<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Layer 3 Stops Passing - All PanOS versions incl. 6.1.3 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50645#M37295</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Continuing to have issues with Large-Scale VPN on 6.1.4 with 65 PA-200 satellite sites.&amp;nbsp; It will sit on reconnecting until I manually reconnect the site several times a week. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes the satellite will also lose the seed route until I pop the VPN manually, either that or the gateway will lose the route to the satellite.&amp;nbsp; I either reset the tunnel on the gateway or the satellite seems to bring it back up.&amp;nbsp; So the result is the tunnel monitor route will connect correctly so the site is maybe pingable so your monitoring will say it's up but your users will report no connectivity.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LSVPN is supposed to be less hassle than manually setting all VPN tunnels but it just is not stable and reliable at all.&amp;nbsp; It seems to be getting a little better each release but still I get woken up almost every night with a site offline.&amp;nbsp; If somebody would guarantee 7.0.0 would fix things I would consider moving to it but I would bet it introduces more unreliability than improvements.&amp;nbsp; About half my tickets go unresolved and TAC has no idea why these things are happening.&amp;nbsp; We paid 50 grand for the Global-Protect licensing of which we do not use for remote access because JunOS Pulse is solid, only for LSVPN.&amp;nbsp; I feel like we are the only company using LSVPN, or the only one voicing the instability.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Jun 2015 15:40:20 GMT</pubDate>
    <dc:creator>dusk2dusk</dc:creator>
    <dc:date>2015-06-29T15:40:20Z</dc:date>
    <item>
      <title>Layer 3 Stops Passing - All PanOS versions incl. 6.1.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50632#M37282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have opened this with TAC a while ago but I continue having issues with Layer 3 not passing through the untrust/internet interface at random times.&amp;nbsp; I have had this happen 5 to 10 times on different PA-200's.&amp;nbsp; Some have repeated.&amp;nbsp; I was hoping a firmware upgrade to 6.1.3 would finally fix this but yesterday one of my first 6.1.3 units locked up.&amp;nbsp; Layer 2 is fine.&amp;nbsp; I look in my router and the ARP entry for the PAN is in there.&amp;nbsp; &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I clear ARP table and it repopulates with MAC/IP as the PAN responds correctly.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Rebooting the router doesn't do anything for the PAN to pass Layer 3 again.&amp;nbsp; The only way to get PAN to pass Layer 3 again is a reboot of the PAN itself.&amp;nbsp; We are running LSVPN on all spoke sites for VPN and the only curveball is that my hubs are on older 6.0.5h3 code.&amp;nbsp; Just throwing this out there for discussion in case others have seen it.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Mar 2015 12:37:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50632#M37282</guid>
      <dc:creator>dusk2dusk</dc:creator>
      <dc:date>2015-03-26T12:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 Stops Passing - All PanOS versions incl. 6.1.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50633#M37283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't have a real solution, but you could try just restarting the routing service instead of the entire PAN device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;gt;debug routing restart&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;gt;debug software restart routed&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Mar 2015 12:02:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50633#M37283</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-03-27T12:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 Stops Passing - All PanOS versions incl. 6.1.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50634#M37284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to upgrade hubs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Mar 2015 08:59:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50634#M37284</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2015-03-28T08:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 Stops Passing - All PanOS versions incl. 6.1.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50635#M37285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;panos - We have upgrades to 6.1.3 scheduled for this week.&amp;nbsp; Are there any particular fixes in there that would address what I am seeing?&amp;nbsp; I am also working on applying 6.1.3 to all spokes as well.&amp;nbsp; 6.1.2 is not very stable for us.&amp;nbsp; I guess I want to make sure we're not just throwing spaghetti at the wall just because we have a pot of it.&amp;nbsp; I will try anything but if there are some known issues addressed, I'd like to know.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Mar 2015 19:25:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50635#M37285</guid>
      <dc:creator>dusk2dusk</dc:creator>
      <dc:date>2015-03-29T19:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 Stops Passing - All PanOS versions incl. 6.1.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50636#M37286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now that you are mentioning LSVPN I know that there is an issue with satellites being upgraded to 6.1.2. After upgrade satellites generate an error that the config retrieval from the portal fails and the tunnel never goes up. I suspect that this issue is also in 6.1.3.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Mar 2015 13:51:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50636#M37286</guid>
      <dc:creator>snaft</dc:creator>
      <dc:date>2015-03-30T13:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 Stops Passing - All PanOS versions incl. 6.1.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50637#M37287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had same issue like You, but more often I have issue related to out os system resources&amp;nbsp; on my PA200. In my case its started on 11.2014 when I moved to 6.1.0 and after on 6.1.1 and 6.1.2&lt;/P&gt;&lt;P&gt;Now I'm on 6.1.3 since 2 two days. Is too early to tell is something changed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to support this issue will be fixed in 6.1.4 (I have case opened for this bug)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Mar 2015 17:51:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50637#M37287</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-03-30T17:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 Stops Passing - All PanOS versions incl. 6.1.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50638#M37288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi &lt;A href="https://live.paloaltonetworks.com/u1/29965"&gt;dusk2dusk&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you mind posting more details regarding instability on 6.1.2? We are planning to go from 6.0.3 to 6.1.2, may be 6.1.3, but not sure how stable these two have been so far.&lt;/P&gt;&lt;P&gt;what model of firewall are&amp;nbsp; you using?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 21:29:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50638#M37288</guid>
      <dc:creator>MMCiobanu</dc:creator>
      <dc:date>2015-04-08T21:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 Stops Passing - All PanOS versions incl. 6.1.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50639#M37289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Specifically, we use GlobalProtect LSVPN to connect all 55 current remote sites, going to 70 shortly.&amp;nbsp; Under 6.1.2 on remote sites and 6.0.5h3 at hubs in datacenter we would see intermittent issues where routes to remote sites are not installed in RIB on the hub so tunnel is declared active on both sides but no traffic passing between remote and hub.&amp;nbsp; Also, on satellite remote sites we would see dataplane full lockup on layer 3.&amp;nbsp; So no routing of traffic until reboot of dataplane or entire firewall on remote sites.&amp;nbsp; Layer 2 and management are fine but that's not worth much.&amp;nbsp; . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6.1.3 on hubs and remote sites seems a great combination so far after the past week.&amp;nbsp; If you're considering 6.1.2 I would say either hold off or go to 6.1.3.&amp;nbsp; The "gold standard" is currently 6.0.8 but with LSVPN and versions we had already in production 6.1.3 was the right choice.&amp;nbsp; I'd say at this point at least 90% improvement over prior versions of code with 6.1.3.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 23:26:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50639#M37289</guid>
      <dc:creator>dusk2dusk</dc:creator>
      <dc:date>2015-04-08T23:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 Stops Passing - All PanOS versions incl. 6.1.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50640#M37290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much; we are not using VPNs, yet, on PaloAlto devices. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 23:29:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50640#M37290</guid>
      <dc:creator>MMCiobanu</dc:creator>
      <dc:date>2015-04-08T23:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 Stops Passing - All PanOS versions incl. 6.1.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50641#M37291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would say that the typical manual IPsec VPNs tend to work fine without issue so it is limited to GlobalProtect prior to 6.1.3 but at this point we're solid on this version. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep in mind that there are A LOT of bug fixes in 6.1.3 over 6.1.2 and I would scour the list to make sure whatever way you are utilizing the PANs you are checking off the list in 6.1.3 in case there's a bug.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 23:33:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50641#M37291</guid>
      <dc:creator>dusk2dusk</dc:creator>
      <dc:date>2015-04-08T23:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 Stops Passing - All PanOS versions incl. 6.1.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50642#M37292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One thing I went through as related, make sure you do not have any management services open to the open internet without a management ACL.&amp;nbsp; I had a problem initially where leaving it wide open, there were issues with the root filling up with failure logs etc.&amp;nbsp; I had to have PAN TAC log in and clear it.&amp;nbsp; Once I closed it down so I could only access directly from my datacenter's public IP's, we have not had another issue with resources.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 23:35:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50642#M37292</guid>
      <dc:creator>dusk2dusk</dc:creator>
      <dc:date>2015-04-08T23:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 Stops Passing - All PanOS versions incl. 6.1.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50643#M37293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great. Thank you, I really appreciate it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 23:42:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50643#M37293</guid>
      <dc:creator>MMCiobanu</dc:creator>
      <dc:date>2015-04-08T23:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 Stops Passing - All PanOS versions incl. 6.1.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50644#M37294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also to note there is a known bug with LSVPN where you can get a 'dataplane tunnel install error' which requires a total reboot of the PA-200.&amp;nbsp; The bug is &lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman','serif';"&gt;78613 and it will be fixed in the new OS version 7.0.0 released sometime in May.&amp;nbsp; I have only had one site out of my 50+ have this issue since starting on 6.1.3 code about 2-3 weeks ago.&amp;nbsp; Luckily it is not a complete dataplane lockup like I have had on previous versions and I could easily pop a reboot on this one.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Apr 2015 18:59:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50644#M37294</guid>
      <dc:creator>dusk2dusk</dc:creator>
      <dc:date>2015-04-21T18:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 Stops Passing - All PanOS versions incl. 6.1.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50645#M37295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Continuing to have issues with Large-Scale VPN on 6.1.4 with 65 PA-200 satellite sites.&amp;nbsp; It will sit on reconnecting until I manually reconnect the site several times a week. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes the satellite will also lose the seed route until I pop the VPN manually, either that or the gateway will lose the route to the satellite.&amp;nbsp; I either reset the tunnel on the gateway or the satellite seems to bring it back up.&amp;nbsp; So the result is the tunnel monitor route will connect correctly so the site is maybe pingable so your monitoring will say it's up but your users will report no connectivity.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LSVPN is supposed to be less hassle than manually setting all VPN tunnels but it just is not stable and reliable at all.&amp;nbsp; It seems to be getting a little better each release but still I get woken up almost every night with a site offline.&amp;nbsp; If somebody would guarantee 7.0.0 would fix things I would consider moving to it but I would bet it introduces more unreliability than improvements.&amp;nbsp; About half my tickets go unresolved and TAC has no idea why these things are happening.&amp;nbsp; We paid 50 grand for the Global-Protect licensing of which we do not use for remote access because JunOS Pulse is solid, only for LSVPN.&amp;nbsp; I feel like we are the only company using LSVPN, or the only one voicing the instability.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jun 2015 15:40:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-stops-passing-all-panos-versions-incl-6-1-3/m-p/50645#M37295</guid>
      <dc:creator>dusk2dusk</dc:creator>
      <dc:date>2015-06-29T15:40:20Z</dc:date>
    </item>
  </channel>
</rss>

