<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to pass Cisco CDP traffic through a  Paloalto in virtual wire mode in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-pass-cisco-cdp-traffic-through-a-paloalto-in-virtual-wire/m-p/46481#M34170</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anything has changed since 2011?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Jan 2014 13:39:24 GMT</pubDate>
    <dc:creator>KovalenkoDmitiriy</dc:creator>
    <dc:date>2014-01-27T13:39:24Z</dc:date>
    <item>
      <title>how to pass Cisco CDP traffic through a  Paloalto in virtual wire mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-pass-cisco-cdp-traffic-through-a-paloalto-in-virtual-wire/m-p/46475#M34164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello everyone,&lt;BR /&gt; I think the title of my subject is explisite, I want to get &lt;EM&gt;Cisco Discovery Protocol&lt;/EM&gt; (CDP)&amp;nbsp; traffic through my palo alto, which is in virtual wire the problem is that frame cdp does not contain IP header so my the question is how to get it through a firewall.&lt;BR /&gt; I did catch the traffic levels I see the traffic coming into the firewall and I see it being simply droped&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jul 2011 11:57:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-pass-cisco-cdp-traffic-through-a-paloalto-in-virtual-wire/m-p/46475#M34164</guid>
      <dc:creator>ext22</dc:creator>
      <dc:date>2011-07-25T11:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: how to pass Cisco CDP traffic through a  Paloalto in virtual wire mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-pass-cisco-cdp-traffic-through-a-paloalto-in-virtual-wire/m-p/46476#M34165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ext22,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check your Traffic Log.&amp;nbsp; Which rule is denying the traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this traffic moving between interfaces in the same zone?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it moving between two different zones?&amp;nbsp; Do you have a policy defined to allow traffic between those zones?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You shouldn't need anything more than the proper security policy configuration for this to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Jared&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jul 2011 17:46:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-pass-cisco-cdp-traffic-through-a-paloalto-in-virtual-wire/m-p/46476#M34165</guid>
      <dc:creator>jdavis</dc:creator>
      <dc:date>2011-07-25T17:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: how to pass Cisco CDP traffic through a  Paloalto in virtual wire mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-pass-cisco-cdp-traffic-through-a-paloalto-in-virtual-wire/m-p/46477#M34166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/people/jdavis" id="jive-669423 539 708 140 067 334"&gt;jdavis&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The traffic has to pass between two interfaces in diffirents zone, you tell me that i have to make a polcie to allow CDP packets but CDP packets don't have any IP or TCP header how can i made a police to allow this type of traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ouassil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jul 2011 15:27:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-pass-cisco-cdp-traffic-through-a-paloalto-in-virtual-wire/m-p/46477#M34166</guid>
      <dc:creator>ext22</dc:creator>
      <dc:date>2011-07-27T15:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: how to pass Cisco CDP traffic through a  Paloalto in virtual wire mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-pass-cisco-cdp-traffic-through-a-paloalto-in-virtual-wire/m-p/46478#M34167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;CDP is a multicast protocol. Have you enabled "multicast firewalling" on the vwire? That ought to allow the traffic. The PAN does not pass multicast traffic in its default configuration state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jul 2011 16:32:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-pass-cisco-cdp-traffic-through-a-paloalto-in-virtual-wire/m-p/46478#M34167</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-07-27T16:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: how to pass Cisco CDP traffic through a  Paloalto in virtual wire mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-pass-cisco-cdp-traffic-through-a-paloalto-in-virtual-wire/m-p/46479#M34168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did some more reading on CDP and found this Cisco.com web page (&lt;A href="http://www.cisco.com/en/US/products/hw/switches/ps663/products_tech_note09186a0080094713.shtml#cdp"&gt;http://www.cisco.com/en/US/products/hw/switches/ps663/products_tech_note09186a0080094713.shtml#cdp&lt;/A&gt;).&amp;nbsp; It states, "CDP uses SNAP encapsulation with type code 2000".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately, it looks like there is not a solution to your issue.&amp;nbsp; The release notes for PAN-OS 3.1.9 and 4.0.4 both list a known issue, bug 908.&amp;nbsp; It reads, "[908] LLC SNAP/802.2 packets do not pass through the device".&amp;nbsp; There are no plans to change this at this time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Jared&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jul 2011 17:15:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-pass-cisco-cdp-traffic-through-a-paloalto-in-virtual-wire/m-p/46479#M34168</guid>
      <dc:creator>jdavis</dc:creator>
      <dc:date>2011-07-27T17:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: how to pass Cisco CDP traffic through a  Paloalto in virtual wire mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-pass-cisco-cdp-traffic-through-a-paloalto-in-virtual-wire/m-p/46480#M34169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jul 2011 14:30:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-pass-cisco-cdp-traffic-through-a-paloalto-in-virtual-wire/m-p/46480#M34169</guid>
      <dc:creator>ext22</dc:creator>
      <dc:date>2011-07-28T14:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: how to pass Cisco CDP traffic through a  Paloalto in virtual wire mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-pass-cisco-cdp-traffic-through-a-paloalto-in-virtual-wire/m-p/46481#M34170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anything has changed since 2011?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 13:39:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-pass-cisco-cdp-traffic-through-a-paloalto-in-virtual-wire/m-p/46481#M34170</guid>
      <dc:creator>KovalenkoDmitiriy</dc:creator>
      <dc:date>2014-01-27T13:39:24Z</dc:date>
    </item>
  </channel>
</rss>

