Newbie looking for some guidance

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Newbie looking for some guidance

L1 Bithead

Hello everyone.  I am new to Palo Alto firewalls.  We have bought many new PA-440's and I am having trouble with my very first installation.

 

I have a site that is currently using a TP-Link AX1500 router.

Very simple setup.... ISPmodem----WANportOfAX1500/LANportOfAX1500----Clients.

 

I have tried, without success, to mimic the setup of the AX1500 and replace it with the PA-440.  I have the PA-440 acting as a DHCP server.  My clients get IP addresses, and then can ping the PA-440.  They cannot ping anything on the Internet.  From the PA-440 command line, I also cannot ping anything on the Internet (ping host 8.8.8.8 for example).

 

I know this post leaves many questions, but is there a guide on a very basic setup like this?  I am sure I am missing something small but have been unable to put my finger on it.

 

Thank you -- Walter

8 REPLIES 8

L7 Applicator

"ping host 8.8.8.8" sends ping requests out from Palo mgmt interface.

For this to work mgmt interface needs to be connected, NAT and security policy need to be in place.

Do you see those sessions under "Monitor > Traffic"?

By default "interzone-default" and "intrazone-default" rules don't log so it is suggested to override them and check "Log at session end" on Actions tab.

 

You can also try "ping source 1.2.3.4 host 8.8.8.8" (replace 1.2.3.4 with your WAN IP).

In this case ping goes out from WAN interface. NAT is not needed and by default "intrazone-default" rule will permit this traffic.

 

If you share output of your results we can help you get them connected.

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

L1 Bithead

Thank you very much for responding.

 

I am now working on the bench in my office.  I have two Windows laptops, one Windows PC, and the Palo.

I have attached a picture of the connections.

 

  • The Palo can successfully ping either of it's own interfaces (10.10.150.1 or 24.197.46.86).
  • Palo cannot ping either laptop from the command line.
  • Dell laptop can ping 24.197.46.86, but not 10.10.150.1.
  • HP laptop can ping 10.10.150.1, but not 24.197.46.86.

I am sure I am missing something fundamental.

 

palo1.JPG

L7 Applicator

Can you share screenshot of security and nat policy?

Have you permitted incoming ping in laptops (or disabled firewall)?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

I have the Windows firewall disabled on both laptops.  Just to make sure of pingability, I changed one laptop to match the subnet of the other laptop, cross-connected them via Ethernet, and they were able to ping each other.

I am attaching 7 screenshots.  Thanks again for your help.palo1.jpgpalo2.jpgpalo3.jpgpalo4.jpgpalo6.jpgpalo5.jpgpalo7.jpg

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!