<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What mean is 'no destination zone from forwarding' on global counters? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-mean-is-no-destination-zone-from-forwarding-on-global/m-p/24106#M17565</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Every packet, including those that match an existing session, gets a route look-up. My recommendation is to ensure that there is a correct route for each IP in question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; test routing fib-lookup virtual-router &amp;lt;VR_NAME&amp;gt; ip &amp;lt;IP_ADDRESS&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do this for both directions, and ensure that the destination interface matches the correct zone. If not, you'll want to either add a static route, update whatever dynamic routing you use, or modify your interface zone configuration to ensure the destination on the return path is pointing to the correct zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 29 Nov 2013 15:26:27 GMT</pubDate>
    <dc:creator>gwesson</dc:creator>
    <dc:date>2013-11-29T15:26:27Z</dc:date>
    <item>
      <title>What mean is 'no destination zone from forwarding' on global counters?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-mean-is-no-destination-zone-from-forwarding-on-global/m-p/24105#M17564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I failed to install FWs to custom.&lt;/P&gt;&lt;P&gt;The FW was L3 mode with two interface(untrust , trust).&lt;/P&gt;&lt;P&gt;When I installed inline, from untrust traffic did not go through to trust.&lt;/P&gt;&lt;P&gt;Destination IP was just trust zone. In addition, FW did not have nat , vpn and protection configurations and security police was allow.&lt;/P&gt;&lt;P&gt;At that time, I found out strange traffic logs and global counters.&lt;/P&gt;&lt;P&gt;This traffic logs was source zone untrust , destination zone untrust , action allow , packet-received 897K and packet-sent 0.&lt;/P&gt;&lt;P&gt;Destination IP was included trust zone. but destination zone was utrust.&lt;/P&gt;&lt;P&gt;Also, 'no destination zone from forwarding' counter on global counters was increasing too many.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please somebody help me for explain this traffic log and this counter.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Nov 2013 07:24:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-mean-is-no-destination-zone-from-forwarding-on-global/m-p/24105#M17564</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-11-27T07:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: What mean is 'no destination zone from forwarding' on global counters?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-mean-is-no-destination-zone-from-forwarding-on-global/m-p/24106#M17565</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Every packet, including those that match an existing session, gets a route look-up. My recommendation is to ensure that there is a correct route for each IP in question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; test routing fib-lookup virtual-router &amp;lt;VR_NAME&amp;gt; ip &amp;lt;IP_ADDRESS&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do this for both directions, and ensure that the destination interface matches the correct zone. If not, you'll want to either add a static route, update whatever dynamic routing you use, or modify your interface zone configuration to ensure the destination on the return path is pointing to the correct zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Nov 2013 15:26:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-mean-is-no-destination-zone-from-forwarding-on-global/m-p/24106#M17565</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2013-11-29T15:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: What mean is 'no destination zone from forwarding' on global counters?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-mean-is-no-destination-zone-from-forwarding-on-global/m-p/24107#M17566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seems like you are trying to allow traffic inbound from outside. &lt;/P&gt;&lt;P&gt;In that case the NAT will be untrust to untrust. &lt;/P&gt;&lt;P&gt;Following doc explains how to create destination NAT on page 15&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;https://live.paloaltonetworks.com/docs/DOC-1517&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Dec 2013 17:06:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-mean-is-no-destination-zone-from-forwarding-on-global/m-p/24107#M17566</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-12-02T17:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: What mean is 'no destination zone from forwarding' on global counters?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-mean-is-no-destination-zone-from-forwarding-on-global/m-p/24108#M17567</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Greg and Numan,&lt;/P&gt;&lt;P&gt;I had checked routing-table and fib-table but it is no problem.&lt;/P&gt;&lt;P&gt;And FW doesn't have NAT setting.&lt;/P&gt;&lt;P&gt;I have tested again on my lab.&lt;/P&gt;&lt;P&gt;This global count is increasing when interface down or no routing-table for destination ip.&lt;/P&gt;&lt;P&gt;Maybe, &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I look like wrong negotiation for speed and duplex when it happened.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Dec 2013 02:57:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-mean-is-no-destination-zone-from-forwarding-on-global/m-p/24108#M17567</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-12-03T02:57:32Z</dc:date>
    </item>
  </channel>
</rss>

