- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-02-2024 08:28 AM - edited 12-02-2024 08:32 AM
Hi,
just purchased a PA-3260 and trying to configure it to use DHCP with my ISP router.
The DHCP server works fine on the ISP router, tried it on my laptop.
I reset the PA-3260 than i removed the wired interface and select the first interface and set ip up as DHCP client with default router and untrust zone.
The zones are in Layer3 mode.
But it stucks on selecting state...
I tested it with another ISP modem, many others interfaces, others cable even fiber one.
Policys are the default one, even with a policy allowing dhcp on untrust zone doesn't work.
When i set it in static, there is no connectivity between the PA and ISP modem
Any help wil be greatly appreciated
Thanks
12-03-2024 04:55 AM
Have you tried release/renew (have you tried turning it off and on again, sorry have to ask)
Are you connecting the ISP router directly to the interface or via a switch?
- Could it be the ISP connection requires a VLAN tag to work?
- if you're not using a switch, can you try using a switch (in case the link speed is somehow not able to sync up)
- have you tried manually setting the link speed/duplex?
Have you tried setting up a pcap on the eth1/1 interface to see if it is sending/receiving DHCP packets ?
12-04-2024 01:00 AM
Hi,
Thanks for your reply.
- when i connect my laptop on the ISP modem, i got a ip, then i think there is no vlan tag.
- I already try with a switch and exact same trouble
- tried this too, no luck
Even in static IP mode i can't get anything, no ping, no traceroute, nothing.
If i issue the command show counter global, i have no error at all
I'am realy lost.
I have configured 2 zones, LAN and WAN on Layer3
One new Virtual router VR1
Only default Policy applied, Intrazone and deny all
PING set to Management profile under interface option
I follow step by step the intial configuration from Palo Alto guide and can't get it working 😕
12-04-2024 01:06 AM
If i release and renew the ip on the interface i'am stuck at INIT on release and then it stucks on SELECTING on renew
New zones
New virtual router
No policy added
all layer 3
Tested on RJ45 and fiber gbics.
DHCP only works on Management interface
What else can it try ?
12-04-2024 01:25 AM
Hi,
Maybe your ISP have configure the DHCP server not to release IP addresses for devices that are not sending also the hostname.
Windows clients will always send the hostname as part of the DHCP request.
Enable Send Hostname on your ethernet1/1 and try after.
12-04-2024 01:45 AM - edited 12-04-2024 01:49 AM
12-04-2024 04:07 AM - edited 12-04-2024 04:11 AM
Hi,
You can check DHCP log file pan_dhcpd.log to see if there are any errors.
The CLI command is:
less mp-log pan_dhcpd.log
or
tail follow yes mp-log pan_dhcpd.log ----> for real-time logs
For more DHCP troubleshooting info, please look here:
12-04-2024 04:34 AM
Do i have a faulty unit ?
2024-12-03 06:54:32.554 -0800 Warning: pan_dhcpd_setup_dp_conn(pan_dhcp_client_thread.c:172): Failed to connect to DP <----
2024-12-03 06:54:37.554 -0800 Error: pan_dhcpd_setup_socket(pan_dhcpd.c:707): bind failed:(errno: 99) Cannot assign requested address
12-04-2024 05:15 AM
Assign a temp static IP on WAN interface same DHCP IP Series and verify connectivity and check it is working or not.
12-04-2024 05:35 AM
Assigned a temp IP on WAN side 192.168.1.11/24
I can ping from LAN Interface 1/19 to WAN interface 1/3 but nothing else
I dont have connectivity after the PA-3260, can't ping the LAN side either my ISP modem
12-04-2024 06:41 AM
Have you tried restarting the ISP modem?
Sometimes those modems register the first MAC address they see and it needs a restart/reset to connect to another one. Easy way to rule out it's that is by connecting another laptop and check if it also gets an IP address.
If the second laptop gets an IP address successfully, I would go this way in troubleshooting:
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!