<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic A very weird Behavior on SIP traffic traffic reversing back to the same egress interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/a-very-weird-behavior-on-sip-traffic-traffic-reversing-back-to/m-p/999929#M122698</link>
    <description>&lt;P&gt;Hello everyone , im seeing a very strange behaviour in my pa-445 version 11.1.4-h7 firewall , where i have an interface on the firewall which is a gateway to my voip devices , the same firewall connects to the voice server through an ipsec tunnel interface , so the traffic flow is like this , voice subnet to firewall and then from firewall to voice server through the tunnel , however on logs i see that the same voice subnet is entering the tunnel interface as "source" &amp;amp; with the "source zone" since its hitting this tunnel interface and ofcourse its denied since the allowed rule is from branch "voice zone" to "hq zone" , however im only seeing this for voice subnet and only on SIP application .&lt;/P&gt;
&lt;P&gt;i would really appreciate any help &amp;amp; thanks&lt;/P&gt;</description>
    <pubDate>Wed, 01 Jan 2025 12:50:42 GMT</pubDate>
    <dc:creator>Esameldin</dc:creator>
    <dc:date>2025-01-01T12:50:42Z</dc:date>
    <item>
      <title>A very weird Behavior on SIP traffic traffic reversing back to the same egress interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-very-weird-behavior-on-sip-traffic-traffic-reversing-back-to/m-p/999929#M122698</link>
      <description>&lt;P&gt;Hello everyone , im seeing a very strange behaviour in my pa-445 version 11.1.4-h7 firewall , where i have an interface on the firewall which is a gateway to my voip devices , the same firewall connects to the voice server through an ipsec tunnel interface , so the traffic flow is like this , voice subnet to firewall and then from firewall to voice server through the tunnel , however on logs i see that the same voice subnet is entering the tunnel interface as "source" &amp;amp; with the "source zone" since its hitting this tunnel interface and ofcourse its denied since the allowed rule is from branch "voice zone" to "hq zone" , however im only seeing this for voice subnet and only on SIP application .&lt;/P&gt;
&lt;P&gt;i would really appreciate any help &amp;amp; thanks&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jan 2025 12:50:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-very-weird-behavior-on-sip-traffic-traffic-reversing-back-to/m-p/999929#M122698</guid>
      <dc:creator>Esameldin</dc:creator>
      <dc:date>2025-01-01T12:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: A very weird Behavior on SIP traffic traffic reversing back to the same egress interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-very-weird-behavior-on-sip-traffic-traffic-reversing-back-to/m-p/1000008#M122716</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/331522"&gt;@Esameldin&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Just to confirm, are you saying that the SIP traffic from your voice subnet is being incorrectly processed as originating from an unintended zone, rather than the local voice zone? If possible, could you please share screenshots (with IPs blurred out) to help us further investigate the issue?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 23:22:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-very-weird-behavior-on-sip-traffic-traffic-reversing-back-to/m-p/1000008#M122716</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2025-01-02T23:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: A very weird Behavior on SIP traffic traffic reversing back to the same egress interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-very-weird-behavior-on-sip-traffic-traffic-reversing-back-to/m-p/1000028#M122722</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yes the traffic is actually generating from the supposed egress interface , its like sent packets are just coming back to the same interface it left , and on the HQ (destination) firewall i have no such logs so traffic is not being generated from HQ, please refer to the below screenshot&lt;/P&gt;
&lt;P&gt;On the below screenshots you will find the ingress and egress interfaces , and also normal legal traffic , &amp;amp; the unusual traffic (as per the routing table when traffic is hitting the HQ interface its redirected back to HQ ) &amp;amp; so its denied by zone policy&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Direct;y Connected Voice interface" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65018i6185DE0077B07B31/image-size/large?v=v2&amp;amp;px=999" role="button" title="voice-zone.png" alt="Direct;y Connected Voice interface" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Direct;y Connected Voice interface&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hq-interface.png" style="width: 720px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65017i7F61E330568C417E/image-size/large?v=v2&amp;amp;px=999" role="button" title="hq-interface.png" alt="hq-interface.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sip-legal-traffic" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65019iA1226EC0EEA8CA2C/image-size/large?v=v2&amp;amp;px=999" role="button" title="sip-legal-traffic.png" alt="sip-legal-traffic" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;sip-legal-traffic&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sip-illegal-traffic" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65020iE02CA2260FB1CB37/image-size/large?v=v2&amp;amp;px=999" role="button" title="sip-illegal-traffic.png" alt="sip-illegal-traffic" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;sip-illegal-traffic&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 04:37:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-very-weird-behavior-on-sip-traffic-traffic-reversing-back-to/m-p/1000028#M122722</guid>
      <dc:creator>Esameldin</dc:creator>
      <dc:date>2025-01-03T04:37:24Z</dc:date>
    </item>
  </channel>
</rss>

