Setting Up the PA-200 for Home Setup question?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Setting Up the PA-200 for Home Setup question?

L4 Transporter

Hey folks,

 

Newbie here.  🙂  I had this going successful before, but after a factory default, not working for me for some reason. 

I've followed this helpful article before and worked on my first try, but not now for some reason.

https://live.paloaltonetworks.com/t5/Configuration-Articles/Setting-Up-the-PA-200-for-Home-and-Small...

 

IE browser will not resolve internet pages.

I can not ping the VLAN gateway IP of 192.168.32.172 from laptop for some reason.  Any ideas?

I can ping the Mgmt interface IP 192.168.32.170, no problem.

Thought I would post my settings and see if anyone sees what I doing wrong?

 

My cabling and client laptop IP configured static.

 PA13.jpg    PA7.jpg

 

Plugged in ethernet cable from ISP modem to 1/1.  Successfully obtained a Dynamic Public IP.

PA1.jpg

 

Created Security Zones.

PA2.jpg

 

Created Vlan Object and assigned to interface 1/2.

PA3.jpg

 

Created vlan object in Trust-L3 Zone, assigned to Vlan Object, and assigned Internal IP address 192.168.32.172 (to be used as internal Gateway).

PA10.jpg

 

Using Default Virtual Router.  You can see the routing entries for the public IP and VLAN IP.

PA8.jpg

 

Security rule created.

PA11.jpg

 

 

NAT rule created.

PA12.jpg

 

 

Internet Security Group profile created.

PA9.jpg

 

 

 

4 REPLIES 4

L6 Presenter

Why VLAN objects? Put IP addresses on network interfaces.

Cyber Elite
Cyber Elite

It looks like you have a single internal vlan?

The easiest way to configure that is to set up your physical interface to layer3 and then, depending on your switch port configuration put an IP on the interface itself (switchport access) or create a tagged subinterface (switchport trunk) with the IP of your choosing

 

layer2 interfaces are fine, but are more useful if you have a bunch of vlans on several switches that you want to bridge through the firewall 🙂

 

To be able to ping an interface on the firewall, you need to attach a management profile to the interface that allows ping (for sneaky stealthy reasons the interfaces don't respond to ping by default)

 

here's a bunch of articles and videos which may be helpful 🙂 Getting Started: The Series

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Correct, yes 1 internal vlan for now.  I was just trying to stick to the article example I was following to get it working intitially and go from there.

 

I will regroup and try again.  Hopefully close this thread this week.

 

Thanks!

I tried it again, this time using the DNS server from Xfinity, instead of 8.8.8.8, working now.

I got ping going on the VLAN interface after assigning a management profile.  I've since removed it (no ping) and internet working fine.

 

Thank you again for the responses.  It's nice to come back to this post for reference.

I am training myself using product documentation, videos, live community, and bought my own used PA-200.

 

I will close this thread.

 

 

  • 1877 Views
  • 4 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!