<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After an upgrade to version 10.2.3 h4 I got this message:    2023/03/08 20:52:23 info     general        general 0  Received conflicting ARP on in in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/after-an-upgrade-to-version-10-2-3-h4-i-got-this-message-2023-03/m-p/534635#M1025</link>
    <description>&lt;P&gt;In VMware environment you can't have 2 VMs with same mac address.&lt;/P&gt;
&lt;P&gt;For that reason virtual Palos in HA cluster have different mac addresses.&lt;/P&gt;
&lt;P&gt;Virtual Palos can have same mac only if VMware port group is configured in p&lt;SPAN&gt;romiscuous&amp;nbsp;mode and this is very bad practice.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But to receive conflicting IP address alert both of your firewalls must be active at the same time.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do you have active/passive HA?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Mar 2023 03:36:40 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2023-03-16T03:36:40Z</dc:date>
    <item>
      <title>After an upgrade to version 10.2.3 h4 I got this message:    2023/03/08 20:52:23 info     general        general 0  Received conflicting ARP on interf</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/after-an-upgrade-to-version-10-2-3-h4-i-got-this-message-2023-03/m-p/534490#M1024</link>
      <description>&lt;P&gt;After an upgrade to version 10.2.3 h4 I got this message:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2023/03/08 20:52:23 info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; general&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; general 0&amp;nbsp; Received conflicting ARP on interface ethernet1/4 indicating duplicate IP 172.16.0.1, sender mac 00:50:56:92:cd:0c&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And this address is for the other peer .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The firewall is a VM300&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 16:26:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/after-an-upgrade-to-version-10-2-3-h4-i-got-this-message-2023-03/m-p/534490#M1024</guid>
      <dc:creator>yassinehounaihi</dc:creator>
      <dc:date>2023-03-15T16:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: After an upgrade to version 10.2.3 h4 I got this message:    2023/03/08 20:52:23 info     general        general 0  Received conflicting ARP on in</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/after-an-upgrade-to-version-10-2-3-h4-i-got-this-message-2023-03/m-p/534635#M1025</link>
      <description>&lt;P&gt;In VMware environment you can't have 2 VMs with same mac address.&lt;/P&gt;
&lt;P&gt;For that reason virtual Palos in HA cluster have different mac addresses.&lt;/P&gt;
&lt;P&gt;Virtual Palos can have same mac only if VMware port group is configured in p&lt;SPAN&gt;romiscuous&amp;nbsp;mode and this is very bad practice.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But to receive conflicting IP address alert both of your firewalls must be active at the same time.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do you have active/passive HA?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 03:36:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/after-an-upgrade-to-version-10-2-3-h4-i-got-this-message-2023-03/m-p/534635#M1025</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-03-16T03:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: After an upgrade to version 10.2.3 h4 I got this message:    2023/03/08 20:52:23 info     general        general 0  Received conflicting ARP on in</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/after-an-upgrade-to-version-10-2-3-h4-i-got-this-message-2023-03/m-p/534653#M1026</link>
      <description>&lt;P&gt;Yes the two firewalls in HA.&lt;/P&gt;
&lt;P&gt;address and mac for the other peer .&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 07:33:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/after-an-upgrade-to-version-10-2-3-h4-i-got-this-message-2023-03/m-p/534653#M1026</guid>
      <dc:creator>yassinehounaihi</dc:creator>
      <dc:date>2023-03-16T07:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: After an upgrade to version 10.2.3 h4 I got this message:    2023/03/08 20:52:23 info     general        general 0  Received conflicting ARP on in</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/after-an-upgrade-to-version-10-2-3-h4-i-got-this-message-2023-03/m-p/534706#M1027</link>
      <description>&lt;P&gt;Are firewalls in active/active or active/passive HA?&lt;/P&gt;
&lt;P&gt;If you enable mac column in both firewalls do mac addresses match on both of them or are they different?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1678970353596.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48830i64075F3473A11BBD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1678970353596.png" alt="Raido_Rattameister_0-1678970353596.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 12:39:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/after-an-upgrade-to-version-10-2-3-h4-i-got-this-message-2023-03/m-p/534706#M1027</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-03-16T12:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: After an upgrade to version 10.2.3 h4 I got this message:    2023/03/08 20:52:23 info     general        general 0  Received conflicting ARP on in</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/after-an-upgrade-to-version-10-2-3-h4-i-got-this-message-2023-03/m-p/534709#M1028</link>
      <description>&lt;P&gt;HA in active passive .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will find below the configuration of the interfaces as well as the message on the two firewalls :&lt;/P&gt;
&lt;P&gt;========================================================&lt;/P&gt;
&lt;P&gt;FW1&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; show interface all&lt;/P&gt;
&lt;P&gt;total configured hardware interfaces: 9&lt;/P&gt;
&lt;P&gt;name id speed/duplex/state mac address &lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;ethernet1/1 16 ukn/ukn/down(power-down) 00:50:56:92:82:af &lt;BR /&gt;ethernet1/2 17 10000/full/up 00:50:56:92:7e:bc &lt;BR /&gt;ethernet1/3 18 10000/full/up 00:50:56:92:20:2f &lt;BR /&gt;ethernet1/4 19 10000/full/up 00:50:56:92:cd:0c &lt;BR /&gt;ethernet1/5 20 10000/full/up 00:50:56:92:f7:49 &lt;BR /&gt;ethernet1/6 21 10000/full/up 00:50:56:92:2f:36 &lt;BR /&gt;ethernet1/7 22 10000/full/up 00:50:56:92:ae:b6 &lt;BR /&gt;ethernet1/8 23 10000/full/up 00:50:56:92:77:3a &lt;BR /&gt;ethernet1/9 24 ukn/ukn/down(autoneg) 00:50:56:92:5e:a5&lt;/P&gt;
&lt;P&gt;aggregation groups: 0&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;total configured logical interfaces: 9&lt;/P&gt;
&lt;P&gt;name id vsys zone forwarding tag address &lt;BR /&gt;------------------- ----- ---- ---------------- ------------------------ ------ ------------------&lt;BR /&gt;ethernet1/1 16 1 tap 0 N/A &lt;BR /&gt;ethernet1/2 17 1 ha 0 192.168.1.67/24 &lt;BR /&gt;ethernet1/3 18 1 ha 0 192.168.2.67/24 &lt;BR /&gt;ethernet1/4 19 1 GUEST_LAN vr:DMZ_WIFI_ROUTEUR 0 172.16.0.1/21 &lt;BR /&gt;ethernet1/5 20 1 DMZ_INTERNET vr:DMZ_WIFI_ROUTEUR 0 90.83.58.124/25 &lt;BR /&gt;ethernet1/6 21 1 VRF_GUEST vr:DMZ_WIFI_ROUTEUR 0 10.109.32.250/32 &lt;BR /&gt;ethernet1/7 22 1 DMZ_SORTANTES vr:DMZ_WIFI_ROUTEUR 0 192.168.215.47/24 &lt;BR /&gt;ethernet1/8 23 1 GUEST_LAN vr:DMZ_WIFI_ROUTEUR 0 172.16.8.1/22 &lt;BR /&gt;ethernet1/9 24 1 tap 0 N/A&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error message :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;============================================&lt;/P&gt;
&lt;P&gt;2023/03/08 20:52:01 info general general 0 Received conflicting ARP on interface ethernet1/4 indicating duplicate IP 172.16.0.1, sender mac 00:50:56:a5:bc:3b&lt;/P&gt;
&lt;P&gt;==========================================&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FW2&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;=================================================&lt;/P&gt;
&lt;P&gt;&amp;gt; show interface all&lt;/P&gt;
&lt;P&gt;total configured hardware interfaces: 9&lt;/P&gt;
&lt;P&gt;name id speed/duplex/state mac address &lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;ethernet1/1 16 ukn/ukn/down(power-down) 00:50:56:a5:9b:91 &lt;BR /&gt;ethernet1/2 17 10000/full/up 00:50:56:a5:79:47 &lt;BR /&gt;ethernet1/3 18 10000/full/up 00:50:56:a5:b1:ca &lt;BR /&gt;ethernet1/4 19 10000/full/up 00:50:56:a5:bc:3b &lt;BR /&gt;ethernet1/5 20 10000/full/up 00:50:56:a5:0d:e4 &lt;BR /&gt;ethernet1/6 21 10000/full/up 00:50:56:a5:51:9b &lt;BR /&gt;ethernet1/7 22 10000/full/up 00:50:56:a5:5c:c5 &lt;BR /&gt;ethernet1/8 23 10000/full/up 00:50:56:a5:63:9a &lt;BR /&gt;ethernet1/9 24 ukn/ukn/down(autoneg) 00:50:56:a5:de:f0&lt;/P&gt;
&lt;P&gt;aggregation groups: 0&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;total configured logical interfaces: 9&lt;/P&gt;
&lt;P&gt;name id vsys zone forwarding tag address &lt;BR /&gt;------------------- ----- ---- ---------------- ------------------------ ------ ------------------&lt;BR /&gt;ethernet1/1 16 1 tap 0 N/A &lt;BR /&gt;ethernet1/2 17 1 ha 0 192.168.1.68/24 &lt;BR /&gt;ethernet1/3 18 1 ha 0 192.168.2.68/24 &lt;BR /&gt;ethernet1/4 19 1 GUEST_LAN vr:DMZ_WIFI_ROUTEUR 0 172.16.0.1/21 &lt;BR /&gt;ethernet1/5 20 1 DMZ_INTERNET vr:DMZ_WIFI_ROUTEUR 0 90.83.58.124/25 &lt;BR /&gt;ethernet1/6 21 1 VRF_GUEST vr:DMZ_WIFI_ROUTEUR 0 10.109.32.250/32 &lt;BR /&gt;ethernet1/7 22 1 DMZ_SORTANTES vr:DMZ_WIFI_ROUTEUR 0 192.168.215.47/24 &lt;BR /&gt;ethernet1/8 23 1 GUEST_LAN vr:DMZ_WIFI_ROUTEUR 0 172.16.8.1/22 &lt;BR /&gt;ethernet1/9 24 1 tap 0 N/A&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;===========================================&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error message&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;========================================&lt;/P&gt;
&lt;P&gt;2023/03/08 20:52:23 info general general 0 Received conflicting ARP on interface ethernet1/4 indicating duplicate IP 172.16.0.1, sender mac 00:50:56:92:cd:0c&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;======================================================================&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 12:58:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/after-an-upgrade-to-version-10-2-3-h4-i-got-this-message-2023-03/m-p/534709#M1028</guid>
      <dc:creator>yassinehounaihi</dc:creator>
      <dc:date>2023-03-16T12:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: After an upgrade to version 10.2.3 h4 I got this message:    2023/03/08 20:52:23 info     general        general 0  Received conflicting ARP on in</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/after-an-upgrade-to-version-10-2-3-h4-i-got-this-message-2023-03/m-p/534710#M1029</link>
      <description>&lt;P&gt;Did you get arp conflict once during upgrade or are you continuously getting those alerts?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 13:12:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/after-an-upgrade-to-version-10-2-3-h4-i-got-this-message-2023-03/m-p/534710#M1029</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-03-16T13:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: After an upgrade to version 10.2.3 h4 I got this message:    2023/03/08 20:52:23 info     general        general 0  Received conflicting ARP on in</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/after-an-upgrade-to-version-10-2-3-h4-i-got-this-message-2023-03/m-p/534711#M1030</link>
      <description>&lt;P&gt;We still have the error message, I turned off one of the firewall so as not to impact the production&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 13:19:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/after-an-upgrade-to-version-10-2-3-h4-i-got-this-message-2023-03/m-p/534711#M1030</guid>
      <dc:creator>yassinehounaihi</dc:creator>
      <dc:date>2023-03-16T13:19:49Z</dc:date>
    </item>
  </channel>
</rss>

