<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packets dropped: forwarded to different zone in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/packets-dropped-forwarded-to-different-zone/m-p/573342#M2458</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SIP-ALG was already disabled, see screenshot below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vnkhwazi_0-1705504375272.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56583i5547BBFF856F438F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="vnkhwazi_0-1705504375272.png" alt="vnkhwazi_0-1705504375272.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jan 2024 15:13:11 GMT</pubDate>
    <dc:creator>vnkhwazi</dc:creator>
    <dc:date>2024-01-17T15:13:11Z</dc:date>
    <item>
      <title>Packets dropped: forwarded to different zone</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/packets-dropped-forwarded-to-different-zone/m-p/573304#M2450</link>
      <description>&lt;P&gt;We have a PaloAlto firewall that we have configured differrent zones, everything is working fine, except for a specific traffic between IP 10.40.129.49 and 172.26.2.58.&amp;nbsp; The 10.40.129.49 is located on a subnet directly in a zone defined on the firewall, 172.26.2.58 is a remote host over a WAN link going via another zone on the firewall.&amp;nbsp; Traffic to and from both IPs is reaching the firewall but does not get through it despite having a Policy that is allowing the traffic.&amp;nbsp; Upon doing further troubleshooting, it looks like the firewall is dropping the packets with a message that "&lt;STRONG&gt;Packets dropped: forwarded to different zone&lt;/STRONG&gt;"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See the test below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;vnkhwazi@PDC_EDGE_FW_P(active)&amp;gt; debug dataplane packet-diag set filter match source 10.40.129.49 destination 172.26.2.58&lt;/P&gt;
&lt;P&gt;vnkhwazi@PDC_EDGE_FW_P(active)&amp;gt; debug dataplane packet-diag set filter on&lt;/P&gt;
&lt;P&gt;debug packet filter: on&lt;BR /&gt;vnkhwazi@PDC_EDGE_FW_P(active)&amp;gt; show counter global filter packet-filter yes delta yes severity drop&lt;/P&gt;
&lt;P&gt;Global counters:&lt;BR /&gt;Elapsed time since last sampling: 19.244 seconds&lt;/P&gt;
&lt;P&gt;name&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;value&amp;nbsp; &amp;nbsp; &amp;nbsp; rate&amp;nbsp; &amp;nbsp; &amp;nbsp;severity&amp;nbsp; &amp;nbsp; &amp;nbsp; category&amp;nbsp; &amp;nbsp; &amp;nbsp;aspect&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; description&lt;BR /&gt;----------------------------------------------------------------------------------------------------&lt;BR /&gt;flow_fwd_zonechange&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 8&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; drop&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;flow&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; forward&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Packets dropped: forwarded to different zone&lt;BR /&gt;------------------------------------------------------------------------------------------------------&lt;BR /&gt;Total counters shown: 1&lt;BR /&gt;-------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What could be the cause of this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 10:22:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/packets-dropped-forwarded-to-different-zone/m-p/573304#M2450</guid>
      <dc:creator>vnkhwazi</dc:creator>
      <dc:date>2024-01-17T10:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: Packets dropped: forwarded to different zone</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/packets-dropped-forwarded-to-different-zone/m-p/573311#M2451</link>
      <description>&lt;P&gt;this is typically a routing problem (concentrated on the reply packets)&lt;/P&gt;
&lt;P&gt;some of the most common issues are&lt;/P&gt;
&lt;P&gt;-either you don't have routes for both subnets set to the right destination interface (connected subnets don't need that, remote do, subnets that are 'local' but don't have an IP on the firewall interface also need this)&lt;/P&gt;
&lt;P&gt;-or if you're using policy based forwarding, symmetric return was not enabled and reply packets are being sent out a different interface due to routing&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 11:29:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/packets-dropped-forwarded-to-different-zone/m-p/573311#M2451</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-01-17T11:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: Packets dropped: forwarded to different zone</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/packets-dropped-forwarded-to-different-zone/m-p/573323#M2455</link>
      <description>&lt;P&gt;i am able to ping between the two IPs, but SIP (UDP 5060) is the one failing.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 12:49:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/packets-dropped-forwarded-to-different-zone/m-p/573323#M2455</guid>
      <dc:creator>vnkhwazi</dc:creator>
      <dc:date>2024-01-17T12:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: Packets dropped: forwarded to different zone</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/packets-dropped-forwarded-to-different-zone/m-p/573335#M2456</link>
      <description>&lt;P&gt;aha&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;sip uses an ALG, maybe that's derailing the whole process&lt;/P&gt;
&lt;P&gt;try disabling the ALG by going to objects &amp;gt; applications, find sip and open it. on the right hand side you'll see the ALG&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_0-1705502427243.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56580iEE58604451B65B76/image-size/large?v=v2&amp;amp;px=999" role="button" title="reaper_0-1705502427243.png" alt="reaper_0-1705502427243.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 14:41:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/packets-dropped-forwarded-to-different-zone/m-p/573335#M2456</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-01-17T14:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: Packets dropped: forwarded to different zone</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/packets-dropped-forwarded-to-different-zone/m-p/573342#M2458</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SIP-ALG was already disabled, see screenshot below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vnkhwazi_0-1705504375272.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56583i5547BBFF856F438F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="vnkhwazi_0-1705504375272.png" alt="vnkhwazi_0-1705504375272.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 15:13:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/packets-dropped-forwarded-to-different-zone/m-p/573342#M2458</guid>
      <dc:creator>vnkhwazi</dc:creator>
      <dc:date>2024-01-17T15:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: Packets dropped: forwarded to different zone</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/packets-dropped-forwarded-to-different-zone/m-p/575069#M2543</link>
      <description>&lt;P&gt;then reverse my question &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;does it help if you enable the ALG?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 09:58:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/packets-dropped-forwarded-to-different-zone/m-p/575069#M2543</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-01-31T09:58:13Z</dc:date>
    </item>
  </channel>
</rss>

