Palo Alto Networks Knowledgebase: Commit Warning: Next Hop IP is not in Subnet of Outgoing Interface

Commit Warning: Next Hop IP is not in Subnet of Outgoing Interface

3015
Created On 04/25/19 08:00 AM - Last Updated 04/26/19 17:22 PM
Initial Configuration 9.0 PAN-OS
Symptom
After upgrading to PAN-OS 9.0, the following warning may be received if the next hop of the static route is not in the subnet of the outgoing interface.
Static route <static-route-name> next hop IP <IP-address> is not in subnet of outgoing interface <outgoing-interface>"
User-added image


Environment
Any firewall running PAN-OS 9.0 and above

Cause
This is a new check introduced in 9.0 part of the new feature where FQDN can be used as "Next Hop."
An FQDN used as a static route next hop must resolve to an IP address that belongs to the same subnet as the interface you configured for the static route.

For consistency, any option used for "Next Hop" will be subjected to this check.
NOTE: This is only a warning and does not cause the commit to fail.


Resolution
Ensure that the next hop must resolve to an IP address that belongs to the same subnet as the interface you configured for the static route.

Attachments
Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLlGCAW&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Attachments