<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Duplicate MAC address in layer two switch when PaloAlto connected to network,.. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/duplicate-mac-address-in-layer-two-switch-when-paloalto/m-p/69839#M40411</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have the setup as shown below,&lt;/P&gt;
&lt;P&gt;In this scenario, &amp;nbsp;&lt;STRONG&gt;Layer 2 switch (2960)&lt;/STRONG&gt; showing the&lt;STRONG&gt; MAC address&lt;/STRONG&gt; of the &lt;STRONG&gt;Exchange server&lt;/STRONG&gt; learnt through the interface of the switch &lt;STRONG&gt;Gi 0/1&lt;/STRONG&gt; which connects to the PAN firewall in V-wire mode to an ASA .&lt;/P&gt;
&lt;P&gt;We connected &lt;STRONG&gt;PA&lt;/STRONG&gt; direclty to Core switch and made a static entry in switch for MAC address entry the port where &lt;STRONG&gt;exchange server&lt;/STRONG&gt; is connected. Now it is working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But we need permanent fix and the reason why PaloAlto id doing this? &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; we have more info after the below snap&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1741i24D0E657DD5AB956/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="100.PNG" title="100.PNG" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt; troubleshoot an issue seen with connectivity to Exchange server cluster IP 172.16.12.190 from any of the remote locations and when the issue occurred, we could notice that the Layer 2 switch showing the MAC of the end host learnt through the interface of the switch Gi 0/1 which connects to the PAN firewall in V-wire mode to an ASA. Though the traffic path for reaching this server does not involve the PAN V-Wire, when the issue occurred, the flow shows at the receive stage in PAN packet capture and traffic logs. The issue is not seen when PAN V-wire is removed from the connectivity.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;Guru&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Dec 2015 06:56:32 GMT</pubDate>
    <dc:creator>Gururaj</dc:creator>
    <dc:date>2015-12-24T06:56:32Z</dc:date>
    <item>
      <title>Duplicate MAC address in layer two switch when PaloAlto connected to network,..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/duplicate-mac-address-in-layer-two-switch-when-paloalto/m-p/69839#M40411</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have the setup as shown below,&lt;/P&gt;
&lt;P&gt;In this scenario, &amp;nbsp;&lt;STRONG&gt;Layer 2 switch (2960)&lt;/STRONG&gt; showing the&lt;STRONG&gt; MAC address&lt;/STRONG&gt; of the &lt;STRONG&gt;Exchange server&lt;/STRONG&gt; learnt through the interface of the switch &lt;STRONG&gt;Gi 0/1&lt;/STRONG&gt; which connects to the PAN firewall in V-wire mode to an ASA .&lt;/P&gt;
&lt;P&gt;We connected &lt;STRONG&gt;PA&lt;/STRONG&gt; direclty to Core switch and made a static entry in switch for MAC address entry the port where &lt;STRONG&gt;exchange server&lt;/STRONG&gt; is connected. Now it is working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But we need permanent fix and the reason why PaloAlto id doing this? &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; we have more info after the below snap&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1741i24D0E657DD5AB956/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="100.PNG" title="100.PNG" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt; troubleshoot an issue seen with connectivity to Exchange server cluster IP 172.16.12.190 from any of the remote locations and when the issue occurred, we could notice that the Layer 2 switch showing the MAC of the end host learnt through the interface of the switch Gi 0/1 which connects to the PAN firewall in V-wire mode to an ASA. Though the traffic path for reaching this server does not involve the PAN V-Wire, when the issue occurred, the flow shows at the receive stage in PAN packet capture and traffic logs. The issue is not seen when PAN V-wire is removed from the connectivity.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;Guru&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2015 06:56:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/duplicate-mac-address-in-layer-two-switch-when-paloalto/m-p/69839#M40411</guid>
      <dc:creator>Gururaj</dc:creator>
      <dc:date>2015-12-24T06:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate MAC address in layer two switch when PaloAlto connected to network,..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/duplicate-mac-address-in-layer-two-switch-when-paloalto/m-p/69851#M40414</link>
      <description>&lt;P&gt;Are you sure that traffic is not passing through the PA firewall? Remove the static mac entry and do a traceroute check. The traffic from the exchange server is going to remote sites(left side)?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2015 11:07:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/duplicate-mac-address-in-layer-two-switch-when-paloalto/m-p/69851#M40414</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-12-24T11:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate MAC address in layer two switch when PaloAlto connected to network,..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/duplicate-mac-address-in-layer-two-switch-when-paloalto/m-p/70109#M40455</link>
      <description>&lt;P&gt;This is extremely odd as we have tested this exact configuration without the issues you are having. A few questions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) &amp;nbsp;What version of PAN-OS are you running?&lt;/P&gt;
&lt;P&gt;2) &amp;nbsp;Are there any NAT translations for the Exchange server configured in the ASA?&lt;/P&gt;
&lt;P&gt;3) &amp;nbsp;Do you have any NAT rules for the Exchange server on the Palo Alto (asuming no as it's in VWire mode)&lt;/P&gt;
&lt;P&gt;4) &amp;nbsp;Do you have any security policies configured on the Palo Alto&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have seen some issues with 7.0.2 and 7.0.3 where if you have configured multiple Palo Alto virtual routers on the same vsys with ports connected to the same network (say Internet) advertise MAC addresses on the wrong interface (NAT), but this is all layer 3. &amp;nbsp;I have never seen something like this in VWire.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would check your STP, make sure that your Core is setup as the root bridge, validate your VTP (if you use it), and check layer 2. &amp;nbsp;I would also make sure your in VWire mode and not Layer 2 mode on the Palo Alto. &amp;nbsp;As a test I would also allow all VLANS (0-4096) on the VWire.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2015 14:56:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/duplicate-mac-address-in-layer-two-switch-when-paloalto/m-p/70109#M40455</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2015-12-30T14:56:40Z</dc:date>
    </item>
  </channel>
</rss>

