<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SD-WAN Issue: Some Traffic Not Matching the Expected Policy in Advanced SD-WAN for NGFW Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-sd-wan-for-ngfw/sd-wan-issue-some-traffic-not-matching-the-expected-policy/m-p/1234870#M40</link>
    <description>&lt;P&gt;I'm having the same problem. Based on the traffic log&amp;nbsp;I can see sessions without any SDWAN policy, empty value on that field.&lt;BR /&gt;Traffic applications are more than one, like ssl, quic or ms-office365-base and sessions are with KBs of traffic (so&amp;nbsp;enough traffic passed on the firewall) and session end reason is TCP-FIN.&lt;BR /&gt;How that is possible?&amp;nbsp;&lt;BR /&gt;I have at the bottom a CatchALL SDWAN policy that MUST match ALL traffic.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jul 2025 10:07:20 GMT</pubDate>
    <dc:creator>davidemoro86</dc:creator>
    <dc:date>2025-07-29T10:07:20Z</dc:date>
    <item>
      <title>SD-WAN Issue: Some Traffic Not Matching the Expected Policy</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-sd-wan-for-ngfw/sd-wan-issue-some-traffic-not-matching-the-expected-policy/m-p/1224905#M28</link>
      <description>&lt;P class="" data-start="142" data-end="159"&gt;Hello everyone,&lt;/P&gt;
&lt;P class="" data-start="161" data-end="227"&gt;I’m facing an issue with Palo Alto SD-WAN on Panorama (FW PA-1440).&lt;/P&gt;
&lt;P class="" data-start="229" data-end="541"&gt;I created an SD-WAN rule to direct traffic for the &lt;STRONG data-start="280" data-end="293"&gt;ms-update&lt;/STRONG&gt; application through a specific WAN link. However, when I check the traffic monitor using an &lt;STRONG data-start="386" data-end="399"&gt;ms-update&lt;/STRONG&gt; filter, I notice that some packets match the &lt;STRONG data-start="445" data-end="468"&gt;"unmatched session"&lt;/STRONG&gt; policy, while others correctly match my &lt;STRONG data-start="509" data-end="531"&gt;"Update Microsoft"&lt;/STRONG&gt; policy.&lt;/P&gt;
&lt;P class="" data-start="543" data-end="628"&gt;Could someone explain why this is happening or guide me on how to debug this issue?&lt;/P&gt;
&lt;P class="" data-start="630" data-end="650"&gt;Thanks in advance!&lt;/P&gt;
&lt;P class="" data-start="652" data-end="667"&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 17:39:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-sd-wan-for-ngfw/sd-wan-issue-some-traffic-not-matching-the-expected-policy/m-p/1224905#M28</guid>
      <dc:creator>R.BONY</dc:creator>
      <dc:date>2025-04-07T17:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN Issue: Some Traffic Not Matching the Expected Policy</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-sd-wan-for-ngfw/sd-wan-issue-some-traffic-not-matching-the-expected-policy/m-p/1225001#M30</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1620085473"&gt;@R.BONY&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please keep in mind App-ID requires some packets before the identification is accurate.&lt;/P&gt;
&lt;P&gt;If you want to confirm that is the cause, you can set the logging at start (for the policies which may allow the initial packet), then in the traffic logs, for a ms-update ended session, you search the corresponding start log to see what app-id that was.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Fri, 28 Mar 2025 09:15:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-sd-wan-for-ngfw/sd-wan-issue-some-traffic-not-matching-the-expected-policy/m-p/1225001#M30</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2025-03-28T09:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN Issue: Some Traffic Not Matching the Expected Policy</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-sd-wan-for-ngfw/sd-wan-issue-some-traffic-not-matching-the-expected-policy/m-p/1225184#M32</link>
      <description>&lt;P class="" data-start="47" data-end="70"&gt;Thanks for the reply,&lt;/P&gt;
&lt;P class="" data-start="72" data-end="173"&gt;I set logging at the start, and the traffic logs look fine they match "ms-update" at the beginning.&lt;/P&gt;
&lt;P class="" data-start="175" data-end="398"&gt;This is very strange because, in the Session Browser, the Palo Alto firewall identifies the traffic as "ms-update," and the egress interface is my SD-WAN interface. However, it does not apply my SD-WAN policy as expected.&lt;/P&gt;
&lt;P class="" data-start="175" data-end="398"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="175" data-end="398"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 08:54:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-sd-wan-for-ngfw/sd-wan-issue-some-traffic-not-matching-the-expected-policy/m-p/1225184#M32</guid>
      <dc:creator>R.BONY</dc:creator>
      <dc:date>2025-03-31T08:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN Issue: Some Traffic Not Matching the Expected Policy</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-sd-wan-for-ngfw/sd-wan-issue-some-traffic-not-matching-the-expected-policy/m-p/1225850#M34</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;Has anyone managed to get SD-WAN traffic working with the application tag 'ms-update'?&lt;/P&gt;
&lt;P&gt;I still don't understand why the rule isn't matching. Maybe I should work with a rule based on the IP instead of the application?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 15:15:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-sd-wan-for-ngfw/sd-wan-issue-some-traffic-not-matching-the-expected-policy/m-p/1225850#M34</guid>
      <dc:creator>R.BONY</dc:creator>
      <dc:date>2025-04-07T15:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN Issue: Some Traffic Not Matching the Expected Policy</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-sd-wan-for-ngfw/sd-wan-issue-some-traffic-not-matching-the-expected-policy/m-p/1230885#M36</link>
      <description>&lt;P&gt;Having the same problem here with ms-update app and even with O365 tagged apps. I have a pair of SD-WAN policies pointing to Prisma tunnels and DIA links respectively and I want to steer traffic from some MSF apps to the former ones and sometimes it does it the right way, other times not, even recognizing the same app....Not understanding the reason of that behaviour.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 14:37:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-sd-wan-for-ngfw/sd-wan-issue-some-traffic-not-matching-the-expected-policy/m-p/1230885#M36</guid>
      <dc:creator>Ivan_PA1983</dc:creator>
      <dc:date>2025-06-03T14:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN Issue: Some Traffic Not Matching the Expected Policy</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-sd-wan-for-ngfw/sd-wan-issue-some-traffic-not-matching-the-expected-policy/m-p/1234870#M40</link>
      <description>&lt;P&gt;I'm having the same problem. Based on the traffic log&amp;nbsp;I can see sessions without any SDWAN policy, empty value on that field.&lt;BR /&gt;Traffic applications are more than one, like ssl, quic or ms-office365-base and sessions are with KBs of traffic (so&amp;nbsp;enough traffic passed on the firewall) and session end reason is TCP-FIN.&lt;BR /&gt;How that is possible?&amp;nbsp;&lt;BR /&gt;I have at the bottom a CatchALL SDWAN policy that MUST match ALL traffic.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2025 10:07:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-sd-wan-for-ngfw/sd-wan-issue-some-traffic-not-matching-the-expected-policy/m-p/1234870#M40</guid>
      <dc:creator>davidemoro86</dc:creator>
      <dc:date>2025-07-29T10:07:20Z</dc:date>
    </item>
  </channel>
</rss>

