Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Palo Alto Intergrade with ACI- Cannot see hop firewall on tranceroute

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Palo Alto Intergrade with ACI- Cannot see hop firewall on tranceroute

L0 Member

I Integrade Firewall Palo Alto with ACI One Arm , virtual system divided into 2 for North South and East West

On Firewall config Subinterface Layer3 ( Vlan Tag) set IP and config default route to Gateway one ACI. (reference guide)

https://docs.paloaltonetworks.com/vm-series/10-2/vm-series-deployment/set-up-a-firewall-in-cisco-aci...

Traffic from ACI will use PBR to route through Palo Alto, and Palo Alto will return back to ACI using the default route

But when I check tracert between 2 host on traceroute table with traffic throught firewall, I can see all host except the Firewall host.

On the firewall I tried opening the policy allow any any, turning off Zone Protection, turning off Packet Buffer Protection but still can't see the firewall hop in the traceroute message. ping between 2 hosts works fine,

When I capture firewall, on TX i see firewall sent icmp ttl exeeded to client but destination MAC is 00:0c:0c:0c:0c:0c (anycast MAC of ACI) not MAC Address Of client in ARP table

Except for TTL Exceeded all other messages sent to the client are sent to the correct MAC address seen in the ARP.

also. when i test ping traceroute from host to firewall, ping and tracert are ok and with this traceroute i can see the host of firewall

Has anyone ever deployed Palo Alto firewall with ACI and tested tracert with packets passing through the firewall? Looking forward to sharing experiences.

Many tks

 

1 REPLY 1

Cyber Elite
Cyber Elite

To be able to see the firewall in traceroute or ping, you need to set an interface management profile on both interfaces with 'ping' enabled

Next a rule needs to allow your hosts to communicate with the firewall interfaces (depends on how strictly you set your rulebase)

 

reaper_0-1722328789221.png

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 448 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!