<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help understanding Asymmetric Path issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/help-understanding-asymmetric-path-issue/m-p/584415#M116738</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Anytime you have more than one possible path from one node to another, you might get asymmetrical routing. Its a pain, but can be controlled. I know it doesn't really answer your questions, just a fact in any product/routing network.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Sun, 21 Apr 2024 16:55:58 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2024-04-21T16:55:58Z</dc:date>
    <item>
      <title>Help understanding Asymmetric Path issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-understanding-asymmetric-path-issue/m-p/584409#M116737</link>
      <description>&lt;P&gt;Hoping that someone can help me to understand my asymmetric path issue (out of sync). I have a single virtual firewall with 2 virtual routers. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Interfaces:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;U&gt;Client&lt;/U&gt; (in zone 'client'). Is gateway for subnet.&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;VPN&lt;/U&gt; (in zone 'vpn'). Is gateway for subnet.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Machines:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;U&gt;Client-01&lt;/U&gt; - (192.168.1.3) 1 interface in 'client' zone.&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;VPN-01&lt;/U&gt; - 2 interfaces, (192.168.2.2) interface in 'vpn' zone. (192.168.1.2) interface in 'client' zone.
&lt;UL&gt;
&lt;LI&gt;Runs IPTables to forward traffic from 192.168.1.0/24 to 192.168.2.2 interface, SNAT to 192.168.2.2.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Virtual Routers:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;U&gt;default&lt;/U&gt; -
&lt;UL&gt;
&lt;LI&gt;has route to WAN (single ISP).&lt;/LI&gt;
&lt;LI&gt;has route to 'untrusted' (192.168.1.0/24 via VR 'untrusted')&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;untrusted&lt;/U&gt; -
&lt;UL&gt;
&lt;LI&gt;default route to IP of VPN (default route via '192.168.1.2')&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I found that this works for ICMP (presumably UDP). However after running tcpdumps on both the vpn and client as well as the PA, I found that traffic was being dropped. Specifically TCP traffic. I found an old Palo article from what appears to be a similar situation (&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/routing-between-virtual-routers-in-same-firewall/td-p/40320" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/routing-between-virtual-routers-in-same-firewall/td-p/40320&lt;/A&gt;). Which led me to find that I am dropping packets, I set 'asymmetric path' to 'bypass', which resolves the issue. However, I'm not understanding where the problematic route is. Most issues I'm finding online involve 2 or more ISP providers, which doesn't apply to my scenario. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Scenario : client-01 to WAN&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;All traffic from&amp;nbsp; 'client-01' to WAN will forward to 'vpn-01' and get NAT'd with a source IP of 192.168.2.2. The Palo will then NAT it to the public IP on the firewall and return traffic will hit the WAN interface on the FW, it will be sent back to 192.168.2.2, which will then be sent back to 'client-01'. I have tried removing the route on the default VR '192.168.1.0/24 via VR untrusted', but this didn't change anything.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This works fine for stateless traffic, but I have dropped packets unless 'asymmetric path' is set to 'bypass' for TCP traffic. Can anyone help me understand what am I missing that would cause packets to arrive out of order? Thanks for any assistance provided. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Network topology:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot from 2024-04-21 09-14-11.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59172iB3A9F5535D8D265C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot from 2024-04-21 09-14-11.png" alt="Screenshot from 2024-04-21 09-14-11.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2024 13:44:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-understanding-asymmetric-path-issue/m-p/584409#M116737</guid>
      <dc:creator>shyrus</dc:creator>
      <dc:date>2024-04-21T13:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: Help understanding Asymmetric Path issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-understanding-asymmetric-path-issue/m-p/584415#M116738</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Anytime you have more than one possible path from one node to another, you might get asymmetrical routing. Its a pain, but can be controlled. I know it doesn't really answer your questions, just a fact in any product/routing network.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2024 16:55:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-understanding-asymmetric-path-issue/m-p/584415#M116738</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-04-21T16:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: Help understanding Asymmetric Path issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-understanding-asymmetric-path-issue/m-p/584567#M116761</link>
      <description>&lt;P&gt;Int. Client won't see the syn-ack in what you've described. vpn-01 and client-01 are on the same subnet so return traffic just forwards, the firewall won't see it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2024 23:34:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-understanding-asymmetric-path-issue/m-p/584567#M116761</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2024-04-22T23:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Help understanding Asymmetric Path issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-understanding-asymmetric-path-issue/m-p/584576#M116762</link>
      <description>&lt;P&gt;Thanks for the replies.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2024 23:58:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-understanding-asymmetric-path-issue/m-p/584576#M116762</guid>
      <dc:creator>shyrus</dc:creator>
      <dc:date>2024-04-22T23:58:53Z</dc:date>
    </item>
  </channel>
</rss>

