I have .ova PAN 6.1, I imported to VMware, and I have another Guest PC in same VMware, both pan OS & PC have Network adapter connect to VMnet 1 (Host only), The PC have IP address 10.5.5.5, default GW: 10.5.5.250, and PAN Inside Interface 1/2: 10.5.5.250, but I can't ping from PC to Pan ova?
Please need your help..
also i created security plus NAT policy but still
Does your interface have a management profile allowing it to be pinged ?
Hope it helps.
Kim.
Yes i configured already and pingable but still the main issue, which is from Guest PC can't access internet but from PaloAlto i can ping internet but from PC i couldn't, I thought bcz can't reach inside interface, but now reachble inside interface
Is there any debug tool i can check from PAN if there is traffic come in to inside interface?
Since it's pingable now I am pretty sure traffic is reaching the inside interface.
You might want to check traffic log or check global counters to see if the firewall is dropping this and why it is doing so :
How-to-Troubleshoot-Using-Counters-via-the-CLI
Cheers !
-Kim.
I see packet drops increse for inside interface, but I do not know why pan drops packets?
even i have security and nat policy for any just to make sure but still
Hi @faziz123
Check the global counters.
This should give you an indication why the packets are being dropped.
Cheers,
Kim.
Hi,
Ok what is a DNS server configured on the PC.? Please use 8.8.8.8
Try to ping from the PC to 8.8.8.8 and let me know if it works
Cheers
I see your using a vm, have you configured the interfaces to use the mac adress the hypervisor assigns? this is an option in the device config. an other option is to make your portgroup promiscuous. This is because the paloalto in normal opperation will assign it's own mac adress and esx's vswitch will filter those packets.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!