<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN in Layer 2 mode and Microsoft NLB in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-in-layer-2-mode-and-microsoft-nlb/m-p/30977#M22667</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Traffic blocked on Palo looks like that:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source IPx, MACx&amp;nbsp; -&amp;gt;&amp;nbsp;&amp;nbsp; Dest: IP virtual,&lt;STRONG&gt; MAC virtual&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SYN&lt;/P&gt;&lt;P&gt;Source: IP virtual, &lt;STRONG&gt;MAC real&lt;/STRONG&gt;&amp;nbsp; -&amp;gt;&amp;nbsp;&amp;nbsp; Dest: IPx, MACx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SYN ACK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does Palo drop session because is getting response from different MAC address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And why NLB works ok on virtual-wire configurations???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you and regards,&lt;/P&gt;&lt;P&gt;Maja&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Feb 2012 14:26:49 GMT</pubDate>
    <dc:creator>mkopcic</dc:creator>
    <dc:date>2012-02-02T14:26:49Z</dc:date>
    <item>
      <title>PAN in Layer 2 mode and Microsoft NLB</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-in-layer-2-mode-and-microsoft-nlb/m-p/30976#M22666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer configured Palo firewall to work in Layer 2 mode to protect VLAN. In that VLAN there are two servers in MS NLB configuration. In VLAN configuration in Palo, static MAC entry is configured for virtual MAC address, but that entry isn't displayed with show mac command. See attached picture and listing:&lt;/P&gt;&lt;P&gt;mkopcic@PA-4020&amp;gt; show mac Bridge_4-440 | match 02:bf:0a:0b:08:f8&lt;/P&gt;&lt;P&gt;mkopcic@PA-4020&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Application (HTTP portal) works if real IP adresses are used, but if virtual IP adress is used, application is unreachable. Ping to virutal IP address is working. On Palo I captured dropped packets and saw that Palo is dropping traffic to NLB virtual address. See attached file. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have idea why Palo is dropping traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Maja&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Feb 2012 13:40:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-in-layer-2-mode-and-microsoft-nlb/m-p/30976#M22666</guid>
      <dc:creator>mkopcic</dc:creator>
      <dc:date>2012-02-02T13:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: PAN in Layer 2 mode and Microsoft NLB</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-in-layer-2-mode-and-microsoft-nlb/m-p/30977#M22667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Traffic blocked on Palo looks like that:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source IPx, MACx&amp;nbsp; -&amp;gt;&amp;nbsp;&amp;nbsp; Dest: IP virtual,&lt;STRONG&gt; MAC virtual&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SYN&lt;/P&gt;&lt;P&gt;Source: IP virtual, &lt;STRONG&gt;MAC real&lt;/STRONG&gt;&amp;nbsp; -&amp;gt;&amp;nbsp;&amp;nbsp; Dest: IPx, MACx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SYN ACK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does Palo drop session because is getting response from different MAC address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And why NLB works ok on virtual-wire configurations???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you and regards,&lt;/P&gt;&lt;P&gt;Maja&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Feb 2012 14:26:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-in-layer-2-mode-and-microsoft-nlb/m-p/30977#M22667</guid>
      <dc:creator>mkopcic</dc:creator>
      <dc:date>2012-02-02T14:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: PAN in Layer 2 mode and Microsoft NLB</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-in-layer-2-mode-and-microsoft-nlb/m-p/30978#M22668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maja, I recommend opening a case with Support for further analysis of your issue. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Feb 2012 20:55:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-in-layer-2-mode-and-microsoft-nlb/m-p/30978#M22668</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2012-02-18T20:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: PAN in Layer 2 mode and Microsoft NLB</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-in-layer-2-mode-and-microsoft-nlb/m-p/30979#M22669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;anyone has a solution for that&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Oct 2014 07:16:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-in-layer-2-mode-and-microsoft-nlb/m-p/30979#M22669</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-10-16T07:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: PAN in Layer 2 mode and Microsoft NLB</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-in-layer-2-mode-and-microsoft-nlb/m-p/30980#M22670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We don't use our Palo Altos in L2 mode; but in L3 mode we need to place a static ARP entry mapping the NLB IP address through to the NLB MAC address on the firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This obviously isn't going to apply to an L2 firewall - but do you have a static ARP entry defined on whichever L3 router/devices that are on the same subnet as the NLB address and communicating with it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Oct 2014 07:29:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-in-layer-2-mode-and-microsoft-nlb/m-p/30980#M22670</guid>
      <dc:creator>ajbool</dc:creator>
      <dc:date>2014-10-16T07:29:28Z</dc:date>
    </item>
  </channel>
</rss>

