<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: A question about ECMP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1226296#M123952</link>
    <description>&lt;P&gt;Yeah! Thank you for your answer, I knew this concept now, and I also make a experimentation about this question. The conclusion is same with your answer. By the way, if I user the vlan interface replace physical L3 interface, and two ecmp vlan interface are in the same security zone but user different vlan tag, will the conclusion same? I mean will the firewall accept returning packets that has a different vlan tag with the request packets?&lt;/P&gt;</description>
    <pubDate>Fri, 11 Apr 2025 02:01:46 GMT</pubDate>
    <dc:creator>459768405</dc:creator>
    <dc:date>2025-04-11T02:01:46Z</dc:date>
    <item>
      <title>A question about ECMP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1226071#M123921</link>
      <description>&lt;P&gt;Hi，&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; I saw a function named ecmp on palo alto NGFW, I think that it can make outbound traffic load balance on two or more physics line or logic line. And I also saw there was a inbound interface information in the session table of firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;So I want to know if there are two out line on the firewall and connect to outside network named port1 and port2. Maybe they are all in the untrust zone, and then we open the ecmp function on virtual router of firewall, of course we have two ecmp routes with the same metric. &amp;nbsp;At that time if there is a traffic transmit from inside network to outside, &amp;nbsp;the syn packet transmit by port1, but the syn+ack answer packet received by port2, will there have a problem caused by outcome port is different to &amp;nbsp;income port? Will the syn+ack packet forward or discard? Will our session table check the information about income or outcome port? I need your help, Thanks! By the way, I only know a little English, So if you can’t understand what I mean, please leave a comment, I’ll explain more about this question, Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 11:11:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1226071#M123921</guid>
      <dc:creator>459768405</dc:creator>
      <dc:date>2025-04-09T11:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: A question about ECMP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1226098#M123928</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Hope this can answer your questions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClH0CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClH0CAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The traffic should return the same port it was sent out from.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 16:02:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1226098#M123928</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-04-09T16:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: A question about ECMP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1226100#M123929</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; Thanks for your answer, but I think if we use ECMP, &amp;nbsp;we can't control which port that the return packet( for example &amp;nbsp; &amp;nbsp;like a syn+ack packet) select, if the route let the packet select a different port with the port which transmit the syn packet, will the firewall discard the syn+ack packet caused of session table mismarch or another reason?&lt;/P&gt;
&lt;P&gt;Best Wishes&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 16:17:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1226100#M123929</guid>
      <dc:creator>459768405</dc:creator>
      <dc:date>2025-04-09T16:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: A question about ECMP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1226202#M123940</link>
      <description>&lt;P&gt;if you have all your ECMP interfaces set in the same zone (e.g. Untrust) the firewall will accept returning packets on the 'wrong' (not egress) interface&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 10:45:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1226202#M123940</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-04-10T10:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: A question about ECMP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1226244#M123945</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;What&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;said. Here is an article that goes over what I think you are wanting to deploy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF8CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF8CAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 18:39:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1226244#M123945</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-04-10T18:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: A question about ECMP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1226296#M123952</link>
      <description>&lt;P&gt;Yeah! Thank you for your answer, I knew this concept now, and I also make a experimentation about this question. The conclusion is same with your answer. By the way, if I user the vlan interface replace physical L3 interface, and two ecmp vlan interface are in the same security zone but user different vlan tag, will the conclusion same? I mean will the firewall accept returning packets that has a different vlan tag with the request packets?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 02:01:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1226296#M123952</guid>
      <dc:creator>459768405</dc:creator>
      <dc:date>2025-04-11T02:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: A question about ECMP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1226301#M123953</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thank you for your help, I try the part for this&amp;nbsp;document(use ecmp between two different zones) but with out the source nat config, it doesn't work. maybe we should use nat in this context.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Wishes&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 03:58:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1226301#M123953</guid>
      <dc:creator>459768405</dc:creator>
      <dc:date>2025-04-11T03:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: A question about ECMP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1227211#M124085</link>
      <description>&lt;P&gt;if you're egressing out of different zones you need to configure source nat or make sure there is no asymmetric return&lt;/P&gt;
&lt;P&gt;asymmetric return is not supported if your egress interfaces have different zones&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 09:54:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1227211#M124085</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-04-23T09:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: A question about ECMP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1227213#M124086</link>
      <description>&lt;P&gt;yes that's true, thanks about your help, I know it now, you are so skillful.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 09:57:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-question-about-ecmp/m-p/1227213#M124086</guid>
      <dc:creator>459768405</dc:creator>
      <dc:date>2025-04-23T09:57:55Z</dc:date>
    </item>
  </channel>
</rss>

