<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: existing session behavior when routing table changes in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/598141#M118980</link>
    <description>&lt;P&gt;Hi, We fixed this in our environment by creating a black hole route with 50 weight. So as soon as bgp comes in the BGP routes take preference as it has 20 weight.&lt;/P&gt;
&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Sep 2024 16:38:41 GMT</pubDate>
    <dc:creator>kashifkhana</dc:creator>
    <dc:date>2024-09-18T16:38:41Z</dc:date>
    <item>
      <title>existing session behavior when routing table changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/72447#M41104</link>
      <description>&lt;P&gt;Does anybody know if existing sessions can be updated when there is a routing table change, or if there is a way to clear sessions?&amp;nbsp; I'm hoping for something analagous to the Session Rematch feature when policies change.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My problem is that I have an existing session that becomes hung when the routing table changes.&amp;nbsp; The routing table updates when our primary link goes down so traffic will follow the backup link.&amp;nbsp; New sessions work properly, but the existing sessions do not.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe part of my issue is that I have a particular session that is UDP, and always uses the same source and destination ports.&amp;nbsp; This means any new traffic continues to match the existing session.&amp;nbsp; Further compounding the problem is that this is SIP traffic, so the session timeout is 60 minutes.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 19:02:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/72447#M41104</guid>
      <dc:creator>alowther_chatham</dc:creator>
      <dc:date>2016-02-09T19:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: existing session behavior when routing table changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/72469#M41106</link>
      <description>&lt;P&gt;Some time issue happens with SIP traffic. Clearing session will help. We can use the folllowing command to clear the session&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PA&amp;gt; clear session all filter source &amp;lt;ip&amp;gt; destination &amp;lt;ip&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 21:17:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/72469#M41106</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-02-09T21:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: existing session behavior when routing table changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/72513#M41111</link>
      <description>&lt;P&gt;&amp;gt; Clearing session will clear out everything and the new session will use the other active gateway&lt;/P&gt;
&lt;P&gt;&amp;gt; A feature called TCP&amp;nbsp;&lt;SPAN&gt;midstream-connection-pickup would have helped your situation but I don't believe that on Paloalto we have that feature, Once I saw this feature on Cyberoam firewall (again a linux based OS)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;gt; I think with root access this can be done, but again I am presuming&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 23:56:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/72513#M41111</guid>
      <dc:creator>vkalal</dc:creator>
      <dc:date>2016-02-09T23:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: existing session behavior when routing table changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/72547#M41124</link>
      <description>&lt;P&gt;Have you verified that firewall stops passing traffic towards new route (take packet capture for example)?&lt;/P&gt;
&lt;P&gt;Maybe application at destination does not map changed source IP to existing session.&lt;/P&gt;
&lt;P&gt;You can't just suddenly change endpoint ip's without application level to be aware of that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2016 12:59:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/72547#M41124</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-02-10T12:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: existing session behavior when routing table changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/72575#M41133</link>
      <description>&lt;P&gt;Thanks for the replies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Clearing the session did fix the issue.&amp;nbsp; I was hoping to find a way to make this automatic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For confirmation, the PaloAlto at the other end of the backup link did not have a session for the traffic.&amp;nbsp; This leads me to believe the traffic never reaches the destination after the route change.&amp;nbsp; The source and destination IPs do not change.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From reviewing documentation, because the source IP, destination IP, source port, destination port, protocol, and ingress interface do not change the session stays in the Fastpath and forwarding lookup never reoccurs.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2016 16:53:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/72575#M41133</guid>
      <dc:creator>alowther_chatham</dc:creator>
      <dc:date>2016-02-10T16:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: existing session behavior when routing table changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/72947#M41248</link>
      <description>&lt;P&gt;Have you configured the same zone on both outgoing interfaces? If not the firewall will drop the packets&lt;/P&gt;
&lt;P&gt;The firewall session's table is based among other things on source and destination zones (not physical interfaces) if the destination zone changed the packets will be dropped (as it broke the ecisting session). There is a Global counter for it but I don't remember it at the top of my head (something lime pkt_flow_zone_change)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can check&amp;nbsp;the global counters and see if the packets are being dropped.&lt;/P&gt;
&lt;P&gt;Before and after the issue,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;gt; show &lt;/SPAN&gt;&lt;SPAN class="lia-search-match-lithium lia-search-match-lithium"&gt;counter&lt;/SPAN&gt;&lt;SPAN&gt; global filter delta yes | match drop&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Gerardo.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2016 00:34:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/72947#M41248</guid>
      <dc:creator>glastra1</dc:creator>
      <dc:date>2016-02-17T00:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: existing session behavior when routing table changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/560383#M113604</link>
      <description>&lt;P&gt;Hello, &lt;BR /&gt;Did you solve this? I have a similar behavior and I need to change the outgoing interface when route change because it is a UDP flow that use default route because is the first available before learn the BGP routes.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 15:40:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/560383#M113604</guid>
      <dc:creator>Raul_Garcia</dc:creator>
      <dc:date>2023-10-03T15:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: existing session behavior when routing table changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/598141#M118980</link>
      <description>&lt;P&gt;Hi, We fixed this in our environment by creating a black hole route with 50 weight. So as soon as bgp comes in the BGP routes take preference as it has 20 weight.&lt;/P&gt;
&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 16:38:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/598141#M118980</guid>
      <dc:creator>kashifkhana</dc:creator>
      <dc:date>2024-09-18T16:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: existing session behavior when routing table changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/1222168#M123424</link>
      <description>&lt;P&gt;After years of providing outputs and asking for a feature request, PaloAlto has finally given us an option to address this. Refer - &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBmqCAG" target="_blank"&gt;UDP sessions stuck after failover - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 09:42:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/existing-session-behavior-when-routing-table-changes/m-p/1222168#M123424</guid>
      <dc:creator>TusharS</dc:creator>
      <dc:date>2025-02-27T09:42:22Z</dc:date>
    </item>
  </channel>
</rss>

