<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why doesn't Firewall PAN automatically change the MAC address of the Rever Proxy device? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/why-doesn-t-firewall-pan-automatically-change-the-mac-address-of/m-p/577960#M115957</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1162955685"&gt;@Namppmtechpro_2410&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Doesn't sound like the Imperva is sending a gratuitous ARP (GARP) when you fail traffic over like it should.&amp;nbsp; When you have a device in any sort of HA you want it GARP'ing when it takes over responsibility for the IP if it's not going to utilize the same MAC address across peers.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The firewall is doing what it should here; if it has an ARP entry for an address already there's no reason to not use the cached entry, hence why GARP exists so that devices can announce that they now control an IP address.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Feb 2024 22:47:34 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2024-02-21T22:47:34Z</dc:date>
    <item>
      <title>Why doesn't Firewall PAN automatically change the MAC address of the Rever Proxy device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-doesn-t-firewall-pan-automatically-change-the-mac-address-of/m-p/577699#M115922</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hello guys, can you help me with this problem?&lt;/P&gt;
&lt;P&gt;We are looking for the following logical scenario, we have 2 Reverse Proxy (Imperva) devices connecting through a PAN Firewall as shown below. When checking for backup on Imperva. We tried the following:&lt;/P&gt;
&lt;P&gt;- Turn off eth2 port on Master and traffic is transferred to Backup successfully. All operations are stable. The PAN firewall will relearn the VIP's MAC address, the MAC address is changed from MASTER ==&amp;gt; BACKUP&lt;/P&gt;
&lt;P&gt;- Enable return port eth2 on Master, traffic cannot be transferred to Master. Because the PAN Firewall still holds the MAC address of the MASTER device. Only when we clear the cache on the PAN does it work properly again.&lt;/P&gt;
&lt;P&gt;Do you have any suggestions for this problem?. Can you help me?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Namppmtechpro_2410_1-1708400988356.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57731i5C3293E9B65F6D81/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Namppmtechpro_2410_1-1708400988356.png" alt="Namppmtechpro_2410_1-1708400988356.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 03:50:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-doesn-t-firewall-pan-automatically-change-the-mac-address-of/m-p/577699#M115922</guid>
      <dc:creator>Namppmtechpro_2410</dc:creator>
      <dc:date>2024-02-20T03:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Firewall PAN automatically change the MAC address of the Rever Proxy device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-doesn-t-firewall-pan-automatically-change-the-mac-address-of/m-p/577700#M115923</link>
      <description>&lt;P&gt;&lt;STRONG&gt;I'm experiencing a similar issue. If anyone has a solution, please kindly assist us.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 03:57:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-doesn-t-firewall-pan-automatically-change-the-mac-address-of/m-p/577700#M115923</guid>
      <dc:creator>duongdt98</dc:creator>
      <dc:date>2024-02-20T03:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Firewall PAN automatically change the MAC address of the Rever Proxy device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-doesn-t-firewall-pan-automatically-change-the-mac-address-of/m-p/577701#M115924</link>
      <description>&lt;DIV id="bodyDisplay_1" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;&lt;STRONG&gt;I'm experiencing a similar issue. If anyone has a solution, please kindly assist us.&lt;/STRONG&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-rating-metoo lia-component-me-too-solution lia-component-message-view-widget-me-too-solution"&gt;
&lt;DIV class="RatingDisplay lia-component-ratings-widget-rating-display"&gt;
&lt;DIV id="ratingenumerationdisplay_1" class="lia-rating-enumeration-system-forum_solution_metoo lia-rating-enumeration rating-enum-577700-forum_solution_metoo"&gt;
&lt;DIV class="lia-button-group-left"&gt;&lt;SPAN class="lia-button-wrapper lia-button-wrapper-secondary"&gt;&lt;A id="link_29" class="lia-button lia-button-secondary lia-rating-image lia-rating-image-selected lia-rating-image-active lia-js-data-ratingValue-0 lia-link-ticket-post-action" title="Click here if you had a similar experience" role="button" href="https://live.paloaltonetworks.com/t5/forums/v5/forumtopicpage.externalratingdisplay.ratingenumerationdisplay.link:rating/rating-enum/0/rating-system/forum_solution_metoo/message-uid/577700?t:ac=board-id/members_discuss/thread-id/115922&amp;amp;t:cp=ratings/contributionpage" rel="nofollow" data-lia-action-token="1ubAkUR7BsfHuO8QtlJo1exG8fIUsG7TKhgvqT2im2uFxFBBAkVutAEMel___OBB" target="_blank"&gt;Me too&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 20 Feb 2024 05:20:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-doesn-t-firewall-pan-automatically-change-the-mac-address-of/m-p/577701#M115924</guid>
      <dc:creator>Dolores56</dc:creator>
      <dc:date>2024-02-20T05:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Firewall PAN automatically change the MAC address of the Rever Proxy device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-doesn-t-firewall-pan-automatically-change-the-mac-address-of/m-p/577960#M115957</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1162955685"&gt;@Namppmtechpro_2410&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Doesn't sound like the Imperva is sending a gratuitous ARP (GARP) when you fail traffic over like it should.&amp;nbsp; When you have a device in any sort of HA you want it GARP'ing when it takes over responsibility for the IP if it's not going to utilize the same MAC address across peers.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The firewall is doing what it should here; if it has an ARP entry for an address already there's no reason to not use the cached entry, hence why GARP exists so that devices can announce that they now control an IP address.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 22:47:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-doesn-t-firewall-pan-automatically-change-the-mac-address-of/m-p/577960#M115957</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-02-21T22:47:34Z</dc:date>
    </item>
  </channel>
</rss>

