<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PAN2050 data stops when global protect client downloaded in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan2050-data-stops-when-global-protect-client-downloaded/m-p/44696#M32810</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;Has anyone seen this issue? &lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif; font-size: 15px;"&gt;We have had this issue for months with no relief and am at my wits end. Forgive me if my frustration comes through......&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-size: 15px; font-family: Calibri, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-size: 15px; font-family: Calibri, sans-serif;"&gt;what happens is this:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif; font-size: 11pt;"&gt;A remote user will login to VPN web page and click the link to download the GP client then..... *poof*! All traffic in every direction stops. ALL the PAN layer 3 interfaces stop pinging. everything except management plane. It stays like this for about 5 minutes then *poof*! &lt;/SPAN&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif; font-size: 15px;"&gt;everything&lt;/SPAN&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif;"&gt;&lt;SPAN style="font-size: 11pt;"&gt; is back. NO errors, NOTHING. The users download has failed but i cant deal with that &lt;/SPAN&gt;&lt;SPAN style="font-size: 15px;"&gt;because&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt;"&gt; my phone is ringing like crazy.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="color: #1f497d; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;I know what your thinking, its you, not PAN.&amp;nbsp; Well, &lt;/SPAN&gt;&lt;SPAN style="color: #1f497d; font-size: 15px; font-family: Calibri, sans-serif;"&gt;keep in mind we run these checks against the PAN appliance from &lt;SPAN style="text-decoration: underline;"&gt;every&lt;/SPAN&gt; direction(dmz,internal,etc). And from each direction we show PAN’s layer 3 interfaces all going dark(no pings) at the same. Crazy right? Im saying this is&amp;nbsp; not just “TRUST” side but also&amp;nbsp; from the “DMZ” side AND External side. all angles, different networks, switches, everything. its as if&amp;nbsp; PAN appliance disappears from network. EXCEPT management plane.&amp;nbsp; which shows no errors. zero traffic, but no errors. HA! Oh btw, the directly connected switches are not related and have redundant power.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt; we even &lt;/SPAN&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif; font-size: 11pt; line-height: 1.5em;"&gt;received a new RMA PA-2050 appliance and updated all PANOS software to the latest versions., we Imported our configuration snapshot and moved cables over to appliance around 4pm yesterday….by &lt;/SPAN&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif; font-size: 11pt; line-height: 1.5em;"&gt;9:15 pm the appliance demonstrated the exact same behavior. That is, &lt;/SPAN&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif; font-size: 11pt; line-height: 1.5em; text-decoration: underline;"&gt;All traffic in all direction stopped for about 5 minutes when someone initiated a download of the VPN client software&lt;/SPAN&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif; font-size: 11pt; line-height: 1.5em;"&gt;. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;before you ask(Forgive me if my frustration comes through......):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes, The current version is installed. This problem has been with us for a LONG time so this issue has existed in every version of 6.x.x. at least. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;yes, i have factory reset the appliance and reloaded config.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;no, it does not happen every-time the client is downloaded, just sometimes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no, the PAN is not being utilized at or near its stated throughput (in fact this will happen late at night too when nearly no load is on the appliance)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes, i have a case open with pan support. for months in fact.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NO, I did not check my switch on the ________ zone/side for setting _______. Listen, i have different model switches (from different manf) on each zone. they are not connected, and I have redundant power supplies, if you think there is a chance my 3 separate unrelated switches all failed in same way at same time then.... well, just think about it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Jan 2015 15:31:21 GMT</pubDate>
    <dc:creator>LCMember2900</dc:creator>
    <dc:date>2015-01-16T15:31:21Z</dc:date>
    <item>
      <title>PAN2050 data stops when global protect client downloaded</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan2050-data-stops-when-global-protect-client-downloaded/m-p/44696#M32810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;Has anyone seen this issue? &lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif; font-size: 15px;"&gt;We have had this issue for months with no relief and am at my wits end. Forgive me if my frustration comes through......&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-size: 15px; font-family: Calibri, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-size: 15px; font-family: Calibri, sans-serif;"&gt;what happens is this:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif; font-size: 11pt;"&gt;A remote user will login to VPN web page and click the link to download the GP client then..... *poof*! All traffic in every direction stops. ALL the PAN layer 3 interfaces stop pinging. everything except management plane. It stays like this for about 5 minutes then *poof*! &lt;/SPAN&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif; font-size: 15px;"&gt;everything&lt;/SPAN&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif;"&gt;&lt;SPAN style="font-size: 11pt;"&gt; is back. NO errors, NOTHING. The users download has failed but i cant deal with that &lt;/SPAN&gt;&lt;SPAN style="font-size: 15px;"&gt;because&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt;"&gt; my phone is ringing like crazy.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="color: #1f497d; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;I know what your thinking, its you, not PAN.&amp;nbsp; Well, &lt;/SPAN&gt;&lt;SPAN style="color: #1f497d; font-size: 15px; font-family: Calibri, sans-serif;"&gt;keep in mind we run these checks against the PAN appliance from &lt;SPAN style="text-decoration: underline;"&gt;every&lt;/SPAN&gt; direction(dmz,internal,etc). And from each direction we show PAN’s layer 3 interfaces all going dark(no pings) at the same. Crazy right? Im saying this is&amp;nbsp; not just “TRUST” side but also&amp;nbsp; from the “DMZ” side AND External side. all angles, different networks, switches, everything. its as if&amp;nbsp; PAN appliance disappears from network. EXCEPT management plane.&amp;nbsp; which shows no errors. zero traffic, but no errors. HA! Oh btw, the directly connected switches are not related and have redundant power.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt; we even &lt;/SPAN&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif; font-size: 11pt; line-height: 1.5em;"&gt;received a new RMA PA-2050 appliance and updated all PANOS software to the latest versions., we Imported our configuration snapshot and moved cables over to appliance around 4pm yesterday….by &lt;/SPAN&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif; font-size: 11pt; line-height: 1.5em;"&gt;9:15 pm the appliance demonstrated the exact same behavior. That is, &lt;/SPAN&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif; font-size: 11pt; line-height: 1.5em; text-decoration: underline;"&gt;All traffic in all direction stopped for about 5 minutes when someone initiated a download of the VPN client software&lt;/SPAN&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif; font-size: 11pt; line-height: 1.5em;"&gt;. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;before you ask(Forgive me if my frustration comes through......):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes, The current version is installed. This problem has been with us for a LONG time so this issue has existed in every version of 6.x.x. at least. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;yes, i have factory reset the appliance and reloaded config.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;no, it does not happen every-time the client is downloaded, just sometimes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no, the PAN is not being utilized at or near its stated throughput (in fact this will happen late at night too when nearly no load is on the appliance)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes, i have a case open with pan support. for months in fact.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NO, I did not check my switch on the ________ zone/side for setting _______. Listen, i have different model switches (from different manf) on each zone. they are not connected, and I have redundant power supplies, if you think there is a chance my 3 separate unrelated switches all failed in same way at same time then.... well, just think about it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jan 2015 15:31:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan2050-data-stops-when-global-protect-client-downloaded/m-p/44696#M32810</guid>
      <dc:creator>LCMember2900</dc:creator>
      <dc:date>2015-01-16T15:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: PAN2050 data stops when global protect client downloaded</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan2050-data-stops-when-global-protect-client-downloaded/m-p/44697#M32811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Paul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a few questions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;What is the software version. Type the command &amp;gt; show system info and paste the output&lt;/LI&gt;&lt;LI&gt;When the GP download is initiated, did you do a packet capture with source and destination filter set? If yes, could you please paste a screen shot of the packet capture.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are the steps to do a packet capture&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL style="list-style-type: decimal;"&gt;&lt;LI&gt;Need to setup the filters for the traffic we are interested in. To do this, execute the following steps:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Navigate to Monitor--Packet Capture&lt;/P&gt;&lt;P&gt;Click 'Manage Filters'&lt;/P&gt;&lt;P&gt;Set Filter ID 1 to be the source IP and destination IP of traffic you feel is affected ( leave all other fields blank )&lt;/P&gt;&lt;P&gt;Set Filter ID 2 to be the exact inverse of what you did in step 3 (destination IP in source field, Source IP in destination field) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Setup up the captures&lt;/P&gt;&lt;P&gt;Create and name the file stage for a packet capture on all the stages (receive, transmit, firewall and drop) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Enable filters and captures&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set filter on&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set capture on &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 4. &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;open 2 CLI windows&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;on 1 run the following command to look at the counter ( make sure it run this command once before running the traffic)&lt;/P&gt;&lt;P&gt;show counter global filter packet-filter yes delta yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the 2nd window run the following command to look at he sessions&lt;/P&gt;&lt;P&gt;show session all filter source &amp;lt;ip address&amp;gt; destination &amp;lt;ip address&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5.&amp;nbsp; Now download the client while it is failing to look at the counters and captures and sessions to determine what is causing the issue. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6.&amp;nbsp; Once you have finished testing and capturing. Make sure to turn off the debugs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen Global protect client download freeze issues in the virtual firewalls and one Shot in the dark is to bypass tcp asymmetric path. For testing purpose please run the following command and try a test to download the global protect client from the portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin# set deviceconfig setting tcp asymmetric-path bypass&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: Please mark any helpful or Correct answers!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Khan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jan 2015 16:53:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan2050-data-stops-when-global-protect-client-downloaded/m-p/44697#M32811</guid>
      <dc:creator>kattaullah</dc:creator>
      <dc:date>2015-01-16T16:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: PAN2050 data stops when global protect client downloaded</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan2050-data-stops-when-global-protect-client-downloaded/m-p/44698#M32812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using default page or custom page for GP?&lt;/P&gt;&lt;P&gt;What exact software version is being used?&lt;/P&gt;&lt;P&gt;Did you import config on same revision of RMA unit?&lt;/P&gt;&lt;P&gt;Does the problem exist in older rev too?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know too many questions but it can give some hints.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Jan 2015 01:17:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan2050-data-stops-when-global-protect-client-downloaded/m-p/44698#M32812</guid>
      <dc:creator>ukhapre</dc:creator>
      <dc:date>2015-01-24T01:17:48Z</dc:date>
    </item>
  </channel>
</rss>

