DHCP with ISP router don't work :/

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

DHCP with ISP router don't work :/

L1 Bithead

Hi,

just purchased a PA-3260 and trying to configure it to use DHCP with my ISP router.

The DHCP server works fine on the ISP router, tried it on my laptop.

I reset the PA-3260 than i removed the wired interface and select the first interface and set ip up as DHCP client with default router and untrust zone.

The zones are in Layer3 mode.

 

But it stucks on selecting state...

I tested it with another ISP modem, many others interfaces, others cable even fiber one.

Policys are the default one, even with a policy allowing dhcp on untrust zone doesn't work.

 

When i set it in static, there is no connectivity between the PA and ISP modem

 

Any help wil be greatly appreciated

Thanks

 

30 REPLIES 30

L1 Bithead

Nothing get out from the PA-3260  😕

L1 Bithead

Have you tried restarting the ISP modem?

 

Sometimes those modems register the first MAC address they see and it needs a restart/reset to connect to another one. Easy way to rule out it's that is by connecting another laptop and check if it also gets an IP address.

 

If the second laptop gets an IP address successfully, I would go this way in troubleshooting:

 

  • Since the unit doesn't seem to be in production yet: reboot firewall (+ ISP modem) and try with a temporary any/any security policy first.
  • make sure there is no NAT policy affecting this traffic
  • Check if it's a relatively recent PAN-OS version to rule out existing bugs
  • check forwarding table (should be correct if locally connected)
  • traffic capture WAN interface and check if you see something weird for DHCP when you physically connect the cable 
  • call TAC

L1 Bithead
  • Since the unit doesn't seem to be in production yet: reboot firewall (+ ISP modem) and try with a temporary any/any security policy first.
  • ---> Tried it and excat same issue
  • make sure there is no NAT policy affecting this traffic
  • --> NO NAT Rule
  • Check if it's a relatively recent PAN-OS version to rule out existing bugs
  • --> PAN-OS v10.1.5-h1
  • check forwarding table (should be correct if locally connected)
  • --> Where do i check this one ? Do you mean routing table on the virual router ?
  • traffic capture WAN interface and check if you see something weird for DHCP when you physically connect the cable 
  • --> Already done and here are the results (attached file)
  • call TAC
  • --> Don't speak English very well to have a full conversation with tech

L1 Bithead

I would like to create an account to upgrade this device but it ask me a SCP ID i do not have.

Can we create an account with a second hand product from Palo Alto ? 

L4 Transporter

Without a valid support subscription you cannot make any upgrades.

Unfortunately, for your end-of-sale model (PA-3200 series) you will not be able to obtain a valid support subscription.

Secondary Market Policy 

Hardware End-of-Life Dates 

 

Cheers,
Cosmin

Don't forget to Like items if a post is helpful to you!
Please help out other users and “Accept as Solution” if a post helps solve your problem!

Read more about how and why to accept solutions.

Disclaimer: All messages are my personal ones and do not represent my company's view in any way.

L1 Bithead

But End of sale mean End of support ?

Even if End of support is planned to be 2028 ??

 

Ertu57_0-1733389880093.png

 

L1 Bithead

Ah just read this, my bad

"Devices that are currently end-of-sale cannot be re-certified."

L1 Bithead

Then i'am stuck 😕 Just bought a brick 🙂

If only i can get the interfaces working properly ..

Do i need a licence/certification to activate data plan ?

L1 Bithead

Still trying to figure out how to get it working.

Even with a simple configuration like a laptop and one ethernet connection with static ip each side, i can't ping nothing.

Interface is in trust zone, ping is enbale in interface managment profile

Firewall is by default allowing trust intrazone...

 

I'am really lost 😕

 

Edit: I can ping internal interfaces via devise/troubleshooting

for ex from LAN interface, i can ping the WAN interface.

But from the WAN interface i can't ping my isp modem

and from the LAN interface i can't ping my laptop

 

LAN 192.168.88.2 -> WAN 192.168.1.16 OK

WAN 192.168.1.16 -> ISP 192.168.1.1 NOK

LAN 192.168.88.2 -> LAPTOP 192.168.88.1 NOK

L1 Bithead

Ertu57_0-1734101127508.png

How do i do a clean install ? this is all the firmware i have ont the unit

Thanks for your help

L4 Transporter

Hello @Ertu57 ,

You can do a factory reset from Maintenance Mode or from CLI.

Performing a factory reset will not change the running version of PAN-OS, but will erase all configurations, logs and admin account.

Cheers,
Cosmin

Don't forget to Like items if a post is helpful to you!
Please help out other users and “Accept as Solution” if a post helps solve your problem!

Read more about how and why to accept solutions.

Disclaimer: All messages are my personal ones and do not represent my company's view in any way.

L1 Bithead

thanks for your reply

Just did the factory reset and running the 9.0 Pan OS software.

Will try to configure interfaces again with this version..

L1 Bithead

**bleep** it works !

Can't explain why but it works 🙂

Now i need to upgrade again to the latest version i have

L1 Bithead

Can i jump to 10.1.5-h1 directly or should i do one by one the disk image upgrade ?

L1 Bithead

Ok really strange

When i try on sysroot1 with 9.1 image with exactly the same config it doesn't work 😕

Do i miss something ?

  • 3400 Views
  • 30 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!