are allowed to run on that interface (except the Management interface which is handled a little bit differently). The interface Management Profile can be found under: Network-Interfaces->[interface_config]->Advanced->Other Info-Management Profile.

 

The Management Profiles define which services (ping, HTTP/HTTPS, SSH, etc.) can run on an interface and are configured from: Network->Network Profiles->Interface Mgmt

L7 Applicator

Is 10.2.100.54 your firewall management interface or have you enabled Interface Management profile on dataplane interface with IP 10.2.100.54?

 

ping host 1.1.1.1 (ping request goes out from mgmt interface)

ping source x.x.x.x host 1.1.1.1 (ping goes out from dataplane interface with IP x.x.x.x)

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Hi @Raido_Rattameister ,

Thanks for your reply.

 

Now I know the difference between these two.
But I still have a question, if can ping to 192.168.30.254, why can't ping to 192.168.30.1 (architecture diagram below)

young19918_0-1676597527112.png

young19918_1-1676597613329.png

young19918_2-1676597715893.png

 

 

Any help is appreciate.

 

L7 Applicator

Well command "ping host 192.168.30.1" sends ping out from management interface.

Something needs to route from 10.2.100.x network to 192.168.30.x network.

 

Packet don't jump from management plane to dataplane inside firewall. Those packets will actually exit from management interface and need to be routed to different subnet to reach 192.168.30.1

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Hi @Raido_Rattameister ,

Thanks for your reply.

 

It looks like there should be

young19918_0-1676603513107.png

 

 

L7 Applicator

Do you have any dataplane interface with 10.2.100.x IP.

What is default gateway IP configured on mgmt interface?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Hi @Raido_Rattameister ,

 

Yes,I have.Here is my structure :

young19918_0-1676603845293.png

 

L7 Applicator

In "Monitor > Traffic" you should see traffic from 10.2.100.54 to 192.168.30.1

If you don't then check that you have overridden interzone-default rule at the bottom of the ruleset and chosen "Log at session end".

If you see sessions but no return packets then OS firewall is blocking incoming ping.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Hi @Raido_Rattameister ,

Thanks for your reply.

Yes,I have chosen "Log at session end".

But I can't see any session...

L7 Applicator

Is management port connected somehow to ethernet1/1 (either directly or through switch)?

What is output of "traceroute host 192.168.30.1"?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Hi @Raido_Rattameister ,

 

It seems that MGMT is first sent to the outside of the core and has no way to switch itself in the PA.

young19918_0-1676606773035.png

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!