<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue with VXLAN traffic passing through the firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-vxlan-traffic-passing-through-the-firewall/m-p/492707#M104990</link>
    <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have an SDWAN box placed behind the firewall and the SD_WAN box need to communicate with the controllers which is located on the internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The topology is given below:&lt;/P&gt;&lt;P&gt;SD_WAN Box&amp;lt;---&amp;gt;F/W LAN interface&amp;lt;---&amp;gt;F/W ISP interface &amp;lt;--&amp;gt; Internet &amp;lt;----&amp;gt;Controllers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The&amp;nbsp;SD_WAN Box is trying to establish VXLAN connectivity to the Controllers located on the internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the traffic logs and the session browsers we could see the traffic flow b/n the&amp;nbsp;&amp;nbsp;SD_WAN Box and the&amp;nbsp;VXLAN is being allowed by the firewall and the application is being correctly identified as "VXLAN".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had configured only source NAT on the firewall but we could see on the log that the destination port is being translated to 511 from 4789&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tamilvanan_0-1653585569659.png" style="width: 683px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41176iD2BE46307E8A53D8/image-dimensions/683x427/is-moderation-mode/true?v=v2" width="683" height="427" role="button" title="tamilvanan_0-1653585569659.png" alt="tamilvanan_0-1653585569659.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why the firewall is translating the destination port even though the DNAT is not configured.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 May 2022 17:21:26 GMT</pubDate>
    <dc:creator>tamilvanan</dc:creator>
    <dc:date>2022-05-26T17:21:26Z</dc:date>
    <item>
      <title>Issue with VXLAN traffic passing through the firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-vxlan-traffic-passing-through-the-firewall/m-p/492707#M104990</link>
      <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have an SDWAN box placed behind the firewall and the SD_WAN box need to communicate with the controllers which is located on the internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The topology is given below:&lt;/P&gt;&lt;P&gt;SD_WAN Box&amp;lt;---&amp;gt;F/W LAN interface&amp;lt;---&amp;gt;F/W ISP interface &amp;lt;--&amp;gt; Internet &amp;lt;----&amp;gt;Controllers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The&amp;nbsp;SD_WAN Box is trying to establish VXLAN connectivity to the Controllers located on the internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the traffic logs and the session browsers we could see the traffic flow b/n the&amp;nbsp;&amp;nbsp;SD_WAN Box and the&amp;nbsp;VXLAN is being allowed by the firewall and the application is being correctly identified as "VXLAN".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had configured only source NAT on the firewall but we could see on the log that the destination port is being translated to 511 from 4789&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tamilvanan_0-1653585569659.png" style="width: 683px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41176iD2BE46307E8A53D8/image-dimensions/683x427/is-moderation-mode/true?v=v2" width="683" height="427" role="button" title="tamilvanan_0-1653585569659.png" alt="tamilvanan_0-1653585569659.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why the firewall is translating the destination port even though the DNAT is not configured.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2022 17:21:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-vxlan-traffic-passing-through-the-firewall/m-p/492707#M104990</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2022-05-26T17:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with VXLAN traffic passing through the firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-vxlan-traffic-passing-through-the-firewall/m-p/492888#M104993</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/165087"&gt;@tamilvanan&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Have you run a test nat-policy-match against the traffic to verify that it's actually hitting the NAT policy that you expect. IF the firewall is modifying the port, sounds like you're hitting a DIPP entry that you might not be expecting.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2022 20:55:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-vxlan-traffic-passing-through-the-firewall/m-p/492888#M104993</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-05-26T20:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with VXLAN traffic passing through the firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-vxlan-traffic-passing-through-the-firewall/m-p/511678#M106359</link>
      <description>&lt;P&gt;What I have found is that the VxLAN Session information (both from the web UI and from the CLI using the "show session ..." output) is incorrect - or at least misleading. The first packet of the session is shown correctly, but all VxLAN packets after the start of the session are assigned to their own session with strange output. I'm not sure, but I think the strange output showed the destination information from *inside* the VxLAN traffic (even with tunnel inspection turned off!). Is it possible that 511 was the destination port inside the VxLAN traffic? A packet capture on the firewall opened in Wireshark shows that the firewall is forwarding traffic correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a case opened with Technical Support to try to determine if there is a way to interpret the output or if it is simply a bug.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 13:33:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-vxlan-traffic-passing-through-the-firewall/m-p/511678#M106359</guid>
      <dc:creator>Travis.Tibbs</dc:creator>
      <dc:date>2022-08-12T13:33:41Z</dc:date>
    </item>
  </channel>
</rss>

