<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS VM Series Gateway Load Balancers not working in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384369#M1114</link>
    <description>&lt;P&gt;I had a 3 interface setup working: GENEVE In/Out through eth1/1, then into eth1/2 -&amp;gt; NAT -&amp;gt; out of eth 1/3 to the ouetside.&lt;/P&gt;&lt;P&gt;Traffic would end up passing through the firewall twice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the other hand GWLB seems to break GP, so cannot run GP portal/Gateway on the outside interface.&lt;/P&gt;</description>
    <pubDate>Sun, 07 Feb 2021 19:19:35 GMT</pubDate>
    <dc:creator>pkhavkine</dc:creator>
    <dc:date>2021-02-07T19:19:35Z</dc:date>
    <item>
      <title>AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/373760#M1074</link>
      <description>&lt;P&gt;Hi All&lt;BR /&gt;&lt;BR /&gt;Has anyone else had a play with the GWLB on AWS?&lt;BR /&gt;I know it must be PAN-OS 10.0.2 or higher to work,&lt;BR /&gt;I have tested with multiple instances,&amp;nbsp;&lt;BR /&gt;As a bump in the wire it works fine. until you apply NAT, then it doesn't work at all for any traffic that is NAT'd.&amp;nbsp;&lt;BR /&gt;I have an open TAC for this, they are replicating the fault to work it out but surely this was all tested before it went public.&lt;/P&gt;&lt;P&gt;I also found overlay routing breaks traffic flow. its not documented anywhere that I could find but what I found was it processes the GENEVE traffic in the virtual router where without it, is just an in-return non routed flow.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you've tinkered with it and actually got inbound/outbound NAT and/or overlay routing to function, please let me know what you did.&amp;nbsp;&lt;/P&gt;&lt;P&gt;sadly the documentation just doesnt provide any decent clarity for this feature.&lt;BR /&gt;&lt;BR /&gt;Also extremely disappointed they havent integrated this into version 9.1.&lt;BR /&gt;I am hopeful they will add it with 9.1.7 in a functional state as I am not planning to move my clients to 10.0 until the list of known issues is about 1/4 its current size.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 05:23:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/373760#M1074</guid>
      <dc:creator>craig.beamish</dc:creator>
      <dc:date>2020-12-11T05:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/373831#M1077</link>
      <description>&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;Thanks for your feedback.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How are you deploying the GWLB with VM-Series? Are you using any of the templates provided on our Github repo?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/PaloAltoNetworks/AWS-GWLB-VMSeries" target="_blank"&gt;https://github.com/PaloAltoNetworks/AWS-GWLB-VMSeries&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you are using a CFT with an autoscale template, then it will create a NAT GW along with other components. The template also takes care of the automatic route population for any new APP VPCs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 07:27:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/373831#M1077</guid>
      <dc:creator>rapatil</dc:creator>
      <dc:date>2020-12-11T07:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/373860#M1079</link>
      <description>&lt;P&gt;As of this time, break out routing is not supported.&amp;nbsp; The traffic must stay in the Geneve tunnel.&amp;nbsp; In reading this, it appears you are addressing the outbound use case.&amp;nbsp; In that traffic flow, the NatGW must be used as the next hop beyond the GWLBe as depicted in this flow.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmeurer_1-1607691268668.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29101iE6D2285A6C414F33/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmeurer_1-1607691268668.png" alt="jmeurer_1-1607691268668.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmeurer_2-1607691284478.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29102iA852A302A7513C50/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmeurer_2-1607691284478.png" alt="jmeurer_2-1607691284478.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 12:57:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/373860#M1079</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2020-12-11T12:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/374804#M1083</link>
      <description>&lt;P&gt;We are using a nat gateway. outbound works just fine until you apply NAT of any sort. just trying to apply any sort of NAT to change the direction of the traffic breaks it.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;so if i put a nat rule that traffic to 1.1.1.1 gets d-nat to&amp;nbsp; 8.8.8.8, the traffic never exits the firewall.&lt;BR /&gt;key use for this was for inbound traffic, redirecting inbound traffic to the correct ALB&amp;nbsp; that lives in another vpc, the traffic seems to get dropped at the firewall, even though pcaps show it *thinks* it is being forwarded on, its not.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 04:18:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/374804#M1083</guid>
      <dc:creator>craig.beamish</dc:creator>
      <dc:date>2020-12-17T04:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/374986#M1085</link>
      <description>&lt;P&gt;Inbound requires ingress routing to use the GWLB without SNAT.&amp;nbsp; You can do that within the application vpc using a public-facing LB in front of the application.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmeurer_0-1608227286234.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29183i34F0512C4305BFEC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmeurer_0-1608227286234.png" alt="jmeurer_0-1608227286234.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Or if you want to have a dedicated inbound VPC, you use the same design as above but move your pool members across the TGW.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmeurer_1-1608227341113.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29184iEB77157FE9158A04/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmeurer_1-1608227341113.png" alt="jmeurer_1-1608227341113.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If you prefer the traditional Load Balancer sandwich design where the firewalls are pool members of the front door LB and you are going to SNAT/DNAT to the application, you would either use a dedicated set of firewalls or add new Untrust and Trust interfaces to the firewall as ETH3/4 and use those for ingress outside of the GWLB.&amp;nbsp; This is necessary as the GWLB traffic must hairpin inside of the Geneve tunnel, you cannot insert flows into the tunnel from another interface.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 17:52:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/374986#M1085</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2020-12-17T17:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/375078#M1086</link>
      <description>&lt;P&gt;neither of those suit the application Im doing.&lt;BR /&gt;&lt;BR /&gt;We have multiple inbound services that sit behind the firewall.&amp;nbsp;&lt;BR /&gt;the current layout is the trust/untrust sandwich but we would prefer to move away from the NLB design as they have a capacity limitation in regards to autoscale groups.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;the design plan is that we have 'anchor' network addresses for each inbound service, the traffic comes in via the IGW, steered through the geneve tunnel to the palo, at which point we apply a destination NAT to the actual application load balancer of that service (which is in a different vpc), the traffic is still supposed to egress the geneve tunnel just with a different destination address, but the palo seems to drop it (even though the palo pcap believes it is forwarded on (seen in transmit stage with correct destination IP)&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;on your comment re: overlay routing, why did they put the feature command in there if they havent got it working yet? /logic &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 22:05:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/375078#M1086</guid>
      <dc:creator>craig.beamish</dc:creator>
      <dc:date>2020-12-17T22:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/375081#M1087</link>
      <description>&lt;P&gt;At this point, I would suggest you reach out to your Account Team to engage with one of the Consulting Engineers to discuss over zoom and whiteboard.&amp;nbsp; There is only so much we can accomplish in the message board and a further understanding of your flows is warranted.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 22:13:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/375081#M1087</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2020-12-17T22:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/380002#M1100</link>
      <description>&lt;P&gt;For those playing at home,&lt;/P&gt;&lt;P&gt;In further discussions with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70475"&gt;@jmeurer&lt;/a&gt;, AWS apply a 5 tuple hash on the traffic to ensure return path, so applying a NAT breaks the traffic flow and AWS drops the traffic.&lt;BR /&gt;&lt;BR /&gt;Overlay routing is not yet functional, hopefully it will be in 10.0.4 or 10.0.5 and I can test if I can get the NAT to work for me in that aspect. I am curious if the return traffic would exit via the same geneve tunnel given theres no routes through it in that situation, only time will tell.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 21:45:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/380002#M1100</guid>
      <dc:creator>craig.beamish</dc:creator>
      <dc:date>2021-01-14T21:45:31Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384096#M1110</link>
      <description>&lt;P&gt;Did this issue Fixed.&lt;/P&gt;&lt;P&gt;I am also facing challenges with AWS GWLB.&amp;nbsp;Traffic is Sourced from Outside towards inside.&lt;BR /&gt;Traffic monitor is showing traffic from Outside to Outside.&lt;/P&gt;&lt;P&gt;Not sure why.....&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 12:11:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384096#M1110</guid>
      <dc:creator>Sandeep_Darak</dc:creator>
      <dc:date>2021-02-05T12:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384099#M1111</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/170814"&gt;@Sandeep_Darak&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;that in depends how you setup your interfaces. when you have only one interface then is of course your traffic recognized als interzone fraffic to Outside -&amp;gt; Outside. when you want to split it then you have to create sub interfaces and map them to a another zone and adopt your FW VR routing.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 12:37:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384099#M1111</guid>
      <dc:creator>tostern</dc:creator>
      <dc:date>2021-02-05T12:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384100#M1112</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70055"&gt;@tostern&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L2-Linker lia-component-message-view-widget-author-username"&gt;In my case my setup is with two interface Eth1/2 (Inside) &amp;amp; Eth1/3(Outside). So whenever I hit traffic from Outside server to Inside Server traffic logs should say Traffic from Out to In. which is not happening.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 05 Feb 2021 12:46:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384100#M1112</guid>
      <dc:creator>Sandeep_Darak</dc:creator>
      <dc:date>2021-02-05T12:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384369#M1114</link>
      <description>&lt;P&gt;I had a 3 interface setup working: GENEVE In/Out through eth1/1, then into eth1/2 -&amp;gt; NAT -&amp;gt; out of eth 1/3 to the ouetside.&lt;/P&gt;&lt;P&gt;Traffic would end up passing through the firewall twice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the other hand GWLB seems to break GP, so cannot run GP portal/Gateway on the outside interface.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Feb 2021 19:19:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384369#M1114</guid>
      <dc:creator>pkhavkine</dc:creator>
      <dc:date>2021-02-07T19:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384431#M1115</link>
      <description>&lt;P&gt;My design is as per below. Let me know if any issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Server-1 (Outside)==&amp;gt;TGW==&amp;gt;SecurityVPC==&amp;gt;GWLBe==&amp;gt;EndPoint Service==&amp;gt;GWLB==&amp;gt;PaloAlto Outside interface (Eth1/1)==&amp;gt;Pa Processing==&amp;gt;PaloAlto Inside interface(Eth1/2)==&amp;gt; Server-2 (Inside).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not using GP instead traffic is ping/ssh. Whenever i process the traffic from Outside to Inside traffic logs saying traffic outside to outside hence not matching correct policy and not processing.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 08:22:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384431#M1115</guid>
      <dc:creator>Sandeep_Darak</dc:creator>
      <dc:date>2021-02-08T08:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384510#M1116</link>
      <description>&lt;P&gt;At this time, GWLB deployments do not support routing outside of the GENEVE interface.&amp;nbsp; The traffic must hairpin back to the GWLB.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, there is a known issue with GP not working on a GWLB enabled firewall that will be resolved in a future release.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 16:07:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384510#M1116</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2021-02-08T16:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384530#M1117</link>
      <description>&lt;P&gt;Thanks for letting me know that it's a known issue with GP, any indication on when to expect a fix?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 18:05:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384530#M1117</guid>
      <dc:creator>pkhavkine</dc:creator>
      <dc:date>2021-02-08T18:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384533#M1118</link>
      <description>&lt;P&gt;It had not been committed to a version yet.&amp;nbsp; You should reach out to your SE to track the progress internally.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 18:08:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/384533#M1118</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2021-02-08T18:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/418513#M1255</link>
      <description>&lt;P&gt;I am also facing the same issue. PA somehow it sees&amp;nbsp;&lt;SPAN&gt;non-SYN packet and it drops it . If i&amp;nbsp;disable TCP reject non-SYN temporarily then the application works. Not sure why PA is dropping the packet or why it sees&amp;nbsp; non-SYN packet&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;the Inbound traffic pattern is&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internet -&amp;gt; ALB -&amp;gt; &lt;STRONG&gt;( GWLB&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;EndPoint Service -&amp;gt; GWLB -&amp;gt; PA FW -&amp;gt; GWLB -&amp;gt;&amp;nbsp;GWLB&amp;nbsp;EndPoint Service )&lt;/STRONG&gt; -&amp;gt; TGW -&amp;gt; Webserver&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 04:05:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/418513#M1255</guid>
      <dc:creator>EsakkimuthuGanesan</dc:creator>
      <dc:date>2021-07-12T04:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/427025#M1302</link>
      <description>&lt;P&gt;I thought i saw on 10.0.5 or 10.0.6 release notes that GWLB was working with overlay routing, is it still not fully functional?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 08:45:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/427025#M1302</guid>
      <dc:creator>craig.beamish</dc:creator>
      <dc:date>2021-08-16T08:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/429650#M1309</link>
      <description>&lt;P&gt;So now overlay routing is out and "functional" i've done more testing,&lt;BR /&gt;&lt;BR /&gt;Its only feasible for single direction flow:&lt;BR /&gt;&lt;BR /&gt;in &amp;gt; out&amp;nbsp;&lt;/P&gt;&lt;P&gt;or out &amp;gt; in&lt;BR /&gt;what ever interface has the VPC endpoints attached MUST be the interface for return traffic (i.e. VPCe Ethernet1/1.1, 'trust' network behind ethernet1/1)&lt;BR /&gt;&lt;BR /&gt;so reading the docs:&lt;BR /&gt;traffic comes in network client &amp;gt; GWLB &amp;gt; VPC endpoint &amp;gt; GENEVE int ethernet1/1.1 &amp;gt; egress eth1/2 &amp;gt; nat/IGW &amp;gt; server&lt;BR /&gt;return: server &amp;gt; in nat/igw &amp;gt; eth1/2 &amp;gt; ethernet1/1 &amp;gt; client&lt;BR /&gt;the docs indicate that return traffic does not egress the geneve sub interface but rather the normal physical interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can't have traffic come in eth1/1.1 and egress eth1/1 it just doesnt seem to work oddly.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 08:32:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/429650#M1309</guid>
      <dc:creator>craig.beamish</dc:creator>
      <dc:date>2021-08-27T08:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM Series Gateway Load Balancers not working</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/448333#M1388</link>
      <description>&lt;P&gt;Has anyone seen traffic coming on the ethernet1/1 interface instead on the subinterface. I'm running version 10.0.8 and it seems it happens randomly. Sometimes traffic appears coming from the private zone attached to the subinterfaces (which is mapped to the vpc endpoint) and some times the traffic appears on the Internal sec zone mapped to the ehternet1/1 interface.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 08:00:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-series-gateway-load-balancers-not-working/m-p/448333#M1388</guid>
      <dc:creator>DLeskov</dc:creator>
      <dc:date>2021-11-18T08:00:06Z</dc:date>
    </item>
  </channel>
</rss>

