<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ping through PBF Policy intermittently dying in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ping-through-pbf-policy-intermittently-dying/m-p/162098#M52650</link>
    <description>&lt;P&gt;Hrm, doing a Packet Capture, I see the ping packets in the drop.pcap, so there's definitely something blocking the pings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just can't figure out what or why. &amp;nbsp;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jun 2017 21:51:31 GMT</pubDate>
    <dc:creator>fjwcash</dc:creator>
    <dc:date>2017-06-19T21:51:31Z</dc:date>
    <item>
      <title>Ping through PBF Policy intermittently dying</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-through-pbf-policy-intermittently-dying/m-p/162096#M52649</link>
      <description>&lt;P&gt;I think this might be related to DoS protection somehow, but I can't find anything being blocked in any of the logs. &amp;nbsp;I'm sure I'm not looking in the right spot, though.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a normal Internet gateway (default route), and a separate point-to-point connection to a SIP provider.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a PBF Policy in place that forwards VoIP traffic through the ptp link. &amp;nbsp;Along with the two sets of NAT/Security Policies to allow traffic through both the Internet gateway and the ptp link. &amp;nbsp;That's all working nicely, including the fail-over (link monitoring).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have another PBF Policy in place that forwards pings from our network monitoring server to the SIP providers router and PBXes through the ptp link. &amp;nbsp;Along with the NAT/Security Policies to allow traffic through both links.It sends 5 ping requests every minute.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Every now and then, I get alerts that the VoIP router is down as there are no ping responses coming back. &amp;nbsp;The PBF Policies are listed as Active, and VoIP traffic is going through correctly. &amp;nbsp;But there are no sessions listed for traffic between the monitor IP and the router IP. &amp;nbsp;Then a few minutes later, I get the alert that things are working again. &amp;nbsp;The PBF Policy is still listed as Active, but now there are sessions showing the ping traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm at a loss as to why the ping packets are not making it through the firewall all the time. &amp;nbsp;The only thing I can think of is DoS protections, but I don't have any DoS Protection Policies configured, or Zone Protection Profiles enabled. &amp;nbsp;There's nothing showing in the Threats log, nor anything listed as Deny in the Traffic log. &amp;nbsp;The MAC of the VoIP router never changes and is always listed in "show arp" on the right interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the network monitor shows the VoIP router as being "up", there are sessions shown on the firewall. &amp;nbsp;When it's shown as "down" there are no sessions shown on the firewall, and the pings are being dropped. &amp;nbsp;I just can't figure out where.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where else can I look to see why these pings are being dropped?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 21:47:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-through-pbf-policy-intermittently-dying/m-p/162096#M52649</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2017-06-19T21:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: Ping through PBF Policy intermittently dying</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-through-pbf-policy-intermittently-dying/m-p/162098#M52650</link>
      <description>&lt;P&gt;Hrm, doing a Packet Capture, I see the ping packets in the drop.pcap, so there's definitely something blocking the pings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just can't figure out what or why. &amp;nbsp;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 21:51:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-through-pbf-policy-intermittently-dying/m-p/162098#M52650</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2017-06-19T21:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: Ping through PBF Policy intermittently dying</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-through-pbf-policy-intermittently-dying/m-p/162105#M52651</link>
      <description>&lt;P&gt;Hrm, this may be due to the NAT Policy and my misunderstanding of the different Source NAT options. &amp;nbsp;Changing the Source NAT type to Dynamic IP and Port makes it work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It was originally set to just Dynamic IP as I didn't want the source port to change, but that seems to be preventing it from sending pings sometimes (maybe one of the other two stations using that same public IP is using that port?).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So far, things are working much better. &amp;nbsp;Will have to monitor for awhile longer to make sure this was the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 22:03:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-through-pbf-policy-intermittently-dying/m-p/162105#M52651</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2017-06-19T22:03:07Z</dc:date>
    </item>
  </channel>
</rss>

