<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Arp issues with L2 failover in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/arp-issues-with-l2-failover/m-p/7035#M5195</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;itnsystem, as a matter of interest what version of PANOS were you running when you had this issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Jan 2011 22:27:20 GMT</pubDate>
    <dc:creator>rds</dc:creator>
    <dc:date>2011-01-20T22:27:20Z</dc:date>
    <item>
      <title>Arp issues with L2 failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-issues-with-l2-failover/m-p/7032#M5192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a new PAN insatllation with a requirement for resilient links to two Cisco core switches running HSRP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have configured the 2 interfaces on the PAN as L2 interfaces and assigned a VLAN which acts as the layer 3 IP. (see diag attached)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we shut one of the interfaces on the switch connectivity is lost and until we manually clear the arp table on the PAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So even though the interface on the PA goes down it retains the arp entry for that interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show arp all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan.100&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:00:0c:07:ac:61 ethernet1/6&amp;nbsp;&amp;nbsp;&amp;nbsp; c&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1603&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after running "clear arp all" it begings to work again and it learns the arp on the correct L2 interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan.100&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:00:0c:07:ac:61 ethernet1/5&amp;nbsp;&amp;nbsp;&amp;nbsp; c&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1776&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="file:/C:/Users/rspence/AppData/Local/Temp/moz-screenshot-1.png" /&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jan 2011 05:31:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-issues-with-l2-failover/m-p/7032#M5192</guid>
      <dc:creator>rds</dc:creator>
      <dc:date>2011-01-20T05:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: Arp issues with L2 failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-issues-with-l2-failover/m-p/7033#M5193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had same problem.&lt;BR /&gt;I asked support team to explain the reason of this.&lt;/P&gt;&lt;P&gt;They said this is normal in PA.&lt;/P&gt;&lt;P&gt;But I don't understand why Paloalto desgned their Firewall not to clear the mac or arp entry after interface goes down.&lt;/P&gt;&lt;P&gt;I think it could be critical problem in some case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jan 2011 15:17:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-issues-with-l2-failover/m-p/7033#M5193</guid>
      <dc:creator>itnsystem</dc:creator>
      <dc:date>2011-01-20T15:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Arp issues with L2 failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-issues-with-l2-failover/m-p/7034#M5194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got this reply from support:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0.0001pt;"&gt;&lt;SPAN style="font-family: &amp;amp;quot;Verdana&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;The problem appears to be in our L2/L3 code. There are several issues contributing to the behavior.&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Verdana&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0.0001pt;"&gt;&lt;SPAN style="font-family: &amp;amp;quot;Verdana&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;The first is we do not flush a MAC entry when the L2 link is brought down. Instead we rely on aging for the removal. The 2nd issue is when the MAC entry is manually removed or moves to a new port, the ARP cache entry does not update it's interface link, so when we originate a packet it egresses the wrong the interface.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0.0001pt;"&gt;&lt;SPAN style="font-family: &amp;amp;quot;Verdana&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;I've filed a bug with Palo's development and will be working with them on the resolution.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jan 2011 22:22:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-issues-with-l2-failover/m-p/7034#M5194</guid>
      <dc:creator>rds</dc:creator>
      <dc:date>2011-01-20T22:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: Arp issues with L2 failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-issues-with-l2-failover/m-p/7035#M5195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;itnsystem, as a matter of interest what version of PANOS were you running when you had this issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jan 2011 22:27:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-issues-with-l2-failover/m-p/7035#M5195</guid>
      <dc:creator>rds</dc:creator>
      <dc:date>2011-01-20T22:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: Arp issues with L2 failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-issues-with-l2-failover/m-p/7036#M5196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any updates on that setup ? we are planning to implememt a similar solution but cannot afford to have down-time, this will be a full voice business.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Aug 2011 10:41:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-issues-with-l2-failover/m-p/7036#M5196</guid>
      <dc:creator>nettobe</dc:creator>
      <dc:date>2011-08-04T10:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: Arp issues with L2 failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-issues-with-l2-failover/m-p/7037#M5197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Upgrading to PANOS 4.x did not fix the problem. After further discussion with support it seems this is in fact normal behaviour and it's the fact that PA doesn't participate in Spanning-tree. It simply passes the traffic so from the Switch point of view it was blocking the backup port going to the PA which means when a failover occured the gratuious arp was not being received while STP converges. To get this to work it meant tweaking the STP cost to make sure the port that's in blocking state is on the link between the switches and not on any of the links going to the PA's.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Aug 2011 13:11:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-issues-with-l2-failover/m-p/7037#M5197</guid>
      <dc:creator>rds</dc:creator>
      <dc:date>2011-08-04T13:11:57Z</dc:date>
    </item>
  </channel>
</rss>

