<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inbound Policy-Based Forwarding Issue - Intermittent loss of connectivity in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/inbound-policy-based-forwarding-issue-intermittent-loss-of/m-p/998042#M5221</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just an update:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Still, no progress from TAC (yes, 8 months).&lt;/P&gt;
&lt;P&gt;We have analyzed deeper and we are sure the issue is with PBFs Symmetric Return.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the issue:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Scenario when working:&lt;/P&gt;
&lt;P&gt;- Incoming packet comes from a non-default route ISP;&lt;/P&gt;
&lt;P&gt;- PBF fowards the packet to the correct server destination on an Internal network;&lt;/P&gt;
&lt;P&gt;- The server responds the packet;&lt;/P&gt;
&lt;P&gt;- The PBF Symmetric Return kicks in and sends the returning packet to the same incoming interface, and with the next hop defined;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Non-working Scenario:&lt;/P&gt;
&lt;P&gt;- Incoming packet comes from a non-default route ISP;&lt;/P&gt;
&lt;P&gt;- PBF fowards the packet to the correct server destination on an Internal network;&lt;/P&gt;
&lt;P&gt;- The server responds the packet;&lt;/P&gt;
&lt;P&gt;- The PBF Symmetric Return kicks in and sends the returning packet &lt;STRONG&gt;to the default route ISP&lt;/STRONG&gt;, and with the next hop defined;&amp;nbsp; ----&amp;gt;&amp;nbsp; &amp;nbsp;(Yes, the MAC Address destination of that packet is still the same as the working scenario)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We still did not identified any correlation that makes the issue happen. It does for a couple of minutes to an hour, and stops.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will update you further when TAC makes progress.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Dec 2024 12:11:14 GMT</pubDate>
    <dc:creator>LeoSalomao</dc:creator>
    <dc:date>2024-12-12T12:11:14Z</dc:date>
    <item>
      <title>Inbound Policy-Based Forwarding Issue - Intermittent loss of connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/inbound-policy-based-forwarding-issue-intermittent-loss-of/m-p/578097#M2686</link>
      <description>&lt;P&gt;&lt;FONT size="2"&gt;Hello,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Got a strange one, that I am hoping someone with deep knowledge of PBF and symmetric return can advise on.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;We have two (2) virtual-routers due to two different ISPs.&amp;nbsp; The history of it is we are migrating off of one ISP to finally decommission it.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Most of the internal DMZs are on VR1&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;New VR2 is the new ISP&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;We have eBGP between VRs using loopbacks to share hundreds of internal routes&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;We have multiple outbound PBFs rules pushing traffic out form VR1 to VR2, which&amp;nbsp;are zone type PBF rules&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;We have several inbound PBF rules, which are all interface type PBF rules pushing traffic to VR1 from VR2 all with Enforce Symmetric Return&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;One of these inbound services and PBF rules is intermittently failing.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Packet captures show :&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Client to server reaching the Palo Alto in VR2&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Palo Alto forwards that onto destination server in VR1 and applies the required NAT&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Server returns TCP-SYN-ACK data to Palo Alto&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;However Palo Alto does not send that TCP-SYN-ACKs to client and is seen in the drop captures&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;At this stage multiple TCP retransmissions ensure from both the client and server but are also dropped until a TCP RST is sent from the server, which again is dropped&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Session browser shows session is built and NAT and symmetric return flag checked&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;This is an intermittent issues last several hours.&amp;nbsp; Other inbound PBF rules and services do not seem to be affected.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;PA support are currently baffled and have not yet stumped up any real next steps.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;We moved from PA-3020s on 9.1.x back in Nov 2023 to new PA-5410s on 10.2.5 when this issue began.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Are there limits as to the number of PBF rules&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Are there limits to the number of outbound PBF rules and inbound rules&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;CPU showing as low at 5-10% on the data plane and session table is 39500 out of 5000000 at it's peak&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Health check on physical network through FW, switches and ISP infrastructure&amp;nbsp;shows as all clear, with no errors. (We would see errors&amp;nbsp;in other services that share this infrastructure)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Looking for any advise and advance cli commands that could help me troubleshoot this problem.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Regards&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 17:41:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/inbound-policy-based-forwarding-issue-intermittent-loss-of/m-p/578097#M2686</guid>
      <dc:creator>GrantCampbell4</dc:creator>
      <dc:date>2024-02-22T17:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound Policy-Based Forwarding Issue - Intermittent loss of connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/inbound-policy-based-forwarding-issue-intermittent-loss-of/m-p/578105#M2687</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/185420"&gt;@GrantCampbell4&lt;/a&gt;&amp;nbsp;- I am going to suggest raising a TAC case for this one; if you've seen the behaviour introduced between 9.1 and 10.2, and no other changes were made, a TAC case is the appropriate way forward.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 19:34:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/inbound-policy-based-forwarding-issue-intermittent-loss-of/m-p/578105#M2687</guid>
      <dc:creator>iarobertson</dc:creator>
      <dc:date>2024-02-22T19:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound Policy-Based Forwarding Issue - Intermittent loss of connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/inbound-policy-based-forwarding-issue-intermittent-loss-of/m-p/589842#M3328</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Having the same problem. In my case, the default route sends to another VSYS connected via a physical cable.&lt;BR /&gt;Normally, the PBF enforces the return to go thru the original ingress interface, but it is going thru the default route one, and for some reason, the SOURCE MAC address is the one the PBF enforces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a TAC oppened for more then two months, and they still did not find the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you gyus find a solution?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 18:30:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/inbound-policy-based-forwarding-issue-intermittent-loss-of/m-p/589842#M3328</guid>
      <dc:creator>LeoSalomao</dc:creator>
      <dc:date>2024-06-18T18:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound Policy-Based Forwarding Issue - Intermittent loss of connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/inbound-policy-based-forwarding-issue-intermittent-loss-of/m-p/998042#M5221</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just an update:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Still, no progress from TAC (yes, 8 months).&lt;/P&gt;
&lt;P&gt;We have analyzed deeper and we are sure the issue is with PBFs Symmetric Return.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the issue:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Scenario when working:&lt;/P&gt;
&lt;P&gt;- Incoming packet comes from a non-default route ISP;&lt;/P&gt;
&lt;P&gt;- PBF fowards the packet to the correct server destination on an Internal network;&lt;/P&gt;
&lt;P&gt;- The server responds the packet;&lt;/P&gt;
&lt;P&gt;- The PBF Symmetric Return kicks in and sends the returning packet to the same incoming interface, and with the next hop defined;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Non-working Scenario:&lt;/P&gt;
&lt;P&gt;- Incoming packet comes from a non-default route ISP;&lt;/P&gt;
&lt;P&gt;- PBF fowards the packet to the correct server destination on an Internal network;&lt;/P&gt;
&lt;P&gt;- The server responds the packet;&lt;/P&gt;
&lt;P&gt;- The PBF Symmetric Return kicks in and sends the returning packet &lt;STRONG&gt;to the default route ISP&lt;/STRONG&gt;, and with the next hop defined;&amp;nbsp; ----&amp;gt;&amp;nbsp; &amp;nbsp;(Yes, the MAC Address destination of that packet is still the same as the working scenario)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We still did not identified any correlation that makes the issue happen. It does for a couple of minutes to an hour, and stops.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will update you further when TAC makes progress.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 12:11:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/inbound-policy-based-forwarding-issue-intermittent-loss-of/m-p/998042#M5221</guid>
      <dc:creator>LeoSalomao</dc:creator>
      <dc:date>2024-12-12T12:11:14Z</dc:date>
    </item>
  </channel>
</rss>

