<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Session Lookup for inter-virtual communication in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/session-lookup-for-inter-virtual-communication/m-p/119065#M45733</link>
    <description>&lt;P&gt;Hello Experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was just wondering how firewall session is created for inter-vr communication. I have scenario like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface eth1/1 (Trust-VR) Trust Zone ---LAN (10.10.10.0/24)&lt;/P&gt;&lt;P&gt;Interface eth1/2 (Untrust-VR) Untrust Zone ---INTERNET&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Trust-VR, I have 0/0 default route towards Untrust-VR, I have created the security policy between Trust to Untrust Zone to allow the communication. My question is, firewall will create the session in which VR? I mean for reverse traffic where the route lookup for 10.10.10.0/24 will happen? In Trust-VR or Untrust-VR?&lt;/P&gt;&lt;P&gt;In case Trust-R then no need for reverse route for 10.10.10.0/24 in Untrust-VR next-hop Trust-VR?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Oct 2016 08:36:16 GMT</pubDate>
    <dc:creator>ghostrider</dc:creator>
    <dc:date>2016-10-13T08:36:16Z</dc:date>
    <item>
      <title>Session Lookup for inter-virtual communication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-lookup-for-inter-virtual-communication/m-p/119065#M45733</link>
      <description>&lt;P&gt;Hello Experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was just wondering how firewall session is created for inter-vr communication. I have scenario like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface eth1/1 (Trust-VR) Trust Zone ---LAN (10.10.10.0/24)&lt;/P&gt;&lt;P&gt;Interface eth1/2 (Untrust-VR) Untrust Zone ---INTERNET&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Trust-VR, I have 0/0 default route towards Untrust-VR, I have created the security policy between Trust to Untrust Zone to allow the communication. My question is, firewall will create the session in which VR? I mean for reverse traffic where the route lookup for 10.10.10.0/24 will happen? In Trust-VR or Untrust-VR?&lt;/P&gt;&lt;P&gt;In case Trust-R then no need for reverse route for 10.10.10.0/24 in Untrust-VR next-hop Trust-VR?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 08:36:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-lookup-for-inter-virtual-communication/m-p/119065#M45733</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-13T08:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: Session Lookup for inter-virtual communication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-lookup-for-inter-virtual-communication/m-p/119069#M45735</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the session is create on the firewall not in the VR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why do you use two VR?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the Untrust-VR you need an Static Route back to the Trust-VR (10.10.10.0/24)&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 09:11:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-lookup-for-inter-virtual-communication/m-p/119069#M45735</guid>
      <dc:creator>FJU-ITCS</dc:creator>
      <dc:date>2016-10-13T09:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Session Lookup for inter-virtual communication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-lookup-for-inter-virtual-communication/m-p/119131#M45775</link>
      <description>&lt;P&gt;Thanks dear. Actually I have the scenario like in firewall I have two VR, &amp;nbsp;VR-1 for one customer-1 and VR-2 for other customer. Both have same subnets (overlapping subnets) but going to internet from global table (trust-vr) interface (connected to internet router and doing the NAT). In Juniper SRX, the session is bind to VR. So if traffic is going from VR-1 to global table then reverse route lookup&amp;nbsp;happens in VR-1 and global table does not need to have reverse static routes for VR-1 and VR-2. It seems Palo Alto firewall session is not bind to any VR.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since VR-1 and VR-2 sharing same subnets. How can I define the reverse static routes in trust-vr for VR-1 and VR-2. Should I enable symmatric retrun? or any other solution&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2016 12:17:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-lookup-for-inter-virtual-communication/m-p/119131#M45775</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-14T12:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: Session Lookup for inter-virtual communication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-lookup-for-inter-virtual-communication/m-p/120557#M45942</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9524"&gt;@pulukas﻿&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please also look into this? Session is bind with virtual router or not?&lt;/P&gt;</description>
      <pubDate>Sat, 22 Oct 2016 14:24:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-lookup-for-inter-virtual-communication/m-p/120557#M45942</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-22T14:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Session Lookup for inter-virtual communication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-lookup-for-inter-virtual-communication/m-p/120562#M45944</link>
      <description>In PAN-OS the sessions are created differently &lt;BR /&gt;Sessions exist inside a vsys (virtual system) and are created by the firewall independent of routing. route lookups are performed per flow direction, so in your example you need routes in both directions</description>
      <pubDate>Sat, 22 Oct 2016 18:47:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-lookup-for-inter-virtual-communication/m-p/120562#M45944</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-10-22T18:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: Session Lookup for inter-virtual communication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-lookup-for-inter-virtual-communication/m-p/120564#M45945</link>
      <description>&lt;P&gt;Thank you &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;. I justed tested quickly. So if my topology is like LAN -&amp;gt; PA -&amp;gt; Internet. Now if traffic has to pass through AV system or transparent proxy (also directly connected to PA) using Filter based forwarding. Traffic will pass like this:&lt;/P&gt;&lt;P&gt;LAN -&amp;gt; PA -&amp;gt; AV System -&amp;gt; PA -&amp;gt; Internet (Outdoing Traffic)&lt;/P&gt;&lt;P&gt;Interenet -&amp;gt; PA -&amp;gt; LAN (return traffic)&lt;/P&gt;&lt;P&gt;This will cause Aysmmetric routing. I cannot play with VR because as you said, session is not bind to VR. The only way I think of is, enable sysmmetric return in Internet interface and that worked like a charm ! The return traffic now taking the same path as outgoing traffic&lt;/P&gt;</description>
      <pubDate>Sat, 22 Oct 2016 20:38:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-lookup-for-inter-virtual-communication/m-p/120564#M45945</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-22T20:38:15Z</dc:date>
    </item>
  </channel>
</rss>

