- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-19-2023 09:54 PM
Hello All
I would be much appreciated if you can help with setting up my static default route which I believe is the culprit why I'm not able to route data traffic to internet.
eth1/1: WAN interface, the interface is set as L3 untagged, configured DHCP-client for IPv4. ISP assigns a new IP every 10-12 hours and the bridge-mode cable modem is connected to the eth 1/1 port. I'm not able to reach internet from 10.0.9.5 and I don't know what needs to be set from the "Next Hop" pull down menu. Can't use IP address since my ISP assigns IP dynamically and changes every 10-12 hours. Please see my settings below which should help you visualize better how my PA is setup as of now.
--thanks for your help in advance
08-20-2023 05:59 PM
Hi @palorox2023 ,
When you check the box "Automatically create default route pointing to default gateway provided by server", you do not have to manually create a default static route. The NGFW does so. The route created from DHCP looks like the 2nd route in the routing table. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClQRCA0
Delete your static default route. That looks like the 1st entry in the routing table. It is not active and not needed.
Your routing and NAT look fine. Do you see the traffic in the traffic logs allowed and forwarded to the proper interface?
Thanks,
Tom
08-26-2023 03:38 AM - edited 08-26-2023 03:39 AM
thanks for your reply. I deleted the static default route, but I still can't route data traffic to outside WAN via eth1/1. I checked the traffic from the Monitor tab but I don't see traffic going out. here is updated route table after deleting the static default route. I am also attaching the interface setup.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!