<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bypassing &amp;quot;Packets dropped: forwarded to different zone&amp;quot; limitation in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/bypassing-quot-packets-dropped-forwarded-to-different-zone-quot/m-p/447898#M100757</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What are you gaining from this granularity? Does the benefits you will gain deserve adding such complexity?&lt;/P&gt;
&lt;P&gt;Don't get wrong - as I said I haven't work with such setup and I am insteresed in the motives and are there any other acceptable solutions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was hoping for the asymetric pass to do the trick...It is very unlickly, but are you applying any IP spoofing protection with the zone-protection profile?&lt;/P&gt;</description>
    <pubDate>Tue, 16 Nov 2021 09:47:08 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2021-11-16T09:47:08Z</dc:date>
    <item>
      <title>Bypassing "Packets dropped: forwarded to different zone" limitation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypassing-quot-packets-dropped-forwarded-to-different-zone-quot/m-p/446128#M100538</link>
      <description>&lt;P&gt;Dear community!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I´d like to consult with you for a possible solution for this scenario:&lt;/P&gt;&lt;P&gt;We have 2 internet lines&amp;nbsp;from two interfaces of the PAN firewall connected to two different routers. Each interface is in a different zone.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;When incoming and returning packets follow different paths then we have an asymmetric routing condition. Situation similar to this one:&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClReCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClReCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We configured the firewall to bypass the non-SYN-TCP check but we still have packets dropped with counter "Packets dropped: forwarded to different zone"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having both external interfaces in the same zone fixes the issue but we´d like to have them in different zones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A possible workaround could be using a PBF as in this article: &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF5CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF5CAK&lt;/A&gt;&lt;BR /&gt;But this is also not an option because the return mac entries supported is not big enough for all the incoming sessions, meaning the firewall will drop new sessions when table is full.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;+ Is there a workaround to bypass the "Packets dropped: forwarded to different zone" counter and allow the firewall to forward s2c traffic to a different zone?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2021 10:43:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypassing-quot-packets-dropped-forwarded-to-different-zone-quot/m-p/446128#M100538</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2021-11-08T10:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing "Packets dropped: forwarded to different zone" limitation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypassing-quot-packets-dropped-forwarded-to-different-zone-quot/m-p/446458#M100574</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I saw the same behavior with an A/A HA-setup.&amp;nbsp; Are you in the same setup ?&lt;/P&gt;
&lt;P&gt;If so, have you considered changing the session setup options ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more info please check:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/session-setup.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/session-setup.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/session-owner.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/session-owner.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 09 Nov 2021 14:19:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypassing-quot-packets-dropped-forwarded-to-different-zone-quot/m-p/446458#M100574</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2021-11-09T14:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing "Packets dropped: forwarded to different zone" limitation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypassing-quot-packets-dropped-forwarded-to-different-zone-quot/m-p/446630#M100601</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the answer.&lt;/P&gt;&lt;P&gt;No we don´t have A/A HA-setup so that wouln´t be a solution for our scenario.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 02:30:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypassing-quot-packets-dropped-forwarded-to-different-zone-quot/m-p/446630#M100601</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2021-11-10T02:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing "Packets dropped: forwarded to different zone" limitation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypassing-quot-packets-dropped-forwarded-to-different-zone-quot/m-p/446719#M100621</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;You mentioned you have disabled the non-SYN TCP check, but did you set "assimetric path" to bypass?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_0-1636548585230.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37568iF25CB87FDFB69327/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_0-1636548585230.png" alt="Astardzhiev_0-1636548585230.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Have you allowed assymetric path globally or per zone with zone protection profile?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I haven't faced a situation like this and I am working that is the actuall purpose of keeping the two ISP connection in different zones?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 12:59:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypassing-quot-packets-dropped-forwarded-to-different-zone-quot/m-p/446719#M100621</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-11-10T12:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing "Packets dropped: forwarded to different zone" limitation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypassing-quot-packets-dropped-forwarded-to-different-zone-quot/m-p/447881#M100754</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We tried allowing assymetric path both globally and per zone, still the same issue.&lt;/P&gt;&lt;P&gt;The purpose of keeping in different zones the two ISP connections is for having more granularity in the security policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 09:18:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypassing-quot-packets-dropped-forwarded-to-different-zone-quot/m-p/447881#M100754</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2021-11-16T09:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing "Packets dropped: forwarded to different zone" limitation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypassing-quot-packets-dropped-forwarded-to-different-zone-quot/m-p/447898#M100757</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What are you gaining from this granularity? Does the benefits you will gain deserve adding such complexity?&lt;/P&gt;
&lt;P&gt;Don't get wrong - as I said I haven't work with such setup and I am insteresed in the motives and are there any other acceptable solutions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was hoping for the asymetric pass to do the trick...It is very unlickly, but are you applying any IP spoofing protection with the zone-protection profile?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 09:47:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypassing-quot-packets-dropped-forwarded-to-different-zone-quot/m-p/447898#M100757</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-11-16T09:47:08Z</dc:date>
    </item>
  </channel>
</rss>

