Hosts behind the firewall in Alibaba Cloud are unable to reach the Internet
16487
Created On 03/23/20 18:01 PM - Last Modified 07/06/26 11:08 AM
Symptom
Environment
- Platform: PA-VM on Alibaba Cloud.
- PAN-OS / Plugin Version: Any
Cause
Egress interface of the firewall instance is not associated with a public IP on Ali Cloud
Resolution
- Create and assign a public IP to the egress interface of firewall instance.
2. Select the newly create IP and click “Bind”
3. Select the instance type as “Secondary ENI”, Mode as “NAT Mode” and under secondary ENI search for Untrust/Egress NIC ID
Note:
o The elastic IP address binds to the ENI as a NAT IP. The ENI supports both public IP address and private IP address.
o You cannot view the elastic IP address in PAN-OS. However, you can use Open API to retrieve the public IP address of a specified ENI.
o NAT mode does not support NAT ALG protocols such as H.323, SIP, DNS, RTSP, TFTP.
o No default route is required in Route Table towards IGW for public IPs to go out to the Internet
o The elastic IP address binds to the ENI as a NAT IP. The ENI supports both public IP address and private IP address.
o You cannot view the elastic IP address in PAN-OS. However, you can use Open API to retrieve the public IP address of a specified ENI.
o NAT mode does not support NAT ALG protocols such as H.323, SIP, DNS, RTSP, TFTP.
o No default route is required in Route Table towards IGW for public IPs to go out to the Internet