<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: M100 - incorrect Message Authentication Code in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/m100-incorrect-message-authentication-code/m-p/25901#M18897</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As in my original post: When I put my PC in the DMZ (so directly connected), the sites work, so the PA is the problem.&lt;/P&gt;&lt;P&gt;The VM's did not move, the only thing that was changed was the migration from a physical PA to a M-100.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 14 Aug 2013 06:03:03 GMT</pubDate>
    <dc:creator>${userLoginName}</dc:creator>
    <dc:date>2013-08-14T06:03:03Z</dc:date>
    <item>
      <title>M100 - incorrect Message Authentication Code</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/m100-incorrect-message-authentication-code/m-p/25899#M18895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the following setup: A VM100 that has multiple VLANs, for example LAN, Guest and DMZ. In the DMZ are some https websites, hosted on VM's on the same VM server as the M-100.&lt;/P&gt;&lt;P&gt;Everything is working as expected, so internet, DHCP, DNS etc. is all working fine.&lt;/P&gt;&lt;P&gt;However, when connected to the LAN, surfing to a https website in the DMZ results in:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secure Connection Failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; An error occurred during a connection to 10.0.0.49:8000.&lt;/P&gt;&lt;P&gt;SSL received a record with an incorrect Message Authentication Code.&lt;/P&gt;&lt;P&gt;(Error code: ssl_error_bad_mac_read)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have this from both the LAN and the DMZ, and all https sites in my DMZ. When I put my PC in the DMZ, the sites work, so the PA is the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More info:&lt;/P&gt;&lt;P&gt;Eth1: Internet&lt;/P&gt;&lt;P&gt;Eth2: LAN&lt;/P&gt;&lt;P&gt;Eth3.4=DMZ&lt;/P&gt;&lt;P&gt;Eth3.5=Guest&lt;/P&gt;&lt;P&gt;tested in PANOS 5.0.5 and 5.0.6, same issue&lt;/P&gt;&lt;P&gt;The PA has valid licenses.&lt;/P&gt;&lt;P&gt;No drops in the monitor.&lt;/P&gt;&lt;P&gt;Tested with different browsers&lt;/P&gt;&lt;P&gt;No SSL decryption policy at all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First tried with all port groups in promisc allow mode, same issue.&lt;/P&gt;&lt;P&gt;Took PA mac addresses and manually entered them on the VM interfaces (took into account that the first interface is the mgmt port)., same issue.&lt;/P&gt;&lt;P&gt;Turned promisc off on all port groups, same issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Aug 2013 21:47:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/m100-incorrect-message-authentication-code/m-p/25899#M18895</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2013-08-13T21:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: M100 - incorrect Message Authentication Code</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/m100-incorrect-message-authentication-code/m-p/25900#M18896</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bob, if your not using decryption on the PA its likely that its not the firewall causing this. What happens when you browse to the site from a system on the same network segment that does not traverse the PA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did the VM hosting the site move to a different ESX recently? I've seen the certs get screwed up after moving a VM and having to re-install the cert locally.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Aug 2013 22:33:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/m100-incorrect-message-authentication-code/m-p/25900#M18896</guid>
      <dc:creator>jteetsel</dc:creator>
      <dc:date>2013-08-13T22:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: M100 - incorrect Message Authentication Code</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/m100-incorrect-message-authentication-code/m-p/25901#M18897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As in my original post: When I put my PC in the DMZ (so directly connected), the sites work, so the PA is the problem.&lt;/P&gt;&lt;P&gt;The VM's did not move, the only thing that was changed was the migration from a physical PA to a M-100.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 06:03:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/m100-incorrect-message-authentication-code/m-p/25901#M18897</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2013-08-14T06:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: M100 - incorrect Message Authentication Code</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/m100-incorrect-message-authentication-code/m-p/25902#M18898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Got it, I must have missed that part..Are you nating when going between zones? Is 10.0.0.49 the IP of the server you are connecting to or the ip of the PAN? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 16:32:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/m100-incorrect-message-authentication-code/m-p/25902#M18898</guid>
      <dc:creator>jteetsel</dc:creator>
      <dc:date>2013-08-14T16:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: M100 - incorrect Message Authentication Code</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/m100-incorrect-message-authentication-code/m-p/25903#M18899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;10.0.0.0/24 is the DMZ, so the IP 10.0.0.49 is one of the servers. The message says port 8000, but it is the same for https sites on port 443.&lt;/P&gt;&lt;P&gt;Except for the HideNAT to the internet, there is no NAT between subnets. I have just tested with an app override, just to disable all checks and scanning, same result.&lt;/P&gt;&lt;P&gt;I wonder if this a Palo Alto or VM (or combination) problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 21:07:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/m100-incorrect-message-authentication-code/m-p/25903#M18899</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2013-08-15T21:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: M100 - incorrect Message Authentication Code</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/m100-incorrect-message-authentication-code/m-p/25904#M18900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okey I got it working now, but I am absolutely clueless as to why.&lt;/P&gt;&lt;P&gt;I removed the eth3.4 interface, and put the same config on eth4. In the VM settings, I attached the DMZ-vlan to the PA interface eth4.&lt;/P&gt;&lt;P&gt;I am now able to connect to all my https websites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps I should create a support case for this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 14:15:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/m100-incorrect-message-authentication-code/m-p/25904#M18900</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2013-08-16T14:15:48Z</dc:date>
    </item>
  </channel>
</rss>

