<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issue/m-p/26133#M19084</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This link contains helpful information to address the issue. &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1260"&gt;https://live.paloaltonetworks.com/docs/DOC-1260&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Disabling tcp-reject-non-syn solves the assymetric routing problem. However, I am not sure about the security implications it could have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Feb 2011 08:02:21 GMT</pubDate>
    <dc:creator>ajripa</dc:creator>
    <dc:date>2011-02-22T08:02:21Z</dc:date>
    <item>
      <title>Routing issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issue/m-p/26131#M19082</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an issue I faced before with OpenBSD's PF Firewall but I am not able to solve with PAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My topology is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;INET ----- PAN ---- DMZ ---- Balancer ---- Balanced Servers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LAN&lt;/P&gt;&lt;P&gt;The domain controllers for the DMZ domain are located in DMZ and their default gateway is PAN. The route to reach the balanced servers network is configured in PAN and I can reach the balanced servers network either from LAN and from DMZ. However, although I can ping from the domain controllers in the DMZ to the balanced servers and viceversa, I am facing some validations issues. These issues dissapear when I configure a static route on the domain controllers to reach the balanced servers directly through the balancer. I know it's weird to go through PAN to reach balanced servers from DMZ, but I don't like adding static routes to servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could solve the problem with PF modifiying the stateful behaviour.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Feb 2011 12:46:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issue/m-p/26131#M19082</guid>
      <dc:creator>ajripa</dc:creator>
      <dc:date>2011-02-21T12:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Routing issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issue/m-p/26132#M19083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks like the Palo Alto firewall is only seeing half of the flows from the DMZ servers to the Balanced Servers.&amp;nbsp; The initial packet from the DMZ server goes to the firewall, which then sends it through the Balancer.&amp;nbsp; When the Balanced Servers send the response back to the Balancer, they see the destination as a connected network, so instead of sending the traffic back to the firewall, it gets sent directly to the DMZ server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a type of asymmetric route.&amp;nbsp; You can either put static routes on your servers, as you have done, or you can put more specific routes to those servers on the Balancer with a next hop of the firewall.&amp;nbsp; Another option would be to put another pair of firewall ports (L3 or Vwire) in front of the Balancer so you can fully inspect the traffic between the DMZ servers and the Balanced Servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Feb 2011 22:10:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issue/m-p/26132#M19083</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-02-21T22:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Routing issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issue/m-p/26133#M19084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This link contains helpful information to address the issue. &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1260"&gt;https://live.paloaltonetworks.com/docs/DOC-1260&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Disabling tcp-reject-non-syn solves the assymetric routing problem. However, I am not sure about the security implications it could have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Feb 2011 08:02:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issue/m-p/26133#M19084</guid>
      <dc:creator>ajripa</dc:creator>
      <dc:date>2011-02-22T08:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: Routing issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issue/m-p/26134#M19085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Answered.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Mar 2011 09:50:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issue/m-p/26134#M19085</guid>
      <dc:creator>ajripa</dc:creator>
      <dc:date>2011-03-01T09:50:06Z</dc:date>
    </item>
  </channel>
</rss>

