<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Weak Path Affinity in Prisma SD-WAN Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/weak-path-affinity/m-p/1225541#M255</link>
    <description>&lt;P&gt;We're looking at some interesting issues around app shift between our Prisma Access tunnel and local/DC breakout. Session starts as SSL, gets pushed over the PA tunnel, gets reidentified as an app that is set to breakout locally and the ION duly changes path and breaks the session. Most apps/devices tolerate this fine, but some refuse to reattempt a new connection and thus are broken from the user perspective.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're looking at a few things, Path Affinity is one. The doco is pretty clear on how None and Strict work when configured in an App Override or Custom App, but looking at the predefined apps, many of them are set to Weak. But I can't find any explanation of what this default behaviour is, so can't really compare it to Strong. A full site search only gives a short summary from the API doco:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN class="openapi-schema__container"&gt;&lt;STRONG class="openapi-schema__property"&gt;path_affinity&lt;/STRONG&gt;&lt;SPAN class="openapi-schema__name"&gt;string&lt;/SPAN&gt;&lt;SPAN class="openapi-schema__required"&gt;required&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;This parameter defines the path affinity characteristics to consider during flow decision making. Allowed values: "none" "weak" "strict". If path affinity is none or weak and a better path is available, flows will be moved to a new path. If path affinity is strict, all application flows will continue on the same path.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Better than nothing, but also doesn't help much. Has anyone seen better doco, or done the experimenting to work out how Weak actually works compared to None?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(we have a TAC case open but it's a bit slow, this might be faster. Also aware the App Affinity might not be related to our issue if the Path Policy is higher precedence, but it's still a good knowledge gap to fill)&lt;/P&gt;</description>
    <pubDate>Thu, 03 Apr 2025 05:58:26 GMT</pubDate>
    <dc:creator>James.McCutcheon</dc:creator>
    <dc:date>2025-04-03T05:58:26Z</dc:date>
    <item>
      <title>Weak Path Affinity</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/weak-path-affinity/m-p/1225541#M255</link>
      <description>&lt;P&gt;We're looking at some interesting issues around app shift between our Prisma Access tunnel and local/DC breakout. Session starts as SSL, gets pushed over the PA tunnel, gets reidentified as an app that is set to breakout locally and the ION duly changes path and breaks the session. Most apps/devices tolerate this fine, but some refuse to reattempt a new connection and thus are broken from the user perspective.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're looking at a few things, Path Affinity is one. The doco is pretty clear on how None and Strict work when configured in an App Override or Custom App, but looking at the predefined apps, many of them are set to Weak. But I can't find any explanation of what this default behaviour is, so can't really compare it to Strong. A full site search only gives a short summary from the API doco:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN class="openapi-schema__container"&gt;&lt;STRONG class="openapi-schema__property"&gt;path_affinity&lt;/STRONG&gt;&lt;SPAN class="openapi-schema__name"&gt;string&lt;/SPAN&gt;&lt;SPAN class="openapi-schema__required"&gt;required&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;This parameter defines the path affinity characteristics to consider during flow decision making. Allowed values: "none" "weak" "strict". If path affinity is none or weak and a better path is available, flows will be moved to a new path. If path affinity is strict, all application flows will continue on the same path.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Better than nothing, but also doesn't help much. Has anyone seen better doco, or done the experimenting to work out how Weak actually works compared to None?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(we have a TAC case open but it's a bit slow, this might be faster. Also aware the App Affinity might not be related to our issue if the Path Policy is higher precedence, but it's still a good knowledge gap to fill)&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 05:58:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/weak-path-affinity/m-p/1225541#M255</guid>
      <dc:creator>James.McCutcheon</dc:creator>
      <dc:date>2025-04-03T05:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Weak Path Affinity</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/weak-path-affinity/m-p/1231818#M285</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153547"&gt;@James.McCutcheon&lt;/a&gt;&amp;nbsp; any info from the SOC as ION devices nowadays utlize the same app database as Palo Alto NGFW but on the NGFW you can see&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm1aCAC" target="_blank"&gt;How to Prevent Application Shift - Knowledge Base - Palo Alto Networks&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/handling-of-and-awareness-of-app-id-shifts-or-new-releases/td-p/568136" target="_blank"&gt;LIVEcommunity - Handling of and Awareness of APP-ID shifts or new releases - LIVEcommunity - 568136&lt;/A&gt;&amp;nbsp;while ION devices seem more limited.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 08:50:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/weak-path-affinity/m-p/1231818#M285</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2025-06-16T08:50:44Z</dc:date>
    </item>
  </channel>
</rss>

