With out ARP entry internet is not working.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

With out ARP entry internet is not working.

L4 Transporter

Dear Friends,

I have 2 interfaces in PAN->lan zone and internet zone

ISP router-huawei mac is not learned in palo alto firewall..As a result, Internet not working

But when i add static ARP entry for huawei router in ISP interface, Internet is working fine.

Please suggest to me.Thanks

Regards

Satish

7 REPLIES 7

Cyber Elite
Cyber Elite

Hi Satish

could you share parts of your config? especially interesting is the configuration of the interfaces and the virtual router + the output of > show routing route and > show arp all

one thing that comes to mind is taht there could be a subnet mismatch between the interface and the IP of the default gateway eg if: 10.0.0.1/25 dg: 10.0.0.254 , this could cause such issue

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L3 Networker

Mis-matched network masks configure on the PAN and Huawei devices perhaps?

Hi Tpiens,

Thanks for your reply but i have done the following things:

Disable/delete Source-Nat dynamic and port translated address Policy

Clear session

Ping source internet ip host 4.2.2.2

Then check all of the possible issues noted in this document: https://live.paloaltonetworks.com/docs/DOC-7571

I can't able to findout why it happen...Please suggest.

Hi Ajbool,

Thanks for reply but both device config is same.

Regards

Satish

Hi Satish

can you get the output of:

> show routing route

> show interface all

> show arp all

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hello Satish,

Try to find out 2 possibilities here.

1-- PAN is sending the ARP request, but the ISP router is not responding back. You can take a packet capture on the PAN firewall. Ref DOC: How To Capture ARP Packets on an Interface

2-- PAN FW itself is not sending the ARP broadcast mesage. In this situation, you can forecefully send a Gratuitous ARP (GARP) message to update an ARP table of the ISP routers ARP table. Ref DOC: Trigger a Gratuitous ARP (GARP) from a Palo Alto Networks Device

Hope this helps.

Thanks

Thanks Dud.. Let me check and i will come back to you. Regards Satish

  • 3719 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!