<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA 5220 (PAN OS 8.1.10) Active / Active not synching tftp traffic in asymmetric routing scenario in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-pan-os-8-1-10-active-active-not-synching-tftp-traffic-in/m-p/519948#M107782</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But other udp applications are normal; only udp tftp has problems;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Nov 2022 01:55:21 GMT</pubDate>
    <dc:creator>ZhouYu</dc:creator>
    <dc:date>2022-11-02T01:55:21Z</dc:date>
    <item>
      <title>PA 5220 (PAN OS 8.1.10) Active / Active not synching tftp traffic in asymmetric routing scenario</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-pan-os-8-1-10-active-active-not-synching-tftp-traffic-in/m-p/299764#M78412</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;I have the following scenario: a pair of PA 5220 (running pan os 8.1.10) in an ACTIVE / ACTIVE Setup (session owner 1st Packter - session setup 1st Packet) -We have been running Active / Active since roughtly 2 Years now without any significant problems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However tftp (PXE Boot) session in an asymmetric scenario do not get properly synched (first packet flows through the Primary Firewall; reply (due to our routing setup) flows back via the secondary FW unit - the session which was initiated by going through the Primary FIrewall is no where to be seen on the Secondary Firewall). TCP traffic (also asymmetric) via both Primary and Secondary Firewall works without any issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was wondering if this is a known issue / limitation or if I have some sort of misconfiguration on our side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestion would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can provide additional infos / schematics if needed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 19:12:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-pan-os-8-1-10-active-active-not-synching-tftp-traffic-in/m-p/299764#M78412</guid>
      <dc:creator>CarloTaddei</dc:creator>
      <dc:date>2019-11-20T19:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: PA 5220 (PAN OS 8.1.10) Active / Active not synching tftp traffic in asymmetric routing scenario</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-pan-os-8-1-10-active-active-not-synching-tftp-traffic-in/m-p/299782#M78416</link>
      <description>&lt;P&gt;Just seeking confirmation on session setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Choices are:&lt;/P&gt;&lt;P&gt;IP Modulo, IP Hash, or Primary Device.&lt;/P&gt;&lt;P&gt;(Definitely do NOT recommend primary device...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So when you wrote "&lt;SPAN&gt;(session owner 1st Packter - session setup 1st Packet)&amp;nbsp;", I am looking to determine what you have.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you truly have Primary Device for Session Setup, then this explains why you are not seeing a session in the Secondary-Active FW.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please confirm and advise.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 21:03:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-pan-os-8-1-10-active-active-not-synching-tftp-traffic-in/m-p/299782#M78416</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-11-20T21:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: PA 5220 (PAN OS 8.1.10) Active / Active not synching tftp traffic in asymmetric routing scenario</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-pan-os-8-1-10-active-active-not-synching-tftp-traffic-in/m-p/299863#M78425</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for your Feedback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I wrote, we are currently using "First Packet" for both &lt;STRONG&gt;Session Owner&lt;/STRONG&gt; as well as &lt;STRONG&gt;Session Setup.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you believe the Problem that we are seeing with tftp is due to this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please note that we haven't seen so far such issues in our asymmetric Routing Scenario with other traffic / application types (mostly TCP based) ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 05:12:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-pan-os-8-1-10-active-active-not-synching-tftp-traffic-in/m-p/299863#M78425</guid>
      <dc:creator>CarloTaddei</dc:creator>
      <dc:date>2019-11-21T05:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: PA 5220 (PAN OS 8.1.10) Active / Active not synching tftp traffic in asymmetric routing scenario</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-pan-os-8-1-10-active-active-not-synching-tftp-traffic-in/m-p/519796#M107765</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;I also have the same problem&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 05:15:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-pan-os-8-1-10-active-active-not-synching-tftp-traffic-in/m-p/519796#M107765</guid>
      <dc:creator>ZhouYu</dc:creator>
      <dc:date>2022-11-01T05:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: PA 5220 (PAN OS 8.1.10) Active / Active not synching tftp traffic in asymmetric routing scenario</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-pan-os-8-1-10-active-active-not-synching-tftp-traffic-in/m-p/519856#M107772</link>
      <description>&lt;P&gt;If an Active/Active FW is setup with Session Owner AND Session Setup as 1st packet, then this is very comparable to a traditional Active/Passive setup where the ACTIVE FW is responsible for establishing the slowpath (session setup) and fastpath (security analysis) of a flow through the FW.&lt;BR /&gt;&lt;BR /&gt;TFTP is a UDP protocol, so there is no reason why the 2nd FW would see any packets from the 1st FW (in the original post, this was due to the routing.&amp;nbsp; With TCP, it is a connection-oriented protocol, yet with UDP, it is "spray and pray".&amp;nbsp;&amp;nbsp; So, if the session has not been fully setup on the 1st FW, then the 2nd FW will not see the session.&amp;nbsp; It is best to probably use a TCP client for tftp is needed.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 14:26:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-pan-os-8-1-10-active-active-not-synching-tftp-traffic-in/m-p/519856#M107772</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2022-11-01T14:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: PA 5220 (PAN OS 8.1.10) Active / Active not synching tftp traffic in asymmetric routing scenario</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-pan-os-8-1-10-active-active-not-synching-tftp-traffic-in/m-p/519948#M107782</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But other udp applications are normal; only udp tftp has problems;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 01:55:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-pan-os-8-1-10-active-active-not-synching-tftp-traffic-in/m-p/519948#M107782</guid>
      <dc:creator>ZhouYu</dc:creator>
      <dc:date>2022-11-02T01:55:21Z</dc:date>
    </item>
  </channel>
</rss>

