<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Guest Wireless - Issues? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32682#M23944</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The cisco-wlc-mobility App-ID covers traffic for wireless lan controllers on udp/16666. If you are seeing this as unknown-udp, please open a case with technical support along with a packet capture.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Mar 2013 06:47:20 GMT</pubDate>
    <dc:creator>SRA</dc:creator>
    <dc:date>2013-03-18T06:47:20Z</dc:date>
    <item>
      <title>Cisco Guest Wireless - Issues?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32679#M23941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recently installed a PAN 5050 cluster in-line between my internal Cisco Wireless Controllers and the DMZ guest access mobility controller and saw the control and data paths flap constantly.&amp;nbsp; I put in an application override rule (along with a number of other measures not related to PAN) and the behaviour seemed to stop.&amp;nbsp; Can anyone confirm whether puting in an application override rule for UDP 16666 has definitively resolved the issue in your environment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To PAN: Is there a proactive way to identify or confirm whether L7 inspection is causing issues with an application?&amp;nbsp; (packets out of sequence, packet in/out difference auditing?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Dec 2012 17:25:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32679#M23941</guid>
      <dc:creator>ttreurniet</dc:creator>
      <dc:date>2012-12-03T17:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Guest Wireless - Issues?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32680#M23942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By checking global counter and/or by making a debug packet-diag to see how packets are handled by the device, You will be able to see if there is a issue.&lt;/P&gt;&lt;P&gt;If you check your traffic logs, how the UDP traffic on port 16666 is seen (unknown-udp ?) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2013 06:00:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32680#M23942</guid>
      <dc:creator>cviaud</dc:creator>
      <dc:date>2013-01-24T06:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Guest Wireless - Issues?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32681#M23943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a similar issue and in the traffic logs we are seeing it as unknown-udp&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Mar 2013 13:55:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32681#M23943</guid>
      <dc:creator>itsecll</dc:creator>
      <dc:date>2013-03-17T13:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Guest Wireless - Issues?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32682#M23944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The cisco-wlc-mobility App-ID covers traffic for wireless lan controllers on udp/16666. If you are seeing this as unknown-udp, please open a case with technical support along with a packet capture.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Mar 2013 06:47:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32682#M23944</guid>
      <dc:creator>SRA</dc:creator>
      <dc:date>2013-03-18T06:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Guest Wireless - Issues?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32683#M23945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif';"&gt;Just yesterday we migrated to a PAN-5050 in active-passive configuration. After that we experienced problems with flapping control and data paths. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif';"&gt;Our setup: 4 remote WLC, 1 centralized Anchor-WLC hosted in a DMZ.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif';"&gt;First of all, it´s important to understand that the etherchannel is always initiated by the host with the lowest MAC-Address. As a result you may want to implement (probably) bidirectional rules for easier handling. The first goal would be to make sure that no packets are dropped by your PAN. As with PAN-OS 5.0.3 and AppVer &lt;SPAN style="color: black; background: #FBFCFC;"&gt;365-1733 (03/26/13)&lt;/SPAN&gt; the Application are detected correctly (etherip and cisco-wlc-mobility) – this is a sitenote realted to the following topic: &lt;/SPAN&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/25148#25148"&gt;https://live.paloaltonetworks.com/message/25148#25148&lt;/A&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: black; background: #FBFCFC;"&gt;. Only one thing see&lt;/SPAN&gt;&lt;SPAN style="background-color: #fbfcfc; color: black; font-family: Arial, sans-serif; font-size: 9pt; line-height: 1.5em;"&gt;ms a little bit weird: The traffic log says that etherip is using Port 0 (I´m not sure about that one).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="6143" alt="PAN_values.PNG" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6143_PAN_values.PNG" style="line-height: 1.5em; color: #000000; font-family: Arial, sans-serif; font-size: 12px; float: right;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: black; background: #FBFCFC;"&gt;In the second step I changed the values for the timeouts on application level (you can set custom values for etherip and&amp;nbsp; cisco-wlc-mobility in the Application Tab). Unfortunately there was no recognizable difference in the behavior.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: black; background: #FBFCFC;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: black; background: #FBFCFC;"&gt;&lt;STRONG&gt;SOLUTION&lt;/STRONG&gt;: I changed the default values for the session timeouts (Device &amp;gt; Setup &amp;gt; Session Tab) and rebooted the foreign as well as the Anchor WLC. After that procedure all Data and Control Paths seem to work fine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: black; background: #FBFCFC;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: black; background: #FBFCFC;"&gt;Additional information: It doesn´t seem like this behavior/problem is Palo Alto specific. In fact I found a topic on the Cisco Support forums where someone is having the same problems with a Checkpoint firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: black; background: #FBFCFC;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: black; background: #FBFCFC;"&gt;It would be nice if someone else in this community could confirm that the described work-around is working.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 13:29:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32683#M23945</guid>
      <dc:creator>VUGD</dc:creator>
      <dc:date>2013-04-03T13:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Guest Wireless - Issues?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32684#M23946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I expect to put our PAN firewalls back into production in approximately 2 weeks.&amp;nbsp; Please share what changes you made to the defaults to under the session tab.&amp;nbsp; I will replicate your settings and report back on the results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As some background on differences - we were previously an active-active cluster when the problem first manifested.&amp;nbsp; The scheduled second attempt will be an active-passive cluster as 5.0.3.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 13:53:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32684#M23946</guid>
      <dc:creator>ttreurniet</dc:creator>
      <dc:date>2013-04-03T13:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Guest Wireless - Issues?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32685#M23947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I changed the default values for sessions according to the picture in my last post (it´s on the right side - grey on grey). &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 13:57:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32685#M23947</guid>
      <dc:creator>VUGD</dc:creator>
      <dc:date>2013-04-03T13:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Guest Wireless - Issues?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32686#M23948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have had our PA-5050 in place with PAN-OS 5.0.4 installed using these settings and guest wireless has been solid for two weeks.&amp;nbsp; Thanks for the post. : )&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 19:00:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-wireless-issues/m-p/32686#M23948</guid>
      <dc:creator>ttreurniet</dc:creator>
      <dc:date>2013-04-24T19:00:20Z</dc:date>
    </item>
  </channel>
</rss>

