<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Asymmetric Routing and TCP syn check based on interface or zone? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/asymmetric-routing-and-tcp-syn-check-based-on-interface-or-zone/m-p/120556#M45941</link>
    <description>&lt;P&gt;Thansk steve !&lt;/P&gt;</description>
    <pubDate>Sat, 22 Oct 2016 14:21:01 GMT</pubDate>
    <dc:creator>ghostrider</dc:creator>
    <dc:date>2016-10-22T14:21:01Z</dc:date>
    <item>
      <title>Asymmetric Routing and TCP syn check based on interface or zone?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/asymmetric-routing-and-tcp-syn-check-based-on-interface-or-zone/m-p/119132#M45776</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have scenario like firewall is connected to two routers R1 and R2 through eth1/1 and eth1/2 interfaces respectively. From firewall, traffic is going through R1 via eth1/1 interface and return traffic is coming through R2 via eth1/2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is asymmetric routing and firewall tcp syn check will fail. My question is that Palo Alto firewall check tcp syn and asymmtric routing based on interface or zone? I mean if both eth1/1 and eth1/2 have same zone then this will not fail tcp syn checking?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GR&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2016 12:33:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/asymmetric-routing-and-tcp-syn-check-based-on-interface-or-zone/m-p/119132#M45776</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-14T12:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Asymmetric Routing and TCP syn check based on interface or zone?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/asymmetric-routing-and-tcp-syn-check-based-on-interface-or-zone/m-p/119141#M45781</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the ZONE Protection profile (TCP Drop), select Bypass for Asymmetric Path.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Packets-are-Dropped-Due-to-TCP-Reassembly/ta-p/57139" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Packets-are-Dropped-Due-to-TCP-Reassembly/ta-p/57139&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HA&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2016 14:05:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/asymmetric-routing-and-tcp-syn-check-based-on-interface-or-zone/m-p/119141#M45781</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2016-10-14T14:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: Asymmetric Routing and TCP syn check based on interface or zone?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/asymmetric-routing-and-tcp-syn-check-based-on-interface-or-zone/m-p/119395#M45792</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply. Just want to know if I put both outoing interfaces interfaces in same zone then firewall will not drop asymmetric traffic?&lt;/P&gt;</description>
      <pubDate>Sun, 16 Oct 2016 11:53:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/asymmetric-routing-and-tcp-syn-check-based-on-interface-or-zone/m-p/119395#M45792</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-16T11:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: Asymmetric Routing and TCP syn check based on interface or zone?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/asymmetric-routing-and-tcp-syn-check-based-on-interface-or-zone/m-p/119412#M45793</link>
      <description>&lt;P&gt;PA session match is based on zone not on interface. &amp;nbsp;So you are correct that if you put both interfaces into the same zone you can still achieve session match and not drop the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can see the details of the packet inspection process in this document.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Packet-Flow-Sequence-in-PAN-OS/ta-p/56081" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Packet-Flow-Sequence-in-PAN-OS/ta-p/56081&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Oct 2016 21:40:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/asymmetric-routing-and-tcp-syn-check-based-on-interface-or-zone/m-p/119412#M45793</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-10-16T21:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Asymmetric Routing and TCP syn check based on interface or zone?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/asymmetric-routing-and-tcp-syn-check-based-on-interface-or-zone/m-p/120556#M45941</link>
      <description>&lt;P&gt;Thansk steve !&lt;/P&gt;</description>
      <pubDate>Sat, 22 Oct 2016 14:21:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/asymmetric-routing-and-tcp-syn-check-based-on-interface-or-zone/m-p/120556#M45941</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-22T14:21:01Z</dc:date>
    </item>
  </channel>
</rss>

