{"id":111,"date":"2022-04-25T07:28:57","date_gmt":"2022-04-25T11:28:57","guid":{"rendered":"https:\/\/pressbooks.bccampus.ca\/paloalto\/?post_type=chapter&#038;p=111"},"modified":"2026-02-18T15:22:43","modified_gmt":"2026-02-18T20:22:43","slug":"dora-the-dhcp-provider","status":"publish","type":"chapter","link":"https:\/\/pressbooks.bccampus.ca\/paloalto\/chapter\/dora-the-dhcp-provider\/","title":{"raw":"1.2 DORA the DHCP Provider","rendered":"1.2 DORA the DHCP Provider"},"content":{"raw":"<div class=\"textbox textbox--learning-objectives\"><header class=\"textbox__header\">\r\n<p class=\"textbox__title\">Learning Objectives<\/p>\r\n\r\n<\/header>\r\n<div class=\"textbox__content\">\r\n<ul>\r\n \t<li>Set up a DHCP server on Palo Alto<\/li>\r\n \t<li>Set up zones<\/li>\r\n \t<li>Connect clients to the <span style=\"background-color: #ffff00\">Internet<\/span> with Palo Alto<\/li>\r\n<\/ul>\r\n<\/div>\r\n<\/div>\r\n<div class=\"textbox shaded\">\r\n\r\n<strong>Scenario<\/strong>: In this lab, we are going to configure our friend DORA (Discover Offer Request Acknowledge) the hander of addresses. And we'll also be configuring internet access so that clients may finally browse their precious Internet with SNAT (Source Network Address Translation).\r\n\r\n<\/div>\r\n\r\n[caption id=\"attachment_141\" align=\"aligncenter\" width=\"1078\"]<img class=\"wp-image-141 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/topology2.png\" alt=\"main scenario\" width=\"1078\" height=\"471\" \/> Figure 1.21: main scenario[\/caption]\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 109px\" border=\"0\"><caption>Table 1.2: Addressing Table<\/caption>\r\n<tbody>\r\n<tr style=\"height: 18px\">\r\n<th style=\"width: 50%;height: 18px\" scope=\"col\">Device<\/th>\r\n<th style=\"width: 50%;height: 18px\" scope=\"col\">Configuration<\/th>\r\n<\/tr>\r\n<tr style=\"height: 55px\">\r\n<td style=\"width: 50%;height: 55px\">PaloAlto<\/td>\r\n<td style=\"width: 50%;height: 55px\">management: 192.168.0.1\/24\r\nEthernet1\/1: 10.0.0.1\/24\r\nEthernet1\/2: DHCP<\/td>\r\n<\/tr>\r\n<tr style=\"height: 18px\">\r\n<td style=\"width: 50%;height: 18px\">Client (WebTerm)<\/td>\r\n<td style=\"width: 50%;height: 18px\">eth0: DHCP<\/td>\r\n<\/tr>\r\n<tr style=\"height: 18px\">\r\n<td style=\"width: 50%;height: 18px\">Management (WebTerm)<\/td>\r\n<td style=\"width: 50%;height: 18px\">eth0: 192.168.0.2\/24<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\" border=\"0\"><caption>Table 1.3: Zone Configuration<\/caption>\r\n<tbody>\r\n<tr>\r\n<th style=\"width: 50%\" scope=\"col\">Zones<\/th>\r\n<th style=\"width: 50%\" scope=\"col\">Interfaces<\/th>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Inside<\/td>\r\n<td style=\"width: 50%\">Ethernet1\/1<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Outside<\/td>\r\n<td style=\"width: 50%\">Ethernet1\/2<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<h2>Create Zones in the Palo Alto Web Interface<\/h2>\r\nUnder the network tab, click zones, then add on the bottom left of the screen.\r\n\r\n[caption id=\"attachment_356\" align=\"aligncenter\" width=\"1024\"]<img class=\"wp-image-356 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP1.jpg\" alt=\"Creating zones\" width=\"1024\" height=\"769\" \/> Figure 1.22: Creating zones[\/caption]\r\n\r\nIn here, we just change the name and type of zone. For information's sake. We will only be dealing with (mostly) layer 3 things in Palo Alto for this book. After that, press <b>OK<\/b>. Remember to create Inside and Outside zones (Remember to also commit changes from time to time!)\r\n\r\n[caption id=\"attachment_357\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-357 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP2.jpg\" alt=\"Create a zone Inside as a layer3\" width=\"1026\" height=\"830\" \/> Figure 1.23: Create a zone Inside as a layer3[\/caption]\r\n\r\n[caption id=\"attachment_501\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-501 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1.jpg\" alt=\"Create a zone Outside as a layer3\" width=\"1026\" height=\"830\" \/> Figure 1.24: Create a zone Outside as a layer3[\/caption]\r\n<h2>Set Up a Static Interface IP Address in Palo Alto<\/h2>\r\nGo under the network tab, and click on ethernet1\/1.\r\n\r\n[caption id=\"attachment_358\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-358 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP3.jpg\" alt=\"Select Ethernet 1\/1\" width=\"1026\" height=\"830\" \/> Figure 1.25: Select Ethernet 1\/1[\/caption]\r\n\r\nThe first thing we want to do when configuring an interface is changing the interface type to layer 3, the virtual router to default, and changing the security zone to the desired zone. In this case, we have to change it to inside for ethernet1\/1, and outside for ethernet1\/2.\r\n\r\n[caption id=\"attachment_359\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-359 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP4.jpg\" alt=\"Ethernet 1\/1 Configuration\" width=\"1026\" height=\"830\" \/> Figure 1.26: Ethernet 1\/1 Configuration[\/caption]\r\n\r\nNow, under the IPv4 tab of the opened window, click on <b>Add<\/b>, then type in the address and prefix of the interface.\r\n\r\n[caption id=\"attachment_360\" align=\"aligncenter\" width=\"1024\"]<img class=\"wp-image-360 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP5.jpg\" alt=\"Set an IP address for Ethernet 1\/1\" width=\"1024\" height=\"769\" \/> Figure 1.27: Set an IP address for Ethernet 1\/1[\/caption]\r\n<h2>Ping an Interface in Palo Alto<\/h2>\r\nBy default, a Palo Alto interface is not pingable. In a lab environment, checking if pings are working is a good sanity test. Go to the advanced tab, click the drop-down menu next to the management profile, then click <b>New<\/b>.\r\n\r\n[caption id=\"attachment_361\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-361 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP6.jpg\" alt=\"Ethernet 1\/1 configuration - Advanced Tab\" width=\"1026\" height=\"830\" \/> Figure 1.28: Ethernet 1\/1 configuration - Advanced Tab[\/caption]\r\n\r\nCall this whatever you want, but make sure to tick the ping option under networking services. Then press <b>OK<\/b>.\r\n\r\n[caption id=\"attachment_362\" align=\"aligncenter\" width=\"1024\"]<img class=\"wp-image-362 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP7.jpg\" alt=\"Enable Ping under Interface Management Profile\" width=\"1024\" height=\"769\" \/> Figure 1.29: Enable Ping under Interface Management Profile[\/caption]\r\n<h2>Enable DHCP on an Interface in Palo Alto<\/h2>\r\nIt's almost the same thing as setting up a static interface, but you act differently in the IPV4 menu. Instead of typing in an IP address and mask, you just specify that this is a DHCP client.\r\n\r\n[caption id=\"attachment_363\" align=\"aligncenter\" width=\"1024\"]<img class=\"wp-image-363 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP8.jpg\" alt=\"Enable DHCP Client on Ethernet 1\/2\" width=\"1024\" height=\"769\" \/> Figure 1.30: Enable DHCP Client on Ethernet 1\/2[\/caption]\r\n\r\nDon't forget to commit your changes!\r\n\r\nIf all is well after a commit, you will be able to check your DHCP IP address by clicking \"dynamic DHCP client\" in the main network menu.\r\n\r\n[caption id=\"attachment_364\" align=\"aligncenter\" width=\"1024\"]<img class=\"wp-image-364 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP9.jpg\" alt=\" Dynamic DHCP Client- Receive an IP address from DHCP Server\" width=\"1024\" height=\"769\" \/> Figure 1.31: Dynamic DHCP Client- Receive an IP address from DHCP Server[\/caption]\r\n\r\nHere is an example of that:\r\n\r\n[caption id=\"attachment_152\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-152 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-17-56-33-image.png\" alt=\"IP Address of Interface 1\/2\" width=\"1026\" height=\"830\" \/> Figure 1.32: IP Address of Interface 1\/2[\/caption]\r\n<h2>Set Up a DHCP Server in Palo Alto<\/h2>\r\nIn the network tab, click on <strong>DHCP<\/strong>, then click <b>Add.<\/b>\r\n\r\n[caption id=\"attachment_365\" align=\"aligncenter\" width=\"1024\"]<img class=\"wp-image-365 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP10.jpg\" alt=\"Add a DHCP Server\" width=\"1024\" height=\"769\" \/> Figure 1.33: Add a DHCP Server[\/caption]\r\n\r\nFirst, we need to define the interface, I set that to ethernet1\/1 because it is our LAN. Then, I press <strong>Add<\/strong> and define a range that fits the network subnet.\r\n\r\n[caption id=\"attachment_366\" align=\"aligncenter\" width=\"1024\"]<img class=\"wp-image-366 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP11.jpg\" alt=\"Set a IP Pools for Interface 1\/1\" width=\"1024\" height=\"769\" \/> Figure 1.34: Set an IP Pools for Interface 1\/1[\/caption]\r\n\r\nAfter that, we need to configure some DHCP options under the options tab. Here we need to define the gateway, (which is usually the interface IP address) subnet mask (which is usually 255.255.255.0), and a DNS server. I just use Google's DNS server as an example.\r\n\r\n[caption id=\"attachment_367\" align=\"aligncenter\" width=\"1024\"]<img class=\"wp-image-367 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP12.jpg\" alt=\"Set a Gateway and a primary DNS\" width=\"1024\" height=\"769\" \/> Figure 1.35: Set a Gateway and a primary DNS[\/caption]\r\n\r\nAgain, remember to commit your changes!\r\n<h2>Ping Palo Alto from a LAN Device<\/h2>\r\nWhen opening up your webterm for \"Client\", click the bottom left button, then click terminal.\r\n\r\n[caption id=\"attachment_368\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-368 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP13.jpg\" alt=\"Open Terminal in WebTerm1\" width=\"1026\" height=\"830\" \/> Figure 1.36: Open Terminal in WebTerm1[\/caption]\r\n\r\nType in <span style=\"background-color: #d9d9d9\"><code>ip a<\/code><\/span><code>\u00a0<\/code><code>or <\/code><span style=\"background-color: #d9d9d9\"><code>ifconfig<\/code><\/span><code> <\/code>on the terminal. If you see an IP address under eth0, the DHCP Server worked!\r\n\r\n[caption id=\"attachment_369\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-369 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP14.jpg\" alt=\"Check the IP address in Terminal\" width=\"1026\" height=\"830\" \/> Figure 1.37: Check the IP address in Terminal[\/caption]\r\n\r\nNow, let's ping our Palo Alto device. Type in <code><span style=\"background-color: #d9d9d9\">ping 10.0.0.1<\/span><\/code>. If all works out, you should see this:\r\n\r\n[caption id=\"attachment_370\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-370 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP15.jpg\" alt=\"Ping 10.0.0.1 in the terminal\" width=\"1026\" height=\"830\" \/> Figure 1.38: Ping 10.0.0.1 in the terminal[\/caption]\r\n\r\nThis means that everything so far worked! Press <strong>Ctrl+C<\/strong> to stop pinging the Palo Alto device.\r\n<h2>Security Profile Basics<\/h2>\r\nIn the policies tab, we want to create a new policy. Click on new in the bottom left of the Palo Alto web interface.\r\n\r\n[caption id=\"attachment_371\" align=\"aligncenter\" width=\"1024\"]<img class=\"wp-image-371 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP16.jpg\" alt=\"Add a Security Policy\" width=\"1024\" height=\"769\" \/> Figure 1.39: Add a Security Policy[\/caption]\r\n\r\nUnder the general tab, we just want to give it a name. We will only be working with universal rules.\r\n\r\n[caption id=\"attachment_372\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-372 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP17.jpg\" alt=\"Set a Name for Security Policy\" width=\"1026\" height=\"830\" \/> Figure 1.40: Set a Name for Security Policy[\/caption]\r\n\r\nUnder the source tab, we specify the inside zone (from). In this case, it will be the \"Inside\" zone.\r\n\r\n[caption id=\"attachment_373\" align=\"aligncenter\" width=\"1024\"]<img class=\"wp-image-373 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP18.jpg\" alt=\"Set a Source Zone for Security Policy\" width=\"1024\" height=\"769\" \/> Figure 1.41: Set a Source Zone for Security Policy[\/caption]\r\n\r\nUnder the outside tab (to). Specify the outside zone.\r\n\r\n[caption id=\"attachment_374\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-374 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP19.jpg\" alt=\"Set a Destination Zone for Security Policy\" width=\"1026\" height=\"830\" \/> Figure 1.42: Set a Destination Zone for Security Policy[\/caption]\r\n\r\nAfter that, press <b>OK<\/b> to confirm.\r\n<h2>SNAT (Source NAT: Access the Internet in Palo Alto)<\/h2>\r\nUnder the policies tab, go to NAT, then click <b>Add<\/b>.\r\n\r\n[caption id=\"attachment_375\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-375 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP20.jpg\" alt=\"Set a NAT\" width=\"1026\" height=\"830\" \/> Figure 1.43: Set a NAT[\/caption]\r\n\r\nIn this case, we want to translate packets originating from the Inside to go to the outside zone using the interface address of ethernet1\/2. This would be Port Address Translation Overload. Under the general tab, just change the name.\r\n\r\n[caption id=\"attachment_376\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-376 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP21.jpg\" alt=\"Set a Name for NAT\" width=\"1026\" height=\"830\" \/> Figure 1.44: Set a Name for NAT[\/caption]\r\n\r\nUnder the original packet tab, click <strong>Add<\/strong> then make the source zone inside. As for the destination zone, make it outside.\r\n\r\n[caption id=\"attachment_377\" align=\"aligncenter\" width=\"1024\"]<img class=\"wp-image-377 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP22.jpg\" alt=\"Set a Source Zone and Destination Zone for NAT\" width=\"1024\" height=\"769\" \/> Figure 1.45: Set a Source Zone and Destination Zone for NAT[\/caption]\r\n\r\nUnder translated packet on source address translation. Specify the translation type as Dynamic IP and port, the address type as interface address, and the interface as ethernet1\/2(The interface in the outside zone) After that, click <b>OK<\/b>.\r\n\r\n[caption id=\"attachment_378\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-378 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP23.jpg\" alt=\"Set a Translated Packet\" width=\"1026\" height=\"830\" \/> Figure 1.46: Set a Translated Packet[\/caption]\r\n\r\nDon't forget to commit!\r\n<h2>Check Internet Connectivity on Webterm<\/h2>\r\nIn webterm, you could test pinging 8.8.8.8 like so:\r\n\r\n[caption id=\"attachment_167\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-167 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-17-28-image.png\" alt=\"Verify your configuration\" width=\"1026\" height=\"830\" \/> Figure 1.47: Verify your configuration[\/caption]\r\n\r\nOr you can try navigating to a website for example https:\/\/something.com.\r\n\r\n[caption id=\"attachment_168\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-168 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-18-05-image.png\" alt=\"Verify your connectivity to the Internet\" width=\"1026\" height=\"830\" \/> Figure 1.48: Verify your connectivity to the Internet[\/caption]\r\n\r\nIf both of these work. You have successfully configured DHCP and SNAT properly!","rendered":"<div class=\"textbox textbox--learning-objectives\">\n<header class=\"textbox__header\">\n<p class=\"textbox__title\">Learning Objectives<\/p>\n<\/header>\n<div class=\"textbox__content\">\n<ul>\n<li>Set up a DHCP server on Palo Alto<\/li>\n<li>Set up zones<\/li>\n<li>Connect clients to the <span style=\"background-color: #ffff00\">Internet<\/span> with Palo Alto<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"textbox shaded\">\n<p><strong>Scenario<\/strong>: In this lab, we are going to configure our friend DORA (Discover Offer Request Acknowledge) the hander of addresses. And we&#8217;ll also be configuring internet access so that clients may finally browse their precious Internet with SNAT (Source Network Address Translation).<\/p>\n<\/div>\n<figure id=\"attachment_141\" aria-describedby=\"caption-attachment-141\" style=\"width: 1078px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-141 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/topology2.png\" alt=\"main scenario\" width=\"1078\" height=\"471\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/topology2.png 1078w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/topology2-300x131.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/topology2-1024x447.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/topology2-768x336.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/topology2-65x28.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/topology2-225x98.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/topology2-350x153.png 350w\" sizes=\"auto, (max-width: 1078px) 100vw, 1078px\" \/><figcaption id=\"caption-attachment-141\" class=\"wp-caption-text\">Figure 1.21: main scenario<\/figcaption><\/figure>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 109px\">\n<caption>Table 1.2: Addressing Table<\/caption>\n<tbody>\n<tr style=\"height: 18px\">\n<th style=\"width: 50%;height: 18px\" scope=\"col\">Device<\/th>\n<th style=\"width: 50%;height: 18px\" scope=\"col\">Configuration<\/th>\n<\/tr>\n<tr style=\"height: 55px\">\n<td style=\"width: 50%;height: 55px\">PaloAlto<\/td>\n<td style=\"width: 50%;height: 55px\">management: 192.168.0.1\/24<br \/>\nEthernet1\/1: 10.0.0.1\/24<br \/>\nEthernet1\/2: DHCP<\/td>\n<\/tr>\n<tr style=\"height: 18px\">\n<td style=\"width: 50%;height: 18px\">Client (WebTerm)<\/td>\n<td style=\"width: 50%;height: 18px\">eth0: DHCP<\/td>\n<\/tr>\n<tr style=\"height: 18px\">\n<td style=\"width: 50%;height: 18px\">Management (WebTerm)<\/td>\n<td style=\"width: 50%;height: 18px\">eth0: 192.168.0.2\/24<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\">\n<caption>Table 1.3: Zone Configuration<\/caption>\n<tbody>\n<tr>\n<th style=\"width: 50%\" scope=\"col\">Zones<\/th>\n<th style=\"width: 50%\" scope=\"col\">Interfaces<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Inside<\/td>\n<td style=\"width: 50%\">Ethernet1\/1<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Outside<\/td>\n<td style=\"width: 50%\">Ethernet1\/2<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Create Zones in the Palo Alto Web Interface<\/h2>\n<p>Under the network tab, click zones, then add on the bottom left of the screen.<\/p>\n<figure id=\"attachment_356\" aria-describedby=\"caption-attachment-356\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-356 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP1.jpg\" alt=\"Creating zones\" width=\"1024\" height=\"769\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP1.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP1-300x225.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP1-768x577.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP1-65x49.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP1-225x169.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP1-350x263.jpg 350w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-356\" class=\"wp-caption-text\">Figure 1.22: Creating zones<\/figcaption><\/figure>\n<p>In here, we just change the name and type of zone. For information&#8217;s sake. We will only be dealing with (mostly) layer 3 things in Palo Alto for this book. After that, press <b>OK<\/b>. Remember to create Inside and Outside zones (Remember to also commit changes from time to time!)<\/p>\n<figure id=\"attachment_357\" aria-describedby=\"caption-attachment-357\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-357 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP2.jpg\" alt=\"Create a zone Inside as a layer3\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP2.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP2-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP2-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP2-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP2-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP2-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP2-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-357\" class=\"wp-caption-text\">Figure 1.23: Create a zone Inside as a layer3<\/figcaption><\/figure>\n<figure id=\"attachment_501\" aria-describedby=\"caption-attachment-501\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-501 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1.jpg\" alt=\"Create a zone Outside as a layer3\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-501\" class=\"wp-caption-text\">Figure 1.24: Create a zone Outside as a layer3<\/figcaption><\/figure>\n<h2>Set Up a Static Interface IP Address in Palo Alto<\/h2>\n<p>Go under the network tab, and click on ethernet1\/1.<\/p>\n<figure id=\"attachment_358\" aria-describedby=\"caption-attachment-358\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-358 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP3.jpg\" alt=\"Select Ethernet 1\/1\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP3.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP3-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP3-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP3-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP3-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP3-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP3-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-358\" class=\"wp-caption-text\">Figure 1.25: Select Ethernet 1\/1<\/figcaption><\/figure>\n<p>The first thing we want to do when configuring an interface is changing the interface type to layer 3, the virtual router to default, and changing the security zone to the desired zone. In this case, we have to change it to inside for ethernet1\/1, and outside for ethernet1\/2.<\/p>\n<figure id=\"attachment_359\" aria-describedby=\"caption-attachment-359\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-359 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP4.jpg\" alt=\"Ethernet 1\/1 Configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP4.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP4-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP4-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP4-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP4-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP4-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP4-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-359\" class=\"wp-caption-text\">Figure 1.26: Ethernet 1\/1 Configuration<\/figcaption><\/figure>\n<p>Now, under the IPv4 tab of the opened window, click on <b>Add<\/b>, then type in the address and prefix of the interface.<\/p>\n<figure id=\"attachment_360\" aria-describedby=\"caption-attachment-360\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-360 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP5.jpg\" alt=\"Set an IP address for Ethernet 1\/1\" width=\"1024\" height=\"769\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP5.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP5-300x225.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP5-768x577.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP5-65x49.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP5-225x169.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP5-350x263.jpg 350w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-360\" class=\"wp-caption-text\">Figure 1.27: Set an IP address for Ethernet 1\/1<\/figcaption><\/figure>\n<h2>Ping an Interface in Palo Alto<\/h2>\n<p>By default, a Palo Alto interface is not pingable. In a lab environment, checking if pings are working is a good sanity test. Go to the advanced tab, click the drop-down menu next to the management profile, then click <b>New<\/b>.<\/p>\n<figure id=\"attachment_361\" aria-describedby=\"caption-attachment-361\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-361 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP6.jpg\" alt=\"Ethernet 1\/1 configuration - Advanced Tab\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP6.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP6-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP6-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP6-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP6-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP6-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP6-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-361\" class=\"wp-caption-text\">Figure 1.28: Ethernet 1\/1 configuration &#8211; Advanced Tab<\/figcaption><\/figure>\n<p>Call this whatever you want, but make sure to tick the ping option under networking services. Then press <b>OK<\/b>.<\/p>\n<figure id=\"attachment_362\" aria-describedby=\"caption-attachment-362\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-362 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP7.jpg\" alt=\"Enable Ping under Interface Management Profile\" width=\"1024\" height=\"769\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP7.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP7-300x225.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP7-768x577.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP7-65x49.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP7-225x169.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP7-350x263.jpg 350w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-362\" class=\"wp-caption-text\">Figure 1.29: Enable Ping under Interface Management Profile<\/figcaption><\/figure>\n<h2>Enable DHCP on an Interface in Palo Alto<\/h2>\n<p>It&#8217;s almost the same thing as setting up a static interface, but you act differently in the IPV4 menu. Instead of typing in an IP address and mask, you just specify that this is a DHCP client.<\/p>\n<figure id=\"attachment_363\" aria-describedby=\"caption-attachment-363\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-363 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP8.jpg\" alt=\"Enable DHCP Client on Ethernet 1\/2\" width=\"1024\" height=\"769\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP8.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP8-300x225.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP8-768x577.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP8-65x49.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP8-225x169.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP8-350x263.jpg 350w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-363\" class=\"wp-caption-text\">Figure 1.30: Enable DHCP Client on Ethernet 1\/2<\/figcaption><\/figure>\n<p>Don&#8217;t forget to commit your changes!<\/p>\n<p>If all is well after a commit, you will be able to check your DHCP IP address by clicking &#8220;dynamic DHCP client&#8221; in the main network menu.<\/p>\n<figure id=\"attachment_364\" aria-describedby=\"caption-attachment-364\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-364 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP9.jpg\" alt=\"Dynamic DHCP Client- Receive an IP address from DHCP Server\" width=\"1024\" height=\"769\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP9.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP9-300x225.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP9-768x577.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP9-65x49.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP9-225x169.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP9-350x263.jpg 350w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-364\" class=\"wp-caption-text\">Figure 1.31: Dynamic DHCP Client- Receive an IP address from DHCP Server<\/figcaption><\/figure>\n<p>Here is an example of that:<\/p>\n<figure id=\"attachment_152\" aria-describedby=\"caption-attachment-152\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-152 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-17-56-33-image.png\" alt=\"IP Address of Interface 1\/2\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-17-56-33-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-17-56-33-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-17-56-33-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-17-56-33-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-17-56-33-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-17-56-33-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-17-56-33-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-152\" class=\"wp-caption-text\">Figure 1.32: IP Address of Interface 1\/2<\/figcaption><\/figure>\n<h2>Set Up a DHCP Server in Palo Alto<\/h2>\n<p>In the network tab, click on <strong>DHCP<\/strong>, then click <b>Add.<\/b><\/p>\n<figure id=\"attachment_365\" aria-describedby=\"caption-attachment-365\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-365 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP10.jpg\" alt=\"Add a DHCP Server\" width=\"1024\" height=\"769\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP10.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP10-300x225.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP10-768x577.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP10-65x49.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP10-225x169.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP10-350x263.jpg 350w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-365\" class=\"wp-caption-text\">Figure 1.33: Add a DHCP Server<\/figcaption><\/figure>\n<p>First, we need to define the interface, I set that to ethernet1\/1 because it is our LAN. Then, I press <strong>Add<\/strong> and define a range that fits the network subnet.<\/p>\n<figure id=\"attachment_366\" aria-describedby=\"caption-attachment-366\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-366 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP11.jpg\" alt=\"Set a IP Pools for Interface 1\/1\" width=\"1024\" height=\"769\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP11.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP11-300x225.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP11-768x577.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP11-65x49.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP11-225x169.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP11-350x263.jpg 350w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-366\" class=\"wp-caption-text\">Figure 1.34: Set an IP Pools for Interface 1\/1<\/figcaption><\/figure>\n<p>After that, we need to configure some DHCP options under the options tab. Here we need to define the gateway, (which is usually the interface IP address) subnet mask (which is usually 255.255.255.0), and a DNS server. I just use Google&#8217;s DNS server as an example.<\/p>\n<figure id=\"attachment_367\" aria-describedby=\"caption-attachment-367\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-367 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP12.jpg\" alt=\"Set a Gateway and a primary DNS\" width=\"1024\" height=\"769\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP12.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP12-300x225.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP12-768x577.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP12-65x49.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP12-225x169.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP12-350x263.jpg 350w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-367\" class=\"wp-caption-text\">Figure 1.35: Set a Gateway and a primary DNS<\/figcaption><\/figure>\n<p>Again, remember to commit your changes!<\/p>\n<h2>Ping Palo Alto from a LAN Device<\/h2>\n<p>When opening up your webterm for &#8220;Client&#8221;, click the bottom left button, then click terminal.<\/p>\n<figure id=\"attachment_368\" aria-describedby=\"caption-attachment-368\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-368 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP13.jpg\" alt=\"Open Terminal in WebTerm1\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP13.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP13-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP13-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP13-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP13-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP13-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP13-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-368\" class=\"wp-caption-text\">Figure 1.36: Open Terminal in WebTerm1<\/figcaption><\/figure>\n<p>Type in <span style=\"background-color: #d9d9d9\"><code>ip a<\/code><\/span><code>\u00a0<\/code><code>or <\/code><span style=\"background-color: #d9d9d9\"><code>ifconfig<\/code><\/span><code> <\/code>on the terminal. If you see an IP address under eth0, the DHCP Server worked!<\/p>\n<figure id=\"attachment_369\" aria-describedby=\"caption-attachment-369\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-369 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP14.jpg\" alt=\"Check the IP address in Terminal\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP14.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP14-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP14-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP14-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP14-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP14-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP14-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-369\" class=\"wp-caption-text\">Figure 1.37: Check the IP address in Terminal<\/figcaption><\/figure>\n<p>Now, let&#8217;s ping our Palo Alto device. Type in <code><span style=\"background-color: #d9d9d9\">ping 10.0.0.1<\/span><\/code>. If all works out, you should see this:<\/p>\n<figure id=\"attachment_370\" aria-describedby=\"caption-attachment-370\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-370 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP15.jpg\" alt=\"Ping 10.0.0.1 in the terminal\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP15.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP15-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP15-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP15-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP15-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP15-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP15-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-370\" class=\"wp-caption-text\">Figure 1.38: Ping 10.0.0.1 in the terminal<\/figcaption><\/figure>\n<p>This means that everything so far worked! Press <strong>Ctrl+C<\/strong> to stop pinging the Palo Alto device.<\/p>\n<h2>Security Profile Basics<\/h2>\n<p>In the policies tab, we want to create a new policy. Click on new in the bottom left of the Palo Alto web interface.<\/p>\n<figure id=\"attachment_371\" aria-describedby=\"caption-attachment-371\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-371 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP16.jpg\" alt=\"Add a Security Policy\" width=\"1024\" height=\"769\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP16.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP16-300x225.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP16-768x577.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP16-65x49.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP16-225x169.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP16-350x263.jpg 350w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-371\" class=\"wp-caption-text\">Figure 1.39: Add a Security Policy<\/figcaption><\/figure>\n<p>Under the general tab, we just want to give it a name. We will only be working with universal rules.<\/p>\n<figure id=\"attachment_372\" aria-describedby=\"caption-attachment-372\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-372 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP17.jpg\" alt=\"Set a Name for Security Policy\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP17.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP17-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP17-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP17-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP17-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP17-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP17-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-372\" class=\"wp-caption-text\">Figure 1.40: Set a Name for Security Policy<\/figcaption><\/figure>\n<p>Under the source tab, we specify the inside zone (from). In this case, it will be the &#8220;Inside&#8221; zone.<\/p>\n<figure id=\"attachment_373\" aria-describedby=\"caption-attachment-373\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-373 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP18.jpg\" alt=\"Set a Source Zone for Security Policy\" width=\"1024\" height=\"769\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP18.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP18-300x225.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP18-768x577.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP18-65x49.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP18-225x169.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP18-350x263.jpg 350w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-373\" class=\"wp-caption-text\">Figure 1.41: Set a Source Zone for Security Policy<\/figcaption><\/figure>\n<p>Under the outside tab (to). Specify the outside zone.<\/p>\n<figure id=\"attachment_374\" aria-describedby=\"caption-attachment-374\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-374 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP19.jpg\" alt=\"Set a Destination Zone for Security Policy\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP19.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP19-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP19-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP19-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP19-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP19-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP19-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-374\" class=\"wp-caption-text\">Figure 1.42: Set a Destination Zone for Security Policy<\/figcaption><\/figure>\n<p>After that, press <b>OK<\/b> to confirm.<\/p>\n<h2>SNAT (Source NAT: Access the Internet in Palo Alto)<\/h2>\n<p>Under the policies tab, go to NAT, then click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_375\" aria-describedby=\"caption-attachment-375\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-375 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP20.jpg\" alt=\"Set a NAT\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP20.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP20-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP20-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP20-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP20-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP20-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP20-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-375\" class=\"wp-caption-text\">Figure 1.43: Set a NAT<\/figcaption><\/figure>\n<p>In this case, we want to translate packets originating from the Inside to go to the outside zone using the interface address of ethernet1\/2. This would be Port Address Translation Overload. Under the general tab, just change the name.<\/p>\n<figure id=\"attachment_376\" aria-describedby=\"caption-attachment-376\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-376 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP21.jpg\" alt=\"Set a Name for NAT\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP21.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP21-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP21-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP21-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP21-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP21-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP21-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-376\" class=\"wp-caption-text\">Figure 1.44: Set a Name for NAT<\/figcaption><\/figure>\n<p>Under the original packet tab, click <strong>Add<\/strong> then make the source zone inside. As for the destination zone, make it outside.<\/p>\n<figure id=\"attachment_377\" aria-describedby=\"caption-attachment-377\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-377 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP22.jpg\" alt=\"Set a Source Zone and Destination Zone for NAT\" width=\"1024\" height=\"769\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP22.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP22-300x225.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP22-768x577.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP22-65x49.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP22-225x169.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP22-350x263.jpg 350w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-377\" class=\"wp-caption-text\">Figure 1.45: Set a Source Zone and Destination Zone for NAT<\/figcaption><\/figure>\n<p>Under translated packet on source address translation. Specify the translation type as Dynamic IP and port, the address type as interface address, and the interface as ethernet1\/2(The interface in the outside zone) After that, click <b>OK<\/b>.<\/p>\n<figure id=\"attachment_378\" aria-describedby=\"caption-attachment-378\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-378 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP23.jpg\" alt=\"Set a Translated Packet\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP23.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP23-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP23-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP23-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP23-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP23-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP23-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-378\" class=\"wp-caption-text\">Figure 1.46: Set a Translated Packet<\/figcaption><\/figure>\n<p>Don&#8217;t forget to commit!<\/p>\n<h2>Check Internet Connectivity on Webterm<\/h2>\n<p>In webterm, you could test pinging 8.8.8.8 like so:<\/p>\n<figure id=\"attachment_167\" aria-describedby=\"caption-attachment-167\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-167 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-17-28-image.png\" alt=\"Verify your configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-17-28-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-17-28-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-17-28-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-17-28-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-17-28-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-17-28-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-17-28-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-167\" class=\"wp-caption-text\">Figure 1.47: Verify your configuration<\/figcaption><\/figure>\n<p>Or you can try navigating to a website for example https:\/\/something.com.<\/p>\n<figure id=\"attachment_168\" aria-describedby=\"caption-attachment-168\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-168 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-18-05-image.png\" alt=\"Verify your connectivity to the Internet\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-18-05-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-18-05-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-18-05-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-18-05-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-18-05-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-18-05-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-03-18-19-18-05-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-168\" class=\"wp-caption-text\">Figure 1.48: Verify your connectivity to the Internet<\/figcaption><\/figure>\n<p>If both of these work. You have successfully configured DHCP and SNAT properly!<\/p>\n","protected":false},"author":1572,"menu_order":2,"template":"","meta":{"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":[],"pb_section_license":""},"chapter-type":[],"contributor":[],"license":[],"class_list":["post-111","chapter","type-chapter","status-publish","hentry"],"part":3,"_links":{"self":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/111","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/users\/1572"}],"version-history":[{"count":25,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/111\/revisions"}],"predecessor-version":[{"id":1336,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/111\/revisions\/1336"}],"part":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/parts\/3"}],"metadata":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/111\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/media?parent=111"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapter-type?post=111"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/contributor?post=111"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/license?post=111"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}