<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS ALB/ALB Sandwich - issue with target group showing firewalls unhealthy (http - 80) in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-alb-alb-sandwich-issue-with-target-group-showing-firewalls/m-p/300946#M723</link>
    <description>&lt;P&gt;Are you using FQDN DNAT objects for NLB and ALB?&amp;nbsp; ALB IP addresses change more frequently which is why I mention the static configuration of the DNS servers.&amp;nbsp; Feel free to post your Route Table from the firewall for review.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Nov 2019 04:15:15 GMT</pubDate>
    <dc:creator>jmeurer</dc:creator>
    <dc:date>2019-11-27T04:15:15Z</dc:date>
    <item>
      <title>AWS ALB/ALB Sandwich - issue with target group showing firewalls unhealthy (http - 80)</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-alb-alb-sandwich-issue-with-target-group-showing-firewalls/m-p/300911#M719</link>
      <description>&lt;P&gt;Configuration in AWS&lt;BR /&gt;External ALB -&amp;gt; VM-series 300 (in 2 AZ) -&amp;gt; Internal ALB -&amp;gt;webserver&lt;BR /&gt;The target group of the external ALB shows unhealthy for port http/80&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;External NLB -&amp;gt;VM-series 300&amp;nbsp; (in 2 AZ)-&amp;gt; Internal NLB -&amp;gt; webserver&lt;BR /&gt;The target group of the external NLB shows healthy for port tcp/80 consistently&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why is the external ALB target group showing unhealthy ? randomly it goes healthy and then toggles&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security Groups are open to all on the untrusted interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 00:38:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-alb-alb-sandwich-issue-with-target-group-showing-firewalls/m-p/300911#M719</guid>
      <dc:creator>SatishNair</dc:creator>
      <dc:date>2019-11-27T00:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: AWS ALB/ALB Sandwich - issue with target group showing firewalls unhealthy (http - 80)</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-alb-alb-sandwich-issue-with-target-group-showing-firewalls/m-p/300935#M721</link>
      <description>&lt;P&gt;Watch your routes on the firewall.&amp;nbsp; The ALB fires its health probes cross zone.&amp;nbsp; If you are using DHCP on your interfaces, ensure that &lt;U&gt;only&lt;/U&gt; your Untrust interface is configured to import the Default route.&amp;nbsp; You will then want to put a static route for any internal subnets that are not directly connected to your Trust interface subnet pointing to the first IP of your trust subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additionally, change your management interface a static DNS server set to the second IP address of the VPC CIDR.&amp;nbsp; We had an issue in older versions of 8.1 where we were not importing the DHCP assigned DNS server.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 01:09:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-alb-alb-sandwich-issue-with-target-group-showing-firewalls/m-p/300935#M721</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2019-11-27T01:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: AWS ALB/ALB Sandwich - issue with target group showing firewalls unhealthy (http - 80)</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-alb-alb-sandwich-issue-with-target-group-showing-firewalls/m-p/300942#M722</link>
      <description>&lt;P&gt;The addresses are static and the default routes are correct. We use the transit gateway to connect to other accounts. In addition using an NLB in a sandwich mode works without issues.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 04:00:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-alb-alb-sandwich-issue-with-target-group-showing-firewalls/m-p/300942#M722</guid>
      <dc:creator>SatishNair</dc:creator>
      <dc:date>2019-11-27T04:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: AWS ALB/ALB Sandwich - issue with target group showing firewalls unhealthy (http - 80)</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-alb-alb-sandwich-issue-with-target-group-showing-firewalls/m-p/300946#M723</link>
      <description>&lt;P&gt;Are you using FQDN DNAT objects for NLB and ALB?&amp;nbsp; ALB IP addresses change more frequently which is why I mention the static configuration of the DNS servers.&amp;nbsp; Feel free to post your Route Table from the firewall for review.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 04:15:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-alb-alb-sandwich-issue-with-target-group-showing-firewalls/m-p/300946#M723</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2019-11-27T04:15:15Z</dc:date>
    </item>
  </channel>
</rss>

