<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active/Active traffic log. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-traffic-log/m-p/4315#M3195</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks cstancill,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Each device(primary and secondary) has different denied log not same log.&lt;/P&gt;&lt;P&gt;For example, Primary device has 'A' session denied log but secondary device doesn't have it. &lt;/P&gt;&lt;P&gt;Secondary device has 'B' session denied log but primary device doesn't.&lt;/P&gt;&lt;P&gt;I think that only session setup device has denied log.&lt;/P&gt;&lt;P&gt;What do you think it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cheon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Dec 2013 07:34:31 GMT</pubDate>
    <dc:creator>KiCheon.Lee</dc:creator>
    <dc:date>2013-12-18T07:34:31Z</dc:date>
    <item>
      <title>Active/Active traffic log.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-traffic-log/m-p/4311#M3191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I knew session owner generate traffic log.&lt;/P&gt;&lt;P&gt;Does session setup device generated traffic log&amp;nbsp; If a session is denied L4 processing before L7 processing???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Network Diagram&lt;/P&gt;&lt;P&gt;Router#1(Power-OFF) ------ Router#2(Power ON)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FW#1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FW#2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; BB#1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; BB#2&lt;/P&gt;&lt;P&gt;*Router#1 has problem. So It is power-off status.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FW configuration&lt;/P&gt;&lt;P&gt;Session owner : first-packet&lt;/P&gt;&lt;P&gt;Session setup : ip-modulo&lt;/P&gt;&lt;P&gt;rule01 on security rule : source zone = untrust , source IP = any , destination zone = trust , destination IP = 192.168.1.1 &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;, service = any , application = any , action = deny.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If rule01 actions is allow, there are rule01 traffic logs in only FW#2 because is session owner. Of course, session setup is load-sharing between FW#1 and FW#2.&lt;/P&gt;&lt;P&gt;But rule01 action is deny and I have seen there are denied traffic logs in all FWs. So I think session setup device can generate traffic logs. &lt;/P&gt;&lt;P&gt;Is it TRUE?? Please anybody know me!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Summary.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Some traffics go to FW#1 through FW#2 and across HA3 Link for session setup.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Another traffics stay FW#2 for session setup.&lt;/P&gt;&lt;P&gt;But these traffics are denied by rule01 during L4 processing before L7 processing.&lt;/P&gt;&lt;P&gt;So There are denied traffic logs in all FWs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Dec 2013 10:26:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-traffic-log/m-p/4311#M3191</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-12-12T10:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Active/Active traffic log.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-traffic-log/m-p/4312#M3192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cheon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Logging on both devices in A/A when traffic is denied due to L4 to L7 processing is expected behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's a simple flow of events to help you understand the logic behind this behavior:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. First packet comes in on Primary device for instance. Primary is session owner (First packet) and Secondary is chosen for setup (IP modulo)&lt;/P&gt;&lt;P&gt;2. Secondary sets up the session (L1-L3) while Primary does the L4-L7 processing&lt;/P&gt;&lt;P&gt;3. At this point, this same session is represented by unique session IDs, one on the Primary and another on the Secondary&lt;/P&gt;&lt;P&gt;4. If the Primary device decides to discard the session based on its L4-L7 processing, then both session IDs on both devices need to be in the DISCARD state&lt;/P&gt;&lt;P&gt;5. After these discard sessions time out, each device needs to log the action of its respective session in its traffic logs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that the logic is a little different if the security policy permits the traffic.&lt;/P&gt;&lt;P&gt;In this case, only session owner logs the traffic because it's the device that is "responsible" for the session and its traffic.&lt;/P&gt;&lt;P&gt;When the policy is deny, no traffic really goes through the pair and so both devices have to log why neither of them allowed the session to live.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;tasonibare&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Dec 2013 19:25:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-traffic-log/m-p/4312#M3192</guid>
      <dc:creator>tasonibare</dc:creator>
      <dc:date>2013-12-14T19:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: Active/Active traffic log.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-traffic-log/m-p/4313#M3193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, taonibare.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have more questions.&lt;/P&gt;&lt;P&gt;1. When primary device receives first packet, primary device copy first packet then send it to secondary device on HA3 link. Right?&lt;/P&gt;&lt;P&gt;2. I know until now that session owner is only L7 processing and session setup is L1 ~ L4 processing. Do I know incorrect it?&lt;/P&gt;&lt;P&gt;3. There are denied traffic log in both devices. It is same session ID. Right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;KC Lee &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Dec 2013 01:42:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-traffic-log/m-p/4313#M3193</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-12-16T01:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: Active/Active traffic log.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-traffic-log/m-p/4314#M3194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cheon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. That is correct, provided packet forwarding is enabled.&lt;/P&gt;&lt;P&gt;2. This is correct as well.&lt;/P&gt;&lt;P&gt;3. Unfortunately, the actual session ID will be different for each firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Dec 2013 08:10:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-traffic-log/m-p/4314#M3194</guid>
      <dc:creator>cstancill</dc:creator>
      <dc:date>2013-12-16T08:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: Active/Active traffic log.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-traffic-log/m-p/4315#M3195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks cstancill,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Each device(primary and secondary) has different denied log not same log.&lt;/P&gt;&lt;P&gt;For example, Primary device has 'A' session denied log but secondary device doesn't have it. &lt;/P&gt;&lt;P&gt;Secondary device has 'B' session denied log but primary device doesn't.&lt;/P&gt;&lt;P&gt;I think that only session setup device has denied log.&lt;/P&gt;&lt;P&gt;What do you think it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cheon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Dec 2013 07:34:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-traffic-log/m-p/4315#M3195</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-12-18T07:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: Active/Active traffic log.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-traffic-log/m-p/4316#M3196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cheon,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Sorry for the delayed response. For denied logs, you are correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Dec 2013 11:50:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-traffic-log/m-p/4316#M3196</guid>
      <dc:creator>cstancill</dc:creator>
      <dc:date>2013-12-27T11:50:50Z</dc:date>
    </item>
  </channel>
</rss>

