<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Possible Issues with 6.0.5-h3 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28576#M20856</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh, thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Oct 2014 07:54:31 GMT</pubDate>
    <dc:creator>pasmartin</dc:creator>
    <dc:date>2014-10-29T07:54:31Z</dc:date>
    <item>
      <title>Possible Issues with 6.0.5-h3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28569#M20849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has anyone discovered any issues with H3? I have an odd issue and am not sure if it has to do with the layer 4 changes in the hotfix to address the evasion issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have upgraded 3 client sites. No issues at 2 of the sites. On the third side, I have an issue. This client has a public web site in a DMZ. The ACL allows it to be directly accessed by the internal network. After the update to H3, you can access the website just fine from across the internet. You cannot access it from the internal network. You can ping the web server just fine. The Traffic log shows Incomplete for the port 80 traffic. Downgrading back to 6.0.5 allows internal users to hit the website in the DMZ just fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Oct 2014 03:51:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28569#M20849</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-10-11T03:51:00Z</dc:date>
    </item>
    <item>
      <title>Re: Possible Issues with 6.0.5-h3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28570#M20850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/12314"&gt;SDorsey&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By any chance is there any asymmetric flow when internal users try to access server in DMZ, because I just saw this in the release notes of 6.0.5-h3:&lt;/P&gt;&lt;P&gt;If you have asymmetric routes in your network, before upgrading to 6.0.5-h3, use the following command to ensure session continuity: &lt;/P&gt;&lt;P&gt;set deviceconfig setting tcp asymmetric-path bypass&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And, if you have attached a zone protection profile, you must also use the&amp;nbsp; following command: &lt;/P&gt;&lt;P&gt;set network profiles zone-protection-profile &amp;lt;profile-name&amp;gt; asymmetric-path [bypass | global]. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you also give us the snapshot of the NAT policy that you are using ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Oct 2014 04:00:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28570#M20850</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-10-11T04:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Possible Issues with 6.0.5-h3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28571#M20851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/28201"&gt;csharma&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you! That fixed it. Apparently the server admins thought it would be okay to dual-home the web server to the internal network. &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Oct 2014 12:08:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28571#M20851</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-10-11T12:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: Possible Issues with 6.0.5-h3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28572#M20852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you add a source nat to interface on the original policy from trust to DMZ that will also fix the asymmetrical flow problem and you can leave the syn checking on.&amp;nbsp; The reason it is asymmetrical is the reply traffic goes out that direct interface.&amp;nbsp; If you source nat the subnet on the firewall the reply will still go back to the firewall to return to the client instead of the direct interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't like to remove basic tcp validity checks on firewalls if at all possible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Oct 2014 15:27:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28572#M20852</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-10-11T15:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: Possible Issues with 6.0.5-h3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28573#M20853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Agreed. I have a request in with the sysadmins to see if we can do away with the dual-homed connection altogether since this is really a design anyway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 12 Oct 2014 23:50:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28573#M20853</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-10-12T23:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: Possible Issues with 6.0.5-h3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28574#M20854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm, is there something I'm missing? I'm getting invalid syntax when trying to run the command "&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;set deviceconfig setting tcp asymmetric-path bypass" &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 11:03:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28574#M20854</guid>
      <dc:creator>pasmartin</dc:creator>
      <dc:date>2014-10-28T11:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: Possible Issues with 6.0.5-h3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28575#M20855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you need to use that in configure mode.&lt;/P&gt;&lt;P&gt;be sure you are.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@PA-VM# set deviceconfig setting tcp asymmetric-path bypass&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 18:05:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28575#M20855</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-10-28T18:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: Possible Issues with 6.0.5-h3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28576#M20856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh, thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Oct 2014 07:54:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-issues-with-6-0-5-h3/m-p/28576#M20856</guid>
      <dc:creator>pasmartin</dc:creator>
      <dc:date>2014-10-29T07:54:31Z</dc:date>
    </item>
  </channel>
</rss>

