Commit Warning: Next Hop IP is not in Subnet of Outgoing Interface
Created On 04/25/19 08:00 AM - Last Updated 04/26/19 17:22 PM
Initial Configuration 9.0 PAN-OSSymptom
After upgrading to PAN-OS 9.0, the following warning may be received if the next hop of the static route is not in the subnet of the outgoing interface.
Static route <static-route-name> next hop IP <IP-address> is not in subnet of outgoing interface <outgoing-interface>"
Any firewall running PAN-OS 9.0 and above
This is a new check introduced in 9.0 part of the new feature where FQDN can be used as "Next Hop."
An FQDN used as a static route next hop must resolve to an IP address that belongs to the same subnet as the interface you configured for the static route.
For consistency, any option used for "Next Hop" will be subjected to this check.
NOTE: This is only a warning and does not cause the commit to fail.
Ensure that the next hop must resolve to an IP address that belongs to the same subnet as the interface you configured for the static route.