<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Aged-out issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163797#M52980</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes i did set up the default gateway..&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="default.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9983i85661845B3E043D0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="default.png" alt="default.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but all of the result is "aged-out" and application is recognised as "incomplete".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="default.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9984i59818EC42672DD6F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="default.png" alt="default.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Jun 2017 08:38:15 GMT</pubDate>
    <dc:creator>itsuki.h1991</dc:creator>
    <dc:date>2017-06-29T08:38:15Z</dc:date>
    <item>
      <title>Aged-out issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163520#M52936</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured PA on Azure but it is unable to ping to PA.&lt;/P&gt;&lt;P&gt;It always shows that "aged-out" as error message.&lt;/P&gt;&lt;P&gt;Once I ping to proxy-server on Azure, the log is shown on PA but it is aged out and could not get the response.&lt;/P&gt;&lt;P&gt;I did set up Static route and everything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have set up as below.&lt;/P&gt;&lt;P&gt;PC-&amp;gt;Azure(PA)-Azure(Proxy server)-Intenet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anybody please help me to solve this issue?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 04:24:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163520#M52936</guid>
      <dc:creator>itsuki.h1991</dc:creator>
      <dc:date>2017-06-29T04:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: Aged-out issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163555#M52939</link>
      <description>&lt;P&gt;Ping always&amp;nbsp;shows in the traffic logs as &amp;nbsp;"aged-out" &amp;nbsp;in the session end reason column. This is because it doesn't&amp;nbsp;have any TCP/UDP port. Are you pinging PA interface?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 06:56:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163555#M52939</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-28T06:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: Aged-out issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163571#M52941</link>
      <description>&lt;P&gt;I understand that, but apart from ping, all of the "application" column shows as "Incompelete."&lt;/P&gt;&lt;P&gt;i did ping to the interface of PA and the proxy servers on Azure, but both of them are failed.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 07:35:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163571#M52941</guid>
      <dc:creator>itsuki.h1991</dc:creator>
      <dc:date>2017-06-28T07:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: Aged-out issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163607#M52949</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/67699"&gt;@itsuki.h1991&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It sounds like something wasn't configured correctly but we would need to know a lot more information then what you have displayed to actually point you in the right direction.&lt;/P&gt;&lt;P&gt;What does your interface configuration look like?&lt;/P&gt;&lt;P&gt;Did you follow any of the guides to configure this setup?&lt;/P&gt;&lt;P&gt;What does your routing look like, and can you reach a website and it's simply showing as incomplete or do you not actually resolve things properly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 14:13:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163607#M52949</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-28T14:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: Aged-out issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163715#M52964</link>
      <description>&lt;P&gt;I have set up as below..&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="interface.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9979i8650F81950C6200B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="interface.JPG" alt="interface.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even i choose DHCP, the interface got correct IP address i expected.&lt;/P&gt;&lt;P&gt;I followed guide regarding PA on VM but the detail is not written much.&lt;/P&gt;&lt;P&gt;No i cant reach any website, it is failed and shows as "Incomplete".&lt;/P&gt;&lt;P&gt;I set up routing table as well but it seems it is not working at all. Regardless i set the routing table or not, the result is completely same.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 23:42:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163715#M52964</guid>
      <dc:creator>itsuki.h1991</dc:creator>
      <dc:date>2017-06-28T23:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: Aged-out issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163768#M52974</link>
      <description>&lt;P&gt;Can Palo reach the internet?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 06:40:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163768#M52974</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-29T06:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: Aged-out issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163769#M52975</link>
      <description>&lt;P&gt;no it cant access internet...&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 06:43:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163769#M52975</guid>
      <dc:creator>itsuki.h1991</dc:creator>
      <dc:date>2017-06-29T06:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: Aged-out issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163773#M52976</link>
      <description>&lt;P&gt;What is your default gateway on PA. Can you ping that&amp;nbsp;ip? Can&amp;nbsp;Palo&amp;nbsp;resolve cisco.com website?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 06:54:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163773#M52976</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-29T06:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: Aged-out issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163787#M52978</link>
      <description>&lt;P&gt;Do you mean MGT default gateway? it is 172.28.194.4, and ping is unreachable. but i can ping to management port and trust and untrust interface now.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 08:18:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163787#M52978</guid>
      <dc:creator>itsuki.h1991</dc:creator>
      <dc:date>2017-06-29T08:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: Aged-out issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163792#M52979</link>
      <description>&lt;P&gt;PA uses mgmt port (by default) &amp;nbsp;for all own communication (means initiated by the&amp;nbsp;device&amp;nbsp;itself). &amp;nbsp;You have to have a default route (at least if you are not using any dynamic protocol) for all your traffic which is traversing device (client traffic):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FFF.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9981i7918FE6E9E688AE2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="FFF.PNG" alt="FFF.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So when you SSHed into the&amp;nbsp;device and pinging let's say 8.8.8.8, you by default, using your mgmt default gateway in order to get to the&amp;nbsp;Google&amp;nbsp;public DNS. All your client's&amp;nbsp;traffic&amp;nbsp;is&amp;nbsp;routed through the&amp;nbsp;firewall based on the virtual router attached to the&amp;nbsp;zone (as well as routing table in the VR).&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 08:27:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163792#M52979</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-29T08:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Aged-out issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163797#M52980</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes i did set up the default gateway..&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="default.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9983i85661845B3E043D0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="default.png" alt="default.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but all of the result is "aged-out" and application is recognised as "incomplete".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="default.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9984i59818EC42672DD6F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="default.png" alt="default.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 08:38:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163797#M52980</guid>
      <dc:creator>itsuki.h1991</dc:creator>
      <dc:date>2017-06-29T08:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: Aged-out issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163806#M52981</link>
      <description>&lt;P&gt;So can you ping your default gateway on the&amp;nbsp;WAN?&lt;/P&gt;&lt;P&gt;Can you add columns bytes set/bytes received in the&amp;nbsp;monitoring TAB.&amp;nbsp;Then you can check if you receive some data back once the session is initiated. Incomplete means not enough&amp;nbsp;data fro the PA in the&amp;nbsp;session to determine&amp;nbsp;which application is in use. Aged-out for TCP most of the&amp;nbsp;time no 3-way handshake&amp;nbsp;completed (routing issue, asymmetric routing, another firewall on the way etc):&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BB.PNG" style="width: 416px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9985iD18A5EF638C2E0BB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="BB.PNG" alt="BB.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSH into the box and source the traffic from the internal PA source ip address. In my case see below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; ping source 192.168.163.1 host cisco.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After, check the&amp;nbsp;logs. Especially&amp;nbsp;bytes received&amp;nbsp;column.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 09:18:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/163806#M52981</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-29T09:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: Aged-out issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/164578#M53077</link>
      <description>&lt;P&gt;Hi sorry for the late reply.&lt;/P&gt;&lt;P&gt;I could not find the "bytes sent" and "byetes receive" on the monitor tab.&lt;/P&gt;&lt;P&gt;However I could ping from the internal IP of PA to cisco.com and it shows on the monitor tab.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cisco.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10069iEC2CD8947E4BB6BA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="cisco.JPG" alt="cisco.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but now it still shows that "incomplete" on the application column.&lt;/P&gt;&lt;P&gt;Could you help me to solve to access the website through PA?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 02:48:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-issue/m-p/164578#M53077</guid>
      <dc:creator>itsuki.h1991</dc:creator>
      <dc:date>2017-07-05T02:48:05Z</dc:date>
    </item>
  </channel>
</rss>

