<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues with Overlay Routing and AWS Gateway Load Balancer in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/511138#M1640</link>
    <description>&lt;P&gt;Just another thing to check, make sure you have&amp;nbsp;enabled the Appliance Mode feature on the Transit Gateway,&amp;nbsp;&lt;SPAN&gt;this feature ensures symmetric bidirectional traffic forwarding between VPC attachments. In other words, the forward and reverse flows are sent to the same firewall instance the same AZ for the lifetime of that flow. This allows firewalls to see both directions of the given flow thereby maintaining stateful traffic inspection capability inside Appliance VPC.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If the EC2 instances are deployed in two different VPCs in two different AZs. When the instances try to communicate with each other through AWS Transit Gateway with VPC attachments that are not in the same AZs results in asymmetric routing of packets. Forward flow and reverse flows from the same two communicating nodes, go to two different firewall instances in two different AZs, and the traffic is disrupted. This happens because, by default, when traffic is routed between VPC attachments, AWS Transit Gateway keeps the traffic in the same AZ where it originated until it reaches its destination.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Aug 2022 20:24:52 GMT</pubDate>
    <dc:creator>Mandanajan</dc:creator>
    <dc:date>2022-08-05T20:24:52Z</dc:date>
    <item>
      <title>Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/500206#M1573</link>
      <description>&lt;P&gt;Hey Folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am having difficulties to get Overlay routing working with AWS GWLB and I was wondering is it something that I am doing wrong or missing some configuration element...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any of you using AWS GWLB with overlay routing enabled?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my test setup when overlay routing is enabled the test VM is able to reach internet over the PAN FW - Outbound is working fine.&lt;/P&gt;
&lt;P&gt;But East-West between VPCs and Inbound traffic is not working. I can see traffic hitting the firewall, but allow traffic log show only byte send and no return traffic. Packet capture on the destination (for both east-west and inbound) doesn't show traffic to be arriving, so it looks like once FW inspect the packet and send back to GWLBe it doesn't send it in the correct direction.&lt;/P&gt;
&lt;P&gt;If overlay routing is disabled everything works - east-west, inbound and outbound.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found some old discussions mentioning issues with overlay routing, but from what I understand those know issues were for version 10.0.x, while we have tested with 10.2.1 and 10.1.6&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="NGFW" id="NGFW"&gt;&lt;/LI-PRODUCT&gt; &lt;LI-PRODUCT title="AWS" id="AWS"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 13:15:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/500206#M1573</guid>
      <dc:creator>A_Astardzhiev</dc:creator>
      <dc:date>2022-06-06T13:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/503889#M1580</link>
      <description>&lt;P&gt;Check the route table that is GWLB endpoint is located, and make sure you have a route back to your internal resources (your VPCs CIDRs)&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 17:44:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/503889#M1580</guid>
      <dc:creator>Mandanajan</dc:creator>
      <dc:date>2022-06-15T17:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/504116#M1582</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/49746"&gt;@Mandanajan&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Thank you for the suggestion, but I doubted the problem is in GWLBe route table. The reason for that is exact same setup (same GWLBe, same route table, everything works for East-West traffic the moment we have disabled route overlay. Also the outbound traffic works over the same GWLBe when overlay is enabled and I believe it wouldn't work if I was missing route for the VPC, right?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 08:28:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/504116#M1582</guid>
      <dc:creator>A_Astardzhiev</dc:creator>
      <dc:date>2022-06-16T08:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/508103#M1606</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@A_Astardzhiev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the same problem, if I disabled Overlay then my east/west traffic worked fine, but outbound did not. With overlay on, it's the reverse. I tried 2.1.4, 2.1.6 and 2.1.7 plugins no change. I am also running 10.1.6. I just downgraded to 10.1.5h1 and now it all works, maybe give that a shot.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 18:40:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/508103#M1606</guid>
      <dc:creator>justin.stone</dc:creator>
      <dc:date>2022-07-06T18:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/508183#M1610</link>
      <description>&lt;P&gt;Hi&amp;nbsp; &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/226156"&gt;@justin.stone&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;That is intersting. At least I know I am not insane...&lt;/P&gt;
&lt;P&gt;I think I had tried with 10.1.5...but can't remember if it was .5 or .5h1. Thanks I will give it a try.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2022 09:06:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/508183#M1610</guid>
      <dc:creator>A_Astardzhiev</dc:creator>
      <dc:date>2022-07-07T09:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/508570#M1612</link>
      <description>&lt;P&gt;We also: we have tried version 10.2.1 and downgraded to&amp;nbsp;&lt;SPAN&gt;10.1.6-h3 on AWS support advise, none work so far in.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have not disable overlay routing yet. But will first try&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;10.1.5h1 as a suggestion and take a look.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;BW&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 16:13:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/508570#M1612</guid>
      <dc:creator>Centogene</dc:creator>
      <dc:date>2022-07-12T16:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/509024#M1614</link>
      <description>&lt;P&gt;This is due to an existing bug which the team is actively working on.&amp;nbsp; 10.1.5-h5 does not have this issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Nidhi&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 06:06:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/509024#M1614</guid>
      <dc:creator>npandey</dc:creator>
      <dc:date>2022-07-15T06:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/509048#M1615</link>
      <description>&lt;P&gt;With 1 post to your name to say something is being fixed, and with all due respect: how do you know 'the team' (assume you mean Palo Alto dev) are actively working on it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you provide more detail please&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/214353"&gt;@npandey&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As we need an upgrade path into version 10.2 and beyond, and this bug (that is known) has not been fixed any any releases beyond 10.1.5-h5&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 08:19:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/509048#M1615</guid>
      <dc:creator>Centogene</dc:creator>
      <dc:date>2022-07-15T08:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/509053#M1616</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have come across this issue and the reason I got&amp;nbsp; tagged to this query. I have already raised this issue with the product team and that’s how I am aware about the Dev team looking into it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this is urgent and the customer is ok with NAT gateway, this could be a workaround otherwise we may have to wait for the fix to be officially available. If the customer needs a more official statement, please raise a TAC case.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 09:02:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/509053#M1616</guid>
      <dc:creator>npandey</dc:creator>
      <dc:date>2022-07-15T09:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/509198#M1618</link>
      <description>&lt;P&gt;What was the outcome of downgrading to 10.1.5h1?&amp;nbsp; I too am running 10.1.6-h3 and I have been banging my **bleep** head over this.&amp;nbsp; I have a firewall pair in another AWS region running 10.0.7 and this works perfectly but not in 10.1.6-h3 in my AWS region where I need it to work.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 17:19:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/509198#M1618</guid>
      <dc:creator>JHall15</dc:creator>
      <dc:date>2022-07-18T17:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/509204#M1619</link>
      <description>&lt;P&gt;FWIW I opened a tac case few weeks ago, and they confirmed that 10.1.6 had issues with gwlb, as well as 10.2.2&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 17:46:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/509204#M1619</guid>
      <dc:creator>justin.stone</dc:creator>
      <dc:date>2022-07-18T17:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/509272#M1621</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206353"&gt;@JHall15&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We went to 10.1.5-h5 and indeed this is the only Pan-OS revision &lt;STRONG&gt;that works&lt;/STRONG&gt;. So basically, if this is in production you have limited options that put your environment at risk due to the out of date firmware.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am opening up a TAC case as we need to add more weight to the issue to get this fixed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 11:20:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/509272#M1621</guid>
      <dc:creator>Centogene</dc:creator>
      <dc:date>2022-07-19T11:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/509306#M1625</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Updating this post - The fix for the issue is committed to 10.1.7 version.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Nidhi&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 16:46:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/509306#M1625</guid>
      <dc:creator>npandey</dc:creator>
      <dc:date>2022-07-19T16:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/509998#M1632</link>
      <description>&lt;P&gt;Just to say this issue has impacted me too after an upgrade to 10.2.2&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;It would be good to have a bug ID associate to this with some more information for what the root cause.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so far TAC only mention 10.1.7&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 23:22:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/509998#M1632</guid>
      <dc:creator>mohamedridha</dc:creator>
      <dc:date>2022-07-26T23:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/510016#M1633</link>
      <description>&lt;P&gt;We have the fix for the issue integrated in 10.1.7. do you still see the issue ?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 04:33:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/510016#M1633</guid>
      <dc:creator>npandey</dc:creator>
      <dc:date>2022-07-27T04:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/510026#M1634</link>
      <description>I don't see it released?&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Jul 2022 07:54:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/510026#M1634</guid>
      <dc:creator>mohamedridha</dc:creator>
      <dc:date>2022-07-27T07:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/510170#M1635</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/214353"&gt;@npandey&lt;/a&gt;&amp;nbsp;When is it released into the 10.2.x streams? 10.1.7 is out-of-date...&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2022 10:36:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/510170#M1635</guid>
      <dc:creator>Centogene</dc:creator>
      <dc:date>2022-07-28T10:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/510179#M1636</link>
      <description>&lt;P&gt;I still don't see any indication 10.1.7 has been released let alone anything new in 10.2.x.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2022 12:44:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/510179#M1636</guid>
      <dc:creator>JHall15</dc:creator>
      <dc:date>2022-07-28T12:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/511138#M1640</link>
      <description>&lt;P&gt;Just another thing to check, make sure you have&amp;nbsp;enabled the Appliance Mode feature on the Transit Gateway,&amp;nbsp;&lt;SPAN&gt;this feature ensures symmetric bidirectional traffic forwarding between VPC attachments. In other words, the forward and reverse flows are sent to the same firewall instance the same AZ for the lifetime of that flow. This allows firewalls to see both directions of the given flow thereby maintaining stateful traffic inspection capability inside Appliance VPC.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If the EC2 instances are deployed in two different VPCs in two different AZs. When the instances try to communicate with each other through AWS Transit Gateway with VPC attachments that are not in the same AZs results in asymmetric routing of packets. Forward flow and reverse flows from the same two communicating nodes, go to two different firewall instances in two different AZs, and the traffic is disrupted. This happens because, by default, when traffic is routed between VPC attachments, AWS Transit Gateway keeps the traffic in the same AZ where it originated until it reaches its destination.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 20:24:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/511138#M1640</guid>
      <dc:creator>Mandanajan</dc:creator>
      <dc:date>2022-08-05T20:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Overlay Routing and AWS Gateway Load Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/511139#M1641</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Appliance Mode is disabled by default on the VPC attachments in AWS Transit Gateway. For VPC-to-VPC traffic inspection through a Security VPC, you are required to enable Appliance Mode on the VPC attachment connected to the Security VPC. However, enabling Appliance Mode is optional for inspection of traffic originating from a spoke VPC destined to the Internet via dedicated Egress VPC.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 20:31:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/issues-with-overlay-routing-and-aws-gateway-load-balancer/m-p/511139#M1641</guid>
      <dc:creator>Mandanajan</dc:creator>
      <dc:date>2022-08-05T20:31:45Z</dc:date>
    </item>
  </channel>
</rss>

