- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
07-29-2024 04:14 AM
I Integrade Firewall Palo Alto with ACI One Arm , virtual system divided into 2 for North South and East West
On Firewall config Subinterface Layer3 ( Vlan Tag) set IP and config default route to Gateway one ACI. (reference guide)
Traffic from ACI will use PBR to route through Palo Alto, and Palo Alto will return back to ACI using the default route
But when I check tracert between 2 host on traceroute table with traffic throught firewall, I can see all host except the Firewall host.
On the firewall I tried opening the policy allow any any, turning off Zone Protection, turning off Packet Buffer Protection but still can't see the firewall hop in the traceroute message. ping between 2 hosts works fine,
When I capture firewall, on TX i see firewall sent icmp ttl exeeded to client but destination MAC is 00:0c:0c:0c:0c:0c (anycast MAC of ACI) not MAC Address Of client in ARP table
Except for TTL Exceeded all other messages sent to the client are sent to the correct MAC address seen in the ARP.
also. when i test ping traceroute from host to firewall, ping and tracert are ok and with this traceroute i can see the host of firewall
Has anyone ever deployed Palo Alto firewall with ACI and tested tracert with packets passing through the firewall? Looking forward to sharing experiences.
Many tks
07-30-2024 01:40 AM
To be able to see the firewall in traceroute or ping, you need to set an interface management profile on both interfaces with 'ping' enabled
Next a rule needs to allow your hosts to communicate with the firewall interfaces (depends on how strictly you set your rulebase)
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!