<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Web page issues  between F5 and PA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/web-page-issues-between-f5-and-pa/m-p/73095#M41346</link>
    <description>&lt;P&gt;Set a packet capture filter for this traffic on all stages. Compare packets received on ingress interface of PA, firewalled and transmited on the egress interface. This way you can make sure if PA is&amp;nbsp;dropping any packets. In drop stage you shouldn't see any packets relevant for the observed TCP session.&lt;/P&gt;
&lt;P&gt;At the same time do packet capture on web server as well. Check if all packets arrive to web server. I don't know about F5 packet capture capabilities. But I would do similar capture as on PA on F5 as well if possible. Do them siultaneuosly to compare them for same session.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This should give you the answer what is happening (or at least where are packets dissapearing).&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Feb 2016 08:07:04 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2016-02-19T08:07:04Z</dc:date>
    <item>
      <title>Web page issues  between F5 and PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-page-issues-between-f5-and-pa/m-p/73039#M41314</link>
      <description>&lt;P&gt;After migrating from an ASA to PA3020, users reported that web pages were not fully loading.&amp;nbsp; The issue was seen on the ASA but rarely.&amp;nbsp; The PA3020 has been showing this issue more often than not resulting in a work around being done on the webpage.&amp;nbsp; The trouble appears to be tied to how the F5 and Palo communicate.&amp;nbsp; With caching enabled, the problem becomes intermittent.&amp;nbsp; With caching disabled, the site fails regularly.&amp;nbsp; F5 support has referenced a bug within the Palo ASIC: &lt;A href="https://www.reddit.com/r/networking/comments/3eshjz/update_tcp_zerowindow_issues/" target="_blank"&gt;https://www.reddit.com/r/networking/comments/3eshjz/update_tcp_zerowindow_issues/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;In working with Palo support, they have stated this is not related as we are running 6.0.10 and the article is relating this to 6.1.5.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To troubleshoot the issue without impacting production, a test environment was created and the issue can be replicated.&amp;nbsp; Prior to inserting the Palo into the mix, the sites did not experience issues.&amp;nbsp; Packet captures on the link show multiple out of sync packets when the page hangs.&amp;nbsp; This is a concern as the only traffic being generated in the test environment is when we are testing which is going through the websites.&lt;/P&gt;
&lt;P&gt;Has anyone seen this issue or know of anything similiar which can point me into the right direction to resolve?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 13:33:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-page-issues-between-f5-and-pa/m-p/73039#M41314</guid>
      <dc:creator>RRAPP</dc:creator>
      <dc:date>2016-02-18T13:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Web page issues  between F5 and PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-page-issues-between-f5-and-pa/m-p/73064#M41325</link>
      <description>&lt;P&gt;Issue seems to be asymmetric routing. Do pacps on firewall to confirm. Check the following documents:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/SYN-ACK-Issues-with-Asymmetric-Routing/ta-p/54090" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/SYN-ACK-Issues-with-Asymmetric-Routing/ta-p/54090&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Packets-are-Dropped-Due-to-TCP-Reassembly/ta-p/57139" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Packets-are-Dropped-Due-to-TCP-Reassembly/ta-p/57139&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Set-the-Palo-Alto-Networks-Firewall-to-Allow-non-Syn/ta-p/62868" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Set-the-Palo-Alto-Networks-Firewall-to-Allow-non-Syn/ta-p/62868&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-Issues-with-Asymmetric-Routing/ta-p/65456" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-Issues-with-Asymmetric-Routing/ta-p/65456&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 17:23:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-page-issues-between-f5-and-pa/m-p/73064#M41325</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-02-18T17:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: Web page issues  between F5 and PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-page-issues-between-f5-and-pa/m-p/73065#M41326</link>
      <description>&lt;P&gt;Check following document for pacps:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Run-a-Packet-Capture/ta-p/62390" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Run-a-Packet-Capture/ta-p/62390&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Documentation-Articles/Packet-Based-Troubleshooting-Configuring-Packet-Captures-and/ta-p/54947" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Documentation-Articles/Packet-Based-Troubleshooting-Configuring-Packet-Captures-and/ta-p/54947&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 17:24:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-page-issues-between-f5-and-pa/m-p/73065#M41326</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-02-18T17:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: Web page issues  between F5 and PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-page-issues-between-f5-and-pa/m-p/73083#M41338</link>
      <description>&lt;P&gt;Thanks for the links as this helped confirm no packets are being dropped due to asymmetric routing.&amp;nbsp; The FW was placed into bypass mode globally after trying by zone and the problem can be reproduced.&amp;nbsp; The site does not fail all the time which is what makes this rather odd.&amp;nbsp; The page also seems to stop loading at the same point which our application team is looking into.&lt;/P&gt;
&lt;P&gt;Can anyone think of something else which can be check?&amp;nbsp; The F5 and site coding has not been ruled out as of yet either.&amp;nbsp; Would be nice to eliminate something in this mix.&lt;/P&gt;
&lt;P&gt;Fun stuff.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 19:56:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-page-issues-between-f5-and-pa/m-p/73083#M41338</guid>
      <dc:creator>RRAPP</dc:creator>
      <dc:date>2016-02-18T19:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Web page issues  between F5 and PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-page-issues-between-f5-and-pa/m-p/73095#M41346</link>
      <description>&lt;P&gt;Set a packet capture filter for this traffic on all stages. Compare packets received on ingress interface of PA, firewalled and transmited on the egress interface. This way you can make sure if PA is&amp;nbsp;dropping any packets. In drop stage you shouldn't see any packets relevant for the observed TCP session.&lt;/P&gt;
&lt;P&gt;At the same time do packet capture on web server as well. Check if all packets arrive to web server. I don't know about F5 packet capture capabilities. But I would do similar capture as on PA on F5 as well if possible. Do them siultaneuosly to compare them for same session.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This should give you the answer what is happening (or at least where are packets dissapearing).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2016 08:07:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-page-issues-between-f5-and-pa/m-p/73095#M41346</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-02-19T08:07:04Z</dc:date>
    </item>
    <item>
      <title>Re: Web page issues  between F5 and PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-page-issues-between-f5-and-pa/m-p/73674#M41493</link>
      <description>&lt;P&gt;Got pulled away to build out a third environment and hopefully will get back on it soon.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2016 13:55:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-page-issues-between-f5-and-pa/m-p/73674#M41493</guid>
      <dc:creator>RRAPP</dc:creator>
      <dc:date>2016-02-26T13:55:41Z</dc:date>
    </item>
  </channel>
</rss>

