<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SIP/RTP Traffic Issues in Palo Alto Active-Active vWire Setup Causing MAC Flapping In L3 devices in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sip-rtp-traffic-issues-in-palo-alto-active-active-vwire-setup/m-p/650846#M5067</link>
    <description>&lt;P&gt;&lt;SPAN&gt;In a Palo Alto Active-Active vWire setup, traffic entering a port on Device A is not supposed to egress from any port on Device B. The HA3 link is typically used to forward packets from the active-secondary device to the active-primary device for processing and evaluation against security policies. However, in your setup, you are observing that traffic—especially SIP and RTP traffic related to phone connectivity between clients and servers—sometimes enters the primary-active firewall, traverses the HA3 link, and then egresses from the secondary-active firewall. This behavior is causing MAC address flapping on the Layer 3 device connected to both firewalls.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To temporarily resolve this issue, I have to manually clear the inbound and outbound phone sessions from the secondary firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can some help me to understand where this issue might be.&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 23 Nov 2024 16:02:14 GMT</pubDate>
    <dc:creator>anthony.fernando83</dc:creator>
    <dc:date>2024-11-23T16:02:14Z</dc:date>
    <item>
      <title>SIP/RTP Traffic Issues in Palo Alto Active-Active vWire Setup Causing MAC Flapping In L3 devices</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sip-rtp-traffic-issues-in-palo-alto-active-active-vwire-setup/m-p/650846#M5067</link>
      <description>&lt;P&gt;&lt;SPAN&gt;In a Palo Alto Active-Active vWire setup, traffic entering a port on Device A is not supposed to egress from any port on Device B. The HA3 link is typically used to forward packets from the active-secondary device to the active-primary device for processing and evaluation against security policies. However, in your setup, you are observing that traffic—especially SIP and RTP traffic related to phone connectivity between clients and servers—sometimes enters the primary-active firewall, traverses the HA3 link, and then egresses from the secondary-active firewall. This behavior is causing MAC address flapping on the Layer 3 device connected to both firewalls.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To temporarily resolve this issue, I have to manually clear the inbound and outbound phone sessions from the secondary firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can some help me to understand where this issue might be.&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Nov 2024 16:02:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sip-rtp-traffic-issues-in-palo-alto-active-active-vwire-setup/m-p/650846#M5067</guid>
      <dc:creator>anthony.fernando83</dc:creator>
      <dc:date>2024-11-23T16:02:14Z</dc:date>
    </item>
  </channel>
</rss>

