This website uses cookies essential to its operation, for analytics, and for personalized content. By continuing to browse this site, you acknowledge the use of cookies. For details on cookie usage on our site, read our Privacy Policy
Under security rules does service refer to source port or destination port and what is the best way to define both source port and destination port in a rule on version 3.1.6
... View more
Cheers, Yes that is exactly what I changed to. Sub interfaces. They are both on the same switch so obviously I do not want to enable routing on the switch but perform the routing through the PA. I think I am working ok now but will fully test next week. Thanks for your suggestions
... View more
Thanks for this. I am saying that pings indicate 'allow' on the traffic log but internal to dmz pings are not getting a response?. I got 2 dmz's working in the last hour by adjusting native vlan on the Cisco switch to the specific vlan and changing every interface to trunking and allowing vlan 1 as well as the vlan I wanted. I am not comfortable that I have actually cracked it yet so any more information would be good.
... View more
I have an issue with getting 2 DMZs working in layer 3 mode on Palo Alto version 3.1.7. I have set up my first DMZ and can communicate perfectly with the internal network. When I setup a second dmz (using completely different interface ports), but exactly the same configuration I cannot communicate from the internal network to the new dmz. Funnily I can communicate perfectly from the new DMZ to the internal but not the other way around. I have enabled policies both ways and if I ping I can see the traffic being allowed both ways. I have double checked the routing and that seems fine as well. I have come to th conclusion there must be some simple configuration to solve this that I am missing :smileyconfused:or there is a bug in the Palo Alto software. Also since I upgraded to version 3.1.7 I get the following error when I do a commit device: Invalid address value 'NaN' Anyone had a similar issue
... View more