<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packet flow question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-question/m-p/22723#M16612</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We suggest confirming the routing on the remote side of the vpn, however this does not explain why this is failing intermittently.&lt;/P&gt;&lt;P&gt;This may require further investigation, you may need to open a case with support. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Mar 2011 01:38:13 GMT</pubDate>
    <dc:creator>gsamuels</dc:creator>
    <dc:date>2011-03-23T01:38:13Z</dc:date>
    <item>
      <title>Packet flow question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-question/m-p/22722#M16611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everybody,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Device: PA-500&lt;/P&gt;&lt;P&gt;Software: 3.1.7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have a problem with our vpn tunnels. The tunnels are up and running,&lt;/P&gt;&lt;P&gt;but when I try to connect or ping a system over the tunnel we are getting timeouts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To figure out what happens, I did a packet flow all and a packet capture and here I get &lt;/P&gt;&lt;P&gt;an entry which I can not explain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"L2 broadcast cannot be forwarded in L3 mode"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm getting this entry after ther route lookup for the vpn peer gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;== Mar 22 09:08:47 ==&lt;BR /&gt;Packet received at forwarding stage&lt;BR /&gt;Packet info: len 1042 port 16 interface 16&lt;BR /&gt;&amp;nbsp; wqe index 229211 packet 0x0x8000000416ff00ce&lt;BR /&gt;Packet decoded dump:&lt;BR /&gt;L2:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:24:73:79:43:81-&amp;gt;00:1b:17:13:2e:10, type 0x0800&lt;BR /&gt;IP:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.x.x.x-&amp;gt;192.168.x.x, protocol 1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; version 4, ihl 5, tos 0x00, len 1028,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; id 61358, frag_off 0x0000, ttl 127, checksum 32071&lt;BR /&gt;ICMP:&amp;nbsp;&amp;nbsp; type 8, code 0, checksum 64558, id 512, seq 21553&lt;BR /&gt;Forwarding lookup, ingress interface 16&lt;BR /&gt;L3 mode, virtual-router 2&lt;BR /&gt;Route lookup in virtual-router 2, IP 192.168.x.x&lt;BR /&gt;Route found, interface tunnel.21, zone 6&lt;BR /&gt;Packet enters tunnel encap stage, tunnel interface tunnel.21&lt;BR /&gt;Resolved tunnel 3&lt;BR /&gt;Forwarding lookup, ingress interface 23&lt;BR /&gt;L3 mode, virtual-router 2&lt;BR /&gt;Route lookup in virtual-router 2, IP x.x.x.x (external)&lt;BR /&gt;L2 broadcast cannot be forwarded in L3 mode&lt;/P&gt;&lt;P&gt;For example the next packet is working fine:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;== Mar 22 09:08:52 ==&lt;BR /&gt;Packet received at forwarding stage&lt;BR /&gt;Packet info: len 1042 port 16 interface 16&lt;BR /&gt;&amp;nbsp; wqe index 229109 packet 0x0x8000000416fdf0ce&lt;BR /&gt;Packet decoded dump:&lt;BR /&gt;L2:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:24:73:79:43:81-&amp;gt;00:1b:17:13:2e:10, type 0x0800&lt;BR /&gt;IP:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.x.x.x-&amp;gt;192.168.x.x, protocol 1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; version 4, ihl 5, tos 0x00, len 1028,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; id 61429, frag_off 0x0000, ttl 127, checksum 32000&lt;BR /&gt;ICMP:&amp;nbsp;&amp;nbsp; type 8, code 0, checksum 64302, id 512, seq 21809&lt;BR /&gt;Forwarding lookup, ingress interface 16&lt;BR /&gt;L3 mode, virtual-router 2&lt;BR /&gt;Route lookup in virtual-router 2, IP 192.168.x.x&lt;/P&gt;&lt;P&gt;Route found, interface tunnel.21, zone 6&lt;BR /&gt;Packet enters tunnel encap stage, tunnel interface tunnel.21&lt;BR /&gt;Resolved tunnel 3&lt;BR /&gt;Forwarding lookup, ingress interface 23&lt;BR /&gt;L3 mode, virtual-router 2&lt;BR /&gt;Route lookup in virtual-router 2, IP x.x.x.x&lt;/P&gt;&lt;P&gt;Route found, interface ethernet1/8, zone 4, nexthop y.y.y.y&lt;/P&gt;&lt;P&gt;Resolve ARP for IP y.y.y.y on interface ethernet1/8&lt;BR /&gt;ARP entry found on interface 23&lt;/P&gt;&lt;P&gt;After this, the packet is dropped, but sometimes its working and the route lookup works fine!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has somebody a hint for me!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Mar 2011 08:49:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-question/m-p/22722#M16611</guid>
      <dc:creator>indevis</dc:creator>
      <dc:date>2011-03-22T08:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Packet flow question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-question/m-p/22723#M16612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We suggest confirming the routing on the remote side of the vpn, however this does not explain why this is failing intermittently.&lt;/P&gt;&lt;P&gt;This may require further investigation, you may need to open a case with support. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Mar 2011 01:38:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-question/m-p/22723#M16612</guid>
      <dc:creator>gsamuels</dc:creator>
      <dc:date>2011-03-23T01:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: Packet flow question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-question/m-p/22724#M16613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for you answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the problem is, that we had changed the hardware one week ago.&lt;/P&gt;&lt;P&gt;Because we had some issues in the logs, that the memory is corrupted.&lt;/P&gt;&lt;P&gt;We made a RMA, a now the new machine is running.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The config and the software release is the same as before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And, what should I say, before we changed it it was working with no timeouts or connection lose.&lt;/P&gt;&lt;P&gt;The other side of the VPN were not changed in any way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now we have updated to 3.1.8 but with no success, this weired behavior is still happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think there is no other chance to open a case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Mar 2011 09:06:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-question/m-p/22724#M16613</guid>
      <dc:creator>indevis</dc:creator>
      <dc:date>2011-03-23T09:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: Packet flow question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-question/m-p/22725#M16614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm seeing the exact same thing on one of our PA-500s running 3.1.9&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"L2 broadcast cannot be forwarded in L3 mode"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot figure out why it is saying this, as the ICMP type 8 packet entering the firewall interface is routed through 2 routers before it hits the firewall, hence it cannot be a L2 packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a hotfix or workaround for this issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hans&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2011 13:32:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-question/m-p/22725#M16614</guid>
      <dc:creator>hmklette</dc:creator>
      <dc:date>2011-06-28T13:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Packet flow question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-question/m-p/22726#M16615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hans,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in our scenario this happens in conjunction with VPN Tunnels.&lt;/P&gt;&lt;P&gt;And it seems that in some scenarios with the releases 3.1.7+8+9&lt;/P&gt;&lt;P&gt;can be some problems.&lt;/P&gt;&lt;P&gt;For sure, this is not happening in all implementations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when it happens, you can make a downgrade to 3.1.6&lt;/P&gt;&lt;P&gt;to solve this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In our scenario the downgrade to 3.1.6 works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jun 2011 10:42:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-question/m-p/22726#M16615</guid>
      <dc:creator>indevis</dc:creator>
      <dc:date>2011-06-29T10:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Packet flow question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-question/m-p/22727#M16616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes it happens in VPN tunnels from one particular box and towards 5 other ones also running 3.1.9.&lt;/P&gt;&lt;P&gt;The other 5 PA500 boxes also have VPNs between them, but we see no packetloss on those VPNs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I guess the quickfix to this, is to downgrade to 3.1.6, as I don't want to go for 4.0.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hans&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jun 2011 10:51:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-question/m-p/22727#M16616</guid>
      <dc:creator>hmklette</dc:creator>
      <dc:date>2011-06-29T10:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: Packet flow question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-question/m-p/22728#M16617</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This issue is resolved in 4.0.3 and affect release 3.1.7, 3.18 and 3.1.9.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jun 2011 19:00:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-question/m-p/22728#M16617</guid>
      <dc:creator>mrajdev</dc:creator>
      <dc:date>2011-06-29T19:00:09Z</dc:date>
    </item>
  </channel>
</rss>

