PA220 routing issue

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PA220 routing issue

L0 Member

I have three PA220s, let's call them

 

PA220-A

PA220-B

PA220-C

 

They are connected in the following manner:

 

PA220-A ---- PA220-B ----- PA220-C

 

All three have an Inside and Outside Interface. All the Outside interfaces are connected via a Layer2 network. My IP addressing, let's say it's the following:

 

PA220-A - Outisde - 172.16.10.1

PA220-A - Inside 192.168.0.0/24 (192.168.0.1/24)

 

PA220-B - Outside - 172.16.10.2

PA220-B - Inside - 192.168.1.0/24 (192.168.1.1/24)

 

PA220-C - Outside - 192.168.1.0/24 (192.168.1.2/24)

PA220-C - Inside - 192.168.2.0/24 (192.168.2.1/24)

 

When I'm pinging from the outside interface of PA220-C, I can traverse the entire network into PA220-A, and vice versa. But when I try to ping from PA220-C inside network, I get a timeout. But I can ping between the Inside and Outside interface of PA220-C. I belive it's a routing issue, but I'm banging my head against the wall trying to figure this one out.

 

 If anyone has any suggestions on areas to look at, that would be helpful.

 

It's also noted that I have deleted all firewall rules on all three PA220, just to test connectivity first. I have also changed the default rules to allow all traffic regardless.

2 REPLIES 2

Cyber Elite
Cyber Elite

Hello,

Make sure you are allowing ping via the management profile for hte interfce and allowing ping via the policies. The traffic logs should tell you where they are getting blocked.

 

Regards,

L0 Member

After stepping away from the issue for a day, I was able to to logically map out my issue. The problem was I didn't have a route back from PA220-B to PA220-C. I had routes that would get me to PA220-A and PA220-B.

 

Thanks

  • 1852 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!