<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strict IP Address Check after 9.1.12 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/463016#M102325</link>
    <description>&lt;P&gt;&lt;SPAN&gt;&amp;gt;ZPP most likely was assigned to public interface,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes, this was the case and what I figured as well.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Feb 2022 14:23:25 GMT</pubDate>
    <dc:creator>JesseCurtis2020</dc:creator>
    <dc:date>2022-02-03T14:23:25Z</dc:date>
    <item>
      <title>Strict IP Address Check after 9.1.12</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/460486#M102082</link>
      <description>&lt;P&gt;Customer upgraded to 9.1.12 and after that it was noticed that for some of the zones, traffic was dropped. During debug,it was concluded that reason is&amp;nbsp;&lt;SPAN&gt;Strict IP Address Check in the Zone Protection Profile:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"flow_dos_pf_strictip 1 0 drop flow dos Packets dropped: Zone protection option 'strict-ip-check'"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In the 9.1.12 release notes it is noted:&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV&gt;PAN-175934&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;Fixed an issue where packed-based zone protection settings (such as Strict IP Address Check) were not applied to return traffic.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;SPAN&gt;So one may think it is a bug that was fixed and customer has his routing table messed up, but after checking - routing seems to be fine. Traffic was dropped even from outside interface (with default route) to GlobalProtect interface which is loopback on the device. Same for Outside &amp;lt;-&amp;gt; DMZ traffic, which is directly connected interface, so essentially&amp;nbsp;no dynamic/static routing is done there.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Behavior can be confirmed and reproduced by turning on and off strict IP check in the zone protection profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone confirm this? Checking before opening TAC case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit a bit later: PBR is not configured.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 08:04:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/460486#M102082</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2022-01-24T08:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: Strict IP Address Check after 9.1.12</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/461284#M102150</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42773"&gt;@nikoo&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have just run into the same issue when going along the upgrade path to 10.1.3, when we hit 9.1.12, GP VPN and IPsec VPN both broke. Turned off 'strict-IP-check' on the internet zone protection profile and both VPNs are working again. Haven't re-tested on 10.1.3 as yet.&lt;BR /&gt;&lt;BR /&gt;Only thing I noticed was our local VPN IP address is on a loopback address in the internet zone, the below KB article seems to suggest that&amp;nbsp;'strict-IP-check' can cause an issue with loopback addresses, in saying that not sure why it only just became a problem with 9.1.12.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U3FCAU" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U3FCAU&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you end up raising this with PA support? or find a solution here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 01:18:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/461284#M102150</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2022-01-27T01:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Strict IP Address Check after 9.1.12</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/461306#M102156</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/181759"&gt;@Ben-Price&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I noted that article as well, but my understanding loopback address was mean to be 127.0.0.1 given the context along with broadcast, network, etc. addresses. Not sure if my guess was correct, though.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently I have not opened a case, would still like to check the effect on traffic passing via the firewall - as that was seen in the customer case as well, so it did not seem to be related to Palo Alto assigned IPs only. Was hoping that someone from PA may confirm this behavior as that would mean less guessing and poking around.&lt;/P&gt;&lt;P&gt;As for now left the workaround - strict IP check disabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 07:55:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/461306#M102156</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2022-01-27T07:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: Strict IP Address Check after 9.1.12</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/461609#M102182</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42773"&gt;@nikoo&lt;/a&gt;&amp;nbsp;OK thanks for the feedback, I think you might be right regarding the meaning of loopback address outlined.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Are you able to comment here on the above issue me and &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42773"&gt;@nikoo&lt;/a&gt;&amp;nbsp;have experienced?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 22:22:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/461609#M102182</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2022-01-27T22:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: Strict IP Address Check after 9.1.12</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/462882#M102307</link>
      <description>&lt;P&gt;Experiencing similar behavior. Suddenly traffic across a WPN was being dropped and did not even have a ZPP on it. Running 9.1.12.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Followed this KB to find it which was helpful. Unchecked strict IP check and returned to normal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 20:06:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/462882#M102307</guid>
      <dc:creator>JesseCurtis2020</dc:creator>
      <dc:date>2022-02-02T20:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Strict IP Address Check after 9.1.12</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/462914#M102309</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42773"&gt;@nikoo&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/143394"&gt;@JesseCurtis2020&lt;/a&gt;&amp;nbsp;My client has updated there firewall to PAN OS 10.1.3. I have asked them to re-enabled the strict IP check and see if the issue remains on that version.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 22:06:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/462914#M102309</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2022-02-02T22:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: Strict IP Address Check after 9.1.12</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/462962#M102315</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/143394"&gt;@JesseCurtis2020&lt;/a&gt;, ZPP most likely was assigned to public interface, as I had similar behavior with VPN traffic being dropped and sounds like the same issue, yeah.&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/181759"&gt;@Ben-Price&lt;/a&gt;,&amp;nbsp;that can be good to know for future reference. In my case though customer is running PA-3xxx series, so no possibility to go above 9.1.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 06:31:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/462962#M102315</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2022-02-03T06:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: Strict IP Address Check after 9.1.12</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/463016#M102325</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;gt;ZPP most likely was assigned to public interface,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes, this was the case and what I figured as well.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 14:23:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/463016#M102325</guid>
      <dc:creator>JesseCurtis2020</dc:creator>
      <dc:date>2022-02-03T14:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: Strict IP Address Check after 9.1.12</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/467334#M102775</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42773"&gt;@nikoo&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/143394"&gt;@JesseCurtis2020&lt;/a&gt;&amp;nbsp;This has been identified as a bug and PA have now updated the PAN OS 9.1.12 known issues documentation outlining the bug (PAN-186937).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BenPrice_0-1645481676703.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39239i2BD64DC2A9D93D1A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BenPrice_0-1645481676703.png" alt="BenPrice_0-1645481676703.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-release-notes/pan-os-9-1-release-information/known-issues/known-issues-related-to-pan-os-9-1-releases/pan-os-9-1-12-known-issues.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-release-notes/pan-os-9-1-release-information/known-issues/known-issues-related-to-pan-os-9-1-releases/pan-os-9-1-12-known-issues.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2022 22:15:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strict-ip-address-check-after-9-1-12/m-p/467334#M102775</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2022-02-21T22:15:15Z</dc:date>
    </item>
  </channel>
</rss>

