<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA Active Active Asynchronous Routing Issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-asynchronous-routing-issue/m-p/160580#M52330</link>
    <description>&lt;P&gt;Thanks for the response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have all interfaces in the same zone and have a policy to permit any any (testing right now). I did move interfaces around in different zones, making sure both FW's matched. We still had the same results.&lt;BR /&gt;&lt;BR /&gt;Doing a show counters global, I didn't see any hits on the stat:&amp;nbsp;flow_tcp_non_syn_drop. Reading up, and appears that would be an indication of the FWs dropping traffic due to asynchronous routing. However, I did notice these two stats get hit constantly (only traffic going through these guys is protocol traffic (BGP) and pings:&lt;/P&gt;&lt;P&gt;flow_rcv_dot1q_tag_err&lt;BR /&gt;flow_no_interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Been playing aroudnd with subinterfaces and what not, and still no go. Everything works as is, but when I introduce asynchronous routing, routes to an opposing side break.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 11 Jun 2017 02:05:44 GMT</pubDate>
    <dc:creator>david13holt</dc:creator>
    <dc:date>2017-06-11T02:05:44Z</dc:date>
    <item>
      <title>HA Active Active Asynchronous Routing Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-asynchronous-routing-issue/m-p/160498#M52311</link>
      <description>Have two PA vm 1000hv setup in active active HA. They see each other on HA 1,2, and 3 link and synching configs (not vr configs). We have an asynchronous routing scenario that is temporary for now, but need it to work. However, the FWs appear to be dropping traffic. I haven't looked at the counters to indicate dropped asynchronous traffic yet, but it's obvious that it's happening as when we stop the loop on routing, we can hit hosts. Anyway, I was wondering if there were known issues with Active Active HA with this type of behavior? Thanks</description>
      <pubDate>Sat, 10 Jun 2017 07:10:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-asynchronous-routing-issue/m-p/160498#M52311</guid>
      <dc:creator>david13holt</dc:creator>
      <dc:date>2017-06-10T07:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active Active Asynchronous Routing Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-asynchronous-routing-issue/m-p/160515#M52314</link>
      <description>&lt;P&gt;With A/A you can have assymetrical flows. &amp;nbsp;But they do need to maintain the zone relationship that match the session for the flow. &amp;nbsp;So make sure the policy that permits the traffic has the zone to zone setup needed for the communication across the two devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Easiest way to troubleshoot this kind of flow is to do the trace route from both devices and then map the interfaces hit by the packets in the flow on the two PA devices. &amp;nbsp;Then lookup the zone assignments and confirm the policy is in place in the correct direction by initiator of the traffic.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jun 2017 11:03:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-asynchronous-routing-issue/m-p/160515#M52314</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-06-10T11:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active Active Asynchronous Routing Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-asynchronous-routing-issue/m-p/160580#M52330</link>
      <description>&lt;P&gt;Thanks for the response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have all interfaces in the same zone and have a policy to permit any any (testing right now). I did move interfaces around in different zones, making sure both FW's matched. We still had the same results.&lt;BR /&gt;&lt;BR /&gt;Doing a show counters global, I didn't see any hits on the stat:&amp;nbsp;flow_tcp_non_syn_drop. Reading up, and appears that would be an indication of the FWs dropping traffic due to asynchronous routing. However, I did notice these two stats get hit constantly (only traffic going through these guys is protocol traffic (BGP) and pings:&lt;/P&gt;&lt;P&gt;flow_rcv_dot1q_tag_err&lt;BR /&gt;flow_no_interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Been playing aroudnd with subinterfaces and what not, and still no go. Everything works as is, but when I introduce asynchronous routing, routes to an opposing side break.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jun 2017 02:05:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-asynchronous-routing-issue/m-p/160580#M52330</guid>
      <dc:creator>david13holt</dc:creator>
      <dc:date>2017-06-11T02:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active Active Asynchronous Routing Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-asynchronous-routing-issue/m-p/160613#M52344</link>
      <description>&lt;P&gt;Are you certain that both directions of the flow cross the A/A firewall pair?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on your description, there should be no asymmetrical flow drops on the firewall.&amp;nbsp; Unless there is a path that can bypass BOTH firewalls in the commuications flow in question.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jun 2017 23:21:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-asynchronous-routing-issue/m-p/160613#M52344</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-06-11T23:21:03Z</dc:date>
    </item>
  </channel>
</rss>

