<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo alto sdwan dia Saas profile issue in Prisma SD-WAN Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/palo-alto-sdwan-dia-saas-profile-issue/m-p/998499#M225</link>
    <description>&lt;P&gt;Recently we have enabled SDWAN DIA setup in the firewall without the Panorama, all the routing and link switchover works fine as expected.&lt;/P&gt;
&lt;P&gt;However we ran into the issue now, we have saas profile probing cisco.com using https when the cisco.com was not reachable via both the ISP the saas profile active monitor went down, since the site was temporarily down for sometime, the internet traffic was not working using the default catch-all policy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;example policies:&lt;/P&gt;
&lt;P&gt;rule number - 1&lt;/P&gt;
&lt;P&gt;source address - project vlan&lt;/P&gt;
&lt;P&gt;source zone - trust&lt;/P&gt;
&lt;P&gt;destination address - any&lt;/P&gt;
&lt;P&gt;destination zone - untrust&lt;/P&gt;
&lt;P&gt;application - any&lt;/P&gt;
&lt;P&gt;path quality profile - general-web&lt;/P&gt;
&lt;P&gt;saas quality - cisco.com(https)&lt;/P&gt;
&lt;P&gt;traffic distribution - best path (two ISPs)&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rule 2:&lt;/P&gt;
&lt;P&gt;source address - any&lt;/P&gt;
&lt;P&gt;source zone - trust&lt;/P&gt;
&lt;P&gt;destination address - any&lt;/P&gt;
&lt;P&gt;destination zone - untrust&lt;/P&gt;
&lt;P&gt;application - any&lt;/P&gt;
&lt;P&gt;path quality profile - general-web&lt;/P&gt;
&lt;P&gt;saas quality - NA&lt;/P&gt;
&lt;P&gt;traffic distribution - best path (two ISPs)&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is there a way to bypass the sdwan policy to which the saas monitoring went down and choose the available policy for internet access&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: No issues at ISPs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Dec 2024 14:06:44 GMT</pubDate>
    <dc:creator>ranjith22</dc:creator>
    <dc:date>2024-12-16T14:06:44Z</dc:date>
    <item>
      <title>Palo alto sdwan dia Saas profile issue</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/palo-alto-sdwan-dia-saas-profile-issue/m-p/998499#M225</link>
      <description>&lt;P&gt;Recently we have enabled SDWAN DIA setup in the firewall without the Panorama, all the routing and link switchover works fine as expected.&lt;/P&gt;
&lt;P&gt;However we ran into the issue now, we have saas profile probing cisco.com using https when the cisco.com was not reachable via both the ISP the saas profile active monitor went down, since the site was temporarily down for sometime, the internet traffic was not working using the default catch-all policy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;example policies:&lt;/P&gt;
&lt;P&gt;rule number - 1&lt;/P&gt;
&lt;P&gt;source address - project vlan&lt;/P&gt;
&lt;P&gt;source zone - trust&lt;/P&gt;
&lt;P&gt;destination address - any&lt;/P&gt;
&lt;P&gt;destination zone - untrust&lt;/P&gt;
&lt;P&gt;application - any&lt;/P&gt;
&lt;P&gt;path quality profile - general-web&lt;/P&gt;
&lt;P&gt;saas quality - cisco.com(https)&lt;/P&gt;
&lt;P&gt;traffic distribution - best path (two ISPs)&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rule 2:&lt;/P&gt;
&lt;P&gt;source address - any&lt;/P&gt;
&lt;P&gt;source zone - trust&lt;/P&gt;
&lt;P&gt;destination address - any&lt;/P&gt;
&lt;P&gt;destination zone - untrust&lt;/P&gt;
&lt;P&gt;application - any&lt;/P&gt;
&lt;P&gt;path quality profile - general-web&lt;/P&gt;
&lt;P&gt;saas quality - NA&lt;/P&gt;
&lt;P&gt;traffic distribution - best path (two ISPs)&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is there a way to bypass the sdwan policy to which the saas monitoring went down and choose the available policy for internet access&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: No issues at ISPs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2024 14:06:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/palo-alto-sdwan-dia-saas-profile-issue/m-p/998499#M225</guid>
      <dc:creator>ranjith22</dc:creator>
      <dc:date>2024-12-16T14:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto sdwan dia Saas profile issue</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/palo-alto-sdwan-dia-saas-profile-issue/m-p/1086793#M231</link>
      <description>&lt;P&gt;Maybe it is better to change the rule order as to have the one without "&lt;SPAN&gt;saas quality&amp;nbsp;&lt;/SPAN&gt;" before the other that has the monitoring or you can just configure also an "&lt;SPAN&gt;application&lt;/SPAN&gt;" that matches the Cisco url, so the first rule to be more specific and not capture all rule.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 08:18:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/palo-alto-sdwan-dia-saas-profile-issue/m-p/1086793#M231</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2025-01-17T08:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto sdwan dia Saas profile issue</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/palo-alto-sdwan-dia-saas-profile-issue/m-p/1223422#M237</link>
      <description>&lt;P&gt;Maybe&amp;nbsp;You can create a policy that bypasses the SD-WAN path selection when the SaaS monitoring is down. This policy should be placed above the existing policies to ensure it takes precedence.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 08:41:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/palo-alto-sdwan-dia-saas-profile-issue/m-p/1223422#M237</guid>
      <dc:creator>VasanthK</dc:creator>
      <dc:date>2025-03-11T08:41:04Z</dc:date>
    </item>
  </channel>
</rss>

