<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA L2 interface ARP problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-l2-interface-arp-problem/m-p/446335#M100559</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/199155"&gt;@DiogoFG&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like a STP design issue.&amp;nbsp; A say "design" because STP is working, just not as you expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The interface shown by "show arp all" is there for convenience.&amp;nbsp; It is not resolved by ARP but rather reflects the L2 forwarding table of "show mac all".&lt;/LI&gt;&lt;LI&gt;The PA does not participate in STP, but rather forwards the BPDUs to assist in loop prevention.&amp;nbsp; So, the STP topology looks like SW1=SW2 (the = represents 2 links).&amp;nbsp; It sounds like once the SW1-PA link goes down, once it comes back up it stays in STP blocking mode.&amp;nbsp; You can confirm what port is in STP blocking mode on the switch.&lt;/LI&gt;&lt;LI&gt;You should design the blocked port according to desired traffic flow.&amp;nbsp; If you want the direct link between SW1 and SW2 to always be in blocking state (when all links are up), then adjust your STP cost or priority accordingly on SW1 or SW2.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Mon, 08 Nov 2021 22:47:41 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2021-11-08T22:47:41Z</dc:date>
    <item>
      <title>PA L2 interface ARP problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-l2-interface-arp-problem/m-p/446199#M100547</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a PA with two switches connected to the PA via L2 interface, in trunk. The same switches have a trunk between them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA---SW1&lt;/P&gt;&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;SW2--|&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So far so good, STP works and the network is stable. If one of the links between switch and PA falls (exemple PA to SW1) everything works too, all the traffic is redirect to PA via SW2, but as soon as link is became ok again, the Palo Alto ARP table does not refresh the Management VLAN and PA continues to think that the sw1 IP is seen by sw2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone felt this behavior?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2021 16:44:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-l2-interface-arp-problem/m-p/446199#M100547</guid>
      <dc:creator>DiogoFG</dc:creator>
      <dc:date>2021-11-08T16:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: PA L2 interface ARP problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-l2-interface-arp-problem/m-p/446320#M100556</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Do you have the PAN in HA, e.g. are there two of them? Also why have the two switches trunked?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2021 21:44:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-l2-interface-arp-problem/m-p/446320#M100556</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-11-08T21:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: PA L2 interface ARP problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-l2-interface-arp-problem/m-p/446335#M100559</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/199155"&gt;@DiogoFG&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like a STP design issue.&amp;nbsp; A say "design" because STP is working, just not as you expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The interface shown by "show arp all" is there for convenience.&amp;nbsp; It is not resolved by ARP but rather reflects the L2 forwarding table of "show mac all".&lt;/LI&gt;&lt;LI&gt;The PA does not participate in STP, but rather forwards the BPDUs to assist in loop prevention.&amp;nbsp; So, the STP topology looks like SW1=SW2 (the = represents 2 links).&amp;nbsp; It sounds like once the SW1-PA link goes down, once it comes back up it stays in STP blocking mode.&amp;nbsp; You can confirm what port is in STP blocking mode on the switch.&lt;/LI&gt;&lt;LI&gt;You should design the blocked port according to desired traffic flow.&amp;nbsp; If you want the direct link between SW1 and SW2 to always be in blocking state (when all links are up), then adjust your STP cost or priority accordingly on SW1 or SW2.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2021 22:47:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-l2-interface-arp-problem/m-p/446335#M100559</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-11-08T22:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: PA L2 interface ARP problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-l2-interface-arp-problem/m-p/446359#M100566</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes there are two of them, with HA in Acive-Passive configuration. The trunk between switches is for redundancy reasons.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 07:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-l2-interface-arp-problem/m-p/446359#M100566</guid>
      <dc:creator>DiogoFG</dc:creator>
      <dc:date>2021-11-09T07:59:54Z</dc:date>
    </item>
  </channel>
</rss>

