<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Rule UUID mismatch in Policies and Traffic Logs/Discrepancy in Rule UUIDs within Traffic Logs and Policy in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/rule-uuid-mismatch-in-policies-and-traffic-logs-discrepancy-in/m-p/585189#M3069</link>
    <description>&lt;P&gt;Dear Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have 2 * PA-5250 Firewall Appliances configured in Active-Passive and managed by Panorama. PANOS version on both the firewalls and Panorama is PANOS: 10.1.12.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I've noticed an inconsistency where the Rule UUID displayed in the Traffic Logs differs from the one shown in the actual Policy. Additionally, the Traffic Logs are associating multiple Rule UUIDs with a single rule. Excluding the correct UUID, various other UUIDs are appearing in the Traffic Logs.&lt;/P&gt;
&lt;P&gt;Furthermore, when filtering the Traffic Logs by the correct Rule UUID, no traffic is displayed. However, if I filter by the rule name, traffic logs appear but with alternate UUIDs.&lt;/P&gt;
&lt;P&gt;This issue is with the Active Firewall only while there is no issue in the Passive firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Rule UUID in Policy&lt;/STRONG&gt;:&amp;nbsp;48d8f35d-e9c9-4bed-9bc9-75317067bf7e&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Rule UUID in Traffic logs&lt;/STRONG&gt;:&amp;nbsp;7d379199-cccf-42ad-9979-2017e5a959d1&lt;BR /&gt;3c79c2c6-88e5-41cd-bc65-99d7b865d63f&lt;BR /&gt;e401849b-4eb2-4153-beb4-4d5f3c171048&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Apr 2024 09:17:32 GMT</pubDate>
    <dc:creator>mohit-singhal</dc:creator>
    <dc:date>2024-04-29T09:17:32Z</dc:date>
    <item>
      <title>Rule UUID mismatch in Policies and Traffic Logs/Discrepancy in Rule UUIDs within Traffic Logs and Policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/rule-uuid-mismatch-in-policies-and-traffic-logs-discrepancy-in/m-p/585189#M3069</link>
      <description>&lt;P&gt;Dear Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have 2 * PA-5250 Firewall Appliances configured in Active-Passive and managed by Panorama. PANOS version on both the firewalls and Panorama is PANOS: 10.1.12.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I've noticed an inconsistency where the Rule UUID displayed in the Traffic Logs differs from the one shown in the actual Policy. Additionally, the Traffic Logs are associating multiple Rule UUIDs with a single rule. Excluding the correct UUID, various other UUIDs are appearing in the Traffic Logs.&lt;/P&gt;
&lt;P&gt;Furthermore, when filtering the Traffic Logs by the correct Rule UUID, no traffic is displayed. However, if I filter by the rule name, traffic logs appear but with alternate UUIDs.&lt;/P&gt;
&lt;P&gt;This issue is with the Active Firewall only while there is no issue in the Passive firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Rule UUID in Policy&lt;/STRONG&gt;:&amp;nbsp;48d8f35d-e9c9-4bed-9bc9-75317067bf7e&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Rule UUID in Traffic logs&lt;/STRONG&gt;:&amp;nbsp;7d379199-cccf-42ad-9979-2017e5a959d1&lt;BR /&gt;3c79c2c6-88e5-41cd-bc65-99d7b865d63f&lt;BR /&gt;e401849b-4eb2-4153-beb4-4d5f3c171048&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 09:17:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/rule-uuid-mismatch-in-policies-and-traffic-logs-discrepancy-in/m-p/585189#M3069</guid>
      <dc:creator>mohit-singhal</dc:creator>
      <dc:date>2024-04-29T09:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: Rule UUID mismatch in Policies and Traffic Logs/Discrepancy in Rule UUIDs within Traffic Logs and Policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/rule-uuid-mismatch-in-policies-and-traffic-logs-discrepancy-in/m-p/585249#M3074</link>
      <description>&lt;P&gt;Hello Friend!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;&lt;SPAN&gt;When rules are pushed from Panorama, they will all have the same UUID. However, rules created locally on a firewall will each have their own unique UUID. If you create a rule on a firewall after pushing rules from Panorama, the locally created rule will have its own UUID.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;On the following Doc you can learn more about this: &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/enumeration-of-rules-within-a-rulebase" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/enumeration-of-rules-within-a-rulebase&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Mark my comment as solved if you think this solves your query&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 19:50:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/rule-uuid-mismatch-in-policies-and-traffic-logs-discrepancy-in/m-p/585249#M3074</guid>
      <dc:creator>jfernandez1</dc:creator>
      <dc:date>2024-04-29T19:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: Rule UUID mismatch in Policies and Traffic Logs/Discrepancy in Rule UUIDs within Traffic Logs and Policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/rule-uuid-mismatch-in-policies-and-traffic-logs-discrepancy-in/m-p/585263#M3075</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Jfernandez1,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for your response. I am aware about this concept, but the issue is not related to this.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Let me rephrase the issue:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For Example: &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Rule Name:&lt;/STRONG&gt; xyz/abc (Pushed from Panorama to the HA pair (Active/Passive).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Rule UUID visible in the Policy in both the Firewalls:&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;48d8f35d-e9c9-4bed-9bc9-75317067bf7e&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Rule UUIDs visible in the Traffic logs for the same rule in the Active Firewall only&lt;/STRONG&gt;:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;7d379199-cccf-42ad-9979-2017e5a959d1&lt;BR /&gt;3c79c2c6-88e5-41cd-bc65-99d7b865d63f&lt;BR /&gt;e401849b-4eb2-4153-beb4-4d5f3c171048&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem is exclusive to the Active Firewall; the Passive Firewall is functioning without any issues.&lt;/P&gt;
&lt;P&gt;Issue is with all the rules configured in Active Firewall not with the specific rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I trust this clarification explained the issue clearly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 00:44:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/rule-uuid-mismatch-in-policies-and-traffic-logs-discrepancy-in/m-p/585263#M3075</guid>
      <dc:creator>mohit-singhal</dc:creator>
      <dc:date>2024-04-30T00:44:32Z</dc:date>
    </item>
  </channel>
</rss>

