<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upgrade to 5.0.14-h3 stopped traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-0-14-h3-stopped-traffic/m-p/48790#M35932</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="4850" data-username="jambulo" href="https://live.paloaltonetworks.com/people/jambulo" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;jambulo&lt;/A&gt;&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have come across this issue with 5.0.14-h3 software code. It is currently being investigated. It would helpful to us if you can open a support ticket and provide the necessary data. This issue needs to be investigated to find the root cause.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Oct 2014 03:09:01 GMT</pubDate>
    <dc:creator>tshiv</dc:creator>
    <dc:date>2014-10-21T03:09:01Z</dc:date>
    <item>
      <title>Upgrade to 5.0.14-h3 stopped traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-0-14-h3-stopped-traffic/m-p/48784#M35926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We just attempted to upgrade some 5020's to 5.0.14-h3(mainly to patch the evasion vulnerability) and quickly found that the upgrade broke traffic traversing the firewall.&amp;nbsp; During the short period of time it we were running on 5.0.14-h3, there were a whole lot of "incomplete" sessions for TCP and a lot of UDP sessions with zero packets received.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone else have experience with 5.0.14-h3?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2014 15:25:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-0-14-h3-stopped-traffic/m-p/48784#M35926</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2014-10-20T15:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to 5.0.14-h3 stopped traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-0-14-h3-stopped-traffic/m-p/48785#M35927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you might have asymmetric traffic in network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it among non-internet zone, if yes you might want to try following command.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier; font-size: 10pt; line-height: 1.5em;"&gt;show counter global | match syn&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier; font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5em; color: #3b3b3b; font-size: 10pt; font-family: 'courier new', courier;"&gt;This will help us to determine potential &lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;asymmetric&lt;/SPAN&gt;&lt;SPAN style="line-height: 1.5em; color: #3b3b3b; font-size: 10pt; font-family: 'courier new', courier;"&gt; routing issue and fix. If values are high than apply following command.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; configure&lt;/P&gt;&lt;P&gt;# set deviceconfig setting session tcp-reject-non-syn no&lt;/P&gt;&lt;P&gt;# commit&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5em; color: #3b3b3b; font-size: 10pt; font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5em; color: #3b3b3b; font-size: 10pt; font-family: 'courier new', courier;"&gt;Refer following document for more help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5em; color: #3b3b3b; font-size: 10pt; font-family: 'courier new', courier;"&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1260"&gt;SYN-ACK Issues with Asymmetric Routing&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;Hardik Shah&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2014 15:40:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-0-14-h3-stopped-traffic/m-p/48785#M35927</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-20T15:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to 5.0.14-h3 stopped traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-0-14-h3-stopped-traffic/m-p/48786#M35928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jambulo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can check if the configured interfaces are having proper arp entries on the PAN. Also, check the arp entries on the connected switches/routers. If the device is in HA mode, and if the connected devices didn't update the arp entries to the active device, you can try to clear the arp entries on those devices so that they learn the arp entries freshly. You can also try to run test gratuitous arp command to send out grat arps that will force connected devices to update their arp entries.&lt;/P&gt;&lt;P&gt;&amp;gt;test arp gratuitous ip &amp;lt;ip/netmask&amp;gt; interface &amp;lt;interface&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Make sure the traffic is hitting the correct rules. For ex, if group-mapping is used in security rules, make sure that the users are properly identified so that they hit correct rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dileep&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2014 16:20:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-0-14-h3-stopped-traffic/m-p/48786#M35928</guid>
      <dc:creator>dreputi</dc:creator>
      <dc:date>2014-10-20T16:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to 5.0.14-h3 stopped traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-0-14-h3-stopped-traffic/m-p/48787#M35929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jabulo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following commands should help.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;# set deviceconfig setting session tcp-reject-non-syn no |yes&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;------- asymmetric routing&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;# set deviceconfig setting tcp asymmetric-path bypass | drop&amp;nbsp; &amp;lt;--------- asymmetric flow of packets&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;I am very positive its following issue.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A href="https://live.paloaltonetworks.com/message/45621"&gt;6.0.5 h3 explanation&lt;/A&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;To verify same, provide us following output.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: 'courier new', courier;"&gt;show counter global | match syn&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: 'courier new', courier;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: 'courier new', courier;"&gt;Hardik Shah&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2014 17:08:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-0-14-h3-stopped-traffic/m-p/48787#M35929</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-20T17:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to 5.0.14-h3 stopped traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-0-14-h3-stopped-traffic/m-p/48788#M35930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the output from&amp;nbsp; "show counter global | match syn"&lt;/P&gt;&lt;P&gt;flow_inter_cpu_nat_mismatch&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 22592&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; flow&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pktproc&amp;nbsp;&amp;nbsp; Inter-CPU NAT sync mismatch&lt;/P&gt;&lt;P&gt;ha_nat_policy_mismatch&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 104559&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 warn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; system&amp;nbsp;&amp;nbsp;&amp;nbsp; HA NAT session sync: policy mismatch&lt;/P&gt;&lt;P&gt;ha_nat_pool_mismatch&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 814&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 warn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; system&amp;nbsp;&amp;nbsp;&amp;nbsp; HA NAT session sync: IP/port pool state mismatch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2014 20:27:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-0-14-h3-stopped-traffic/m-p/48788#M35930</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2014-10-20T20:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to 5.0.14-h3 stopped traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-0-14-h3-stopped-traffic/m-p/48789#M35931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jambulo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This doesnt look like a asymmetric routing issue. Please provide us traffic log snapshot. Make sure its enlarged view.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2014 20:30:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-0-14-h3-stopped-traffic/m-p/48789#M35931</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-20T20:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to 5.0.14-h3 stopped traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-0-14-h3-stopped-traffic/m-p/48790#M35932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="4850" data-username="jambulo" href="https://live.paloaltonetworks.com/people/jambulo" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;jambulo&lt;/A&gt;&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have come across this issue with 5.0.14-h3 software code. It is currently being investigated. It would helpful to us if you can open a support ticket and provide the necessary data. This issue needs to be investigated to find the root cause.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Oct 2014 03:09:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-0-14-h3-stopped-traffic/m-p/48790#M35932</guid>
      <dc:creator>tshiv</dc:creator>
      <dc:date>2014-10-21T03:09:01Z</dc:date>
    </item>
  </channel>
</rss>

