ESXI Server - Inside Host is on Same Port Group as Palo Alto FW Inside Interface and Pings are failing from all inside hosts

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

ESXI Server - Inside Host is on Same Port Group as Palo Alto FW Inside Interface and Pings are failing from all inside hosts

L1 Bithead

I have a ESXI Server with firewall (Inside, DMZ and Outside) zones

Palo Alto has a rule to allow interzone traffice from inside to outside

Palo Alto has NAT configured for Outside Interface

 

When I try to ping from host to host on in the same port group...all is good.

When I try to ping to the Inside Firewall Interface, the ping times out..."Destination Unreachable.

 

Host---->Vnic------->Port Group-------->Vswitch....

 

 

1 REPLY 1

Cyber Elite
Cyber Elite

Hi @ETate So as per my understanding, you are trying to ping inside (or Data Plane) interface of the firewall. I would recommend you to check few things given below-

 

1. Check if Interface MGMT profile is configured on the interface which actually allows required services like ping on it.

2. Check routing to reach host from the firewall. If interface IP is configured using /32 subnet mask, you would need to define specific routes for the host to reach.

3. Verify the traffic logs on the firewalls to see what's happening on the firewall. 

 

Mayur
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!