<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic logged in an interface in down state in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logged-in-an-interface-in-down-state/m-p/22812#M16673</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These are most probably sessions which were started before the interface was shutdown. They stay in the session table until they idle out and then produce the session end log entry.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Sep 2013 11:56:56 GMT</pubDate>
    <dc:creator>Anon1</dc:creator>
    <dc:date>2013-09-18T11:56:56Z</dc:date>
    <item>
      <title>Traffic logged in an interface in down state</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logged-in-an-interface-in-down-state/m-p/22811#M16672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is our scenario:&lt;/P&gt;&lt;P&gt;- A PA-200 with a subinterface tagged with VLAN ID 200.&lt;/P&gt;&lt;P&gt;- Connected to a Cisco Catalyst switch (trunk with VLAN ID 200 allowed).&lt;/P&gt;&lt;P&gt;- It has been working without problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, we want to divert traffic to a Cisco router with same IP address as PA-200.&lt;/P&gt;&lt;P&gt;We put Catalyst interface in shutdown state (where PA-200 is connected) at 10.52h.&lt;/P&gt;&lt;P&gt;- We can see interface in "down" state (red) in PA-200.&lt;/P&gt;&lt;P&gt;- We cannot ping this interface IP.&lt;/P&gt;&lt;P&gt;- There's no other interface in this security zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, traffic log is showing that there's some traffic in this interface. How is it possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I attach some pictures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank for your answers!&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-09-18_13h08_22.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8454_2013-09-18_13h08_22.png" style="width: 620px; height: 160px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-09-18_13h12_02.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8455_2013-09-18_13h12_02.png" style="font-size: 10pt; line-height: 1.5em; width: 620px; height: 212px;" /&gt;&lt;IMG alt="2013-09-18_13h13_14.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8456_2013-09-18_13h13_14.png" style="font-size: 10pt; line-height: 1.5em; width: 620px; height: 432px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Sep 2013 11:16:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logged-in-an-interface-in-down-state/m-p/22811#M16672</guid>
      <dc:creator>dept_tec_bcn</dc:creator>
      <dc:date>2013-09-18T11:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic logged in an interface in down state</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logged-in-an-interface-in-down-state/m-p/22812#M16673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These are most probably sessions which were started before the interface was shutdown. They stay in the session table until they idle out and then produce the session end log entry.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Sep 2013 11:56:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logged-in-an-interface-in-down-state/m-p/22812#M16673</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2013-09-18T11:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic logged in an interface in down state</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logged-in-an-interface-in-down-state/m-p/22813#M16674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As you can see from the log details, the session start time was at 10:42 and you have the log option set to log at session end (Type: end), log generated time: 12:09. So as pointed out by Anon, these might be the old sessions which timed out much later and a log was generated at session end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Aditi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Sep 2013 15:37:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logged-in-an-interface-in-down-state/m-p/22813#M16674</guid>
      <dc:creator>apasupulati</dc:creator>
      <dc:date>2013-09-18T15:37:26Z</dc:date>
    </item>
  </channel>
</rss>

