<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packets dropped: invalid interface (route to second public network in trust interface) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/packets-dropped-invalid-interface-route-to-second-public-network/m-p/147357#M49371</link>
    <description>&lt;P&gt;I'm afraid i would need much more details to debug this (routing, interface configurations..)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I suspect it's topology issue.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Mar 2017 07:55:58 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2017-03-13T07:55:58Z</dc:date>
    <item>
      <title>Packets dropped: invalid interface (route to second public network in trust interface)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packets-dropped-invalid-interface-route-to-second-public-network/m-p/147263#M49353</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello All,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My system is&amp;nbsp;multi vsys environment, I need to route traffic from untrust to trust.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My source is internet and destination is my second Public IP subnet in trust interface.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I investigate and found log from Global Counters "Packets dropped: invalid interface".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I try to add public ip to loopback and secondary ip but could not help.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How can I solve this problem?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 780px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8116i58613D3C75C79726/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 07:44:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packets-dropped-invalid-interface-route-to-second-public-network/m-p/147263#M49353</guid>
      <dc:creator>jocjak</dc:creator>
      <dc:date>2017-03-13T07:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: Packets dropped: invalid interface (route to second public network in trust interface)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packets-dropped-invalid-interface-route-to-second-public-network/m-p/147340#M49362</link>
      <description>&lt;P&gt;Why is second IP on trust interface?&lt;/P&gt;&lt;P&gt;Just put the second public IP on untrust interface (or to wherever ISP route directs it) &amp;nbsp;and PA will respond to ARP requests for it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 07:23:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packets-dropped-invalid-interface-route-to-second-public-network/m-p/147340#M49362</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-03-13T07:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Packets dropped: invalid interface (route to second public network in trust interface)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packets-dropped-invalid-interface-route-to-second-public-network/m-p/147354#M49368</link>
      <description>&lt;P&gt;My environment like this. I need to route traffic to my public IP via Palo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 780px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8117i258197166C158F9B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 07:46:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packets-dropped-invalid-interface-route-to-second-public-network/m-p/147354#M49368</guid>
      <dc:creator>jocjak</dc:creator>
      <dc:date>2017-03-13T07:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: Packets dropped: invalid interface (route to second public network in trust interface)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packets-dropped-invalid-interface-route-to-second-public-network/m-p/147357#M49371</link>
      <description>&lt;P&gt;I'm afraid i would need much more details to debug this (routing, interface configurations..)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I suspect it's topology issue.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 07:55:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packets-dropped-invalid-interface-route-to-second-public-network/m-p/147357#M49371</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-03-13T07:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: Packets dropped: invalid interface (route to second public network in trust interface)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packets-dropped-invalid-interface-route-to-second-public-network/m-p/147363#M49375</link>
      <description>&lt;P&gt;Routing is correct. I can ping from Palo to public IP at HQ. (routing fib is correct)&lt;/P&gt;&lt;P&gt;When ping from internet packet drop by palo as follow counter log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8118i76BE5E92C983527D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.JPG" alt="2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 08:11:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packets-dropped-invalid-interface-route-to-second-public-network/m-p/147363#M49375</guid>
      <dc:creator>jocjak</dc:creator>
      <dc:date>2017-03-13T08:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Packets dropped: invalid interface (route to second public network in trust interface)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packets-dropped-invalid-interface-route-to-second-public-network/m-p/147368#M49379</link>
      <description>&lt;P&gt;I have to agree with &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;, we'll need much more information to dissect this issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;why is your public IP range on the trust interface?&lt;/P&gt;
&lt;P&gt;for your multi vsys envirnment, did you create 2 vsys specific vritual routers or are you floating one VR outside the vsys (no vsys assigned to it)&lt;/P&gt;
&lt;P&gt;The invalid interface error could be caused by your VR trying to forward the incoming packet to an interface that's outside the receiving vsys&lt;/P&gt;
&lt;P&gt;flow_rcv_dot1q_tag_err usually means you are receiving 802.1q tagged packets on a non-tagged interface (or a tag that is not configured on one of the subinterfaces), you might want to look into that also&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 08:52:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packets-dropped-invalid-interface-route-to-second-public-network/m-p/147368#M49379</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-03-13T08:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: Packets dropped: invalid interface (route to second public network in trust interface)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packets-dropped-invalid-interface-route-to-second-public-network/m-p/150695#M50002</link>
      <description>&lt;P&gt;Since you have multiple vsys and a path to the main office via both the internet and what looks like an internal link. &amp;nbsp;I think you are likely dealing with some asymmetrical routing. &amp;nbsp;Firewalls do not like asymmetrical routing and drop the packet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To confirm this perform this test:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Run a trace route from the device at the trust interface to the public ip address at the home office in question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Run a second trace route from the device on the public ip address at the home office back to your trust device (nat address if this is nat or the public address if it is public)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Compare the path on both and verify they go the same way.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Apr 2017 15:41:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packets-dropped-invalid-interface-route-to-second-public-network/m-p/150695#M50002</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-04-01T15:41:45Z</dc:date>
    </item>
  </channel>
</rss>

