<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama traffic invisible in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-traffic-invisible/m-p/180377#M55848</link>
    <description>&lt;P&gt;Not sure if l fully understood your&amp;nbsp;question, but for the traffic visibility on VM you must have an active licenses, otherwise no traffic will be shown&amp;nbsp;in the&amp;nbsp;monitor tab.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Oct 2017 19:32:02 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-10-05T19:32:02Z</dc:date>
    <item>
      <title>Panorama traffic invisible</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-traffic-invisible/m-p/180369#M55847</link>
      <description>&lt;P&gt;PAN(VM) and PA1 management interfaces are both Zone A.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA1 connects to PA2(remote site) on IPSEC tunnel. Traffic from PA2 on PA1 is considered in Zone A and viceversa on PA2 for traffic from PA1.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i do packet capture on either PA, I can see there is bidirectional traffic between PA2 and PAN. But traffic logs don't show anything, I may select&amp;nbsp;any PAN/PA&amp;nbsp;as source or destination.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 19:19:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-traffic-invisible/m-p/180369#M55847</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2017-10-05T19:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama traffic invisible</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-traffic-invisible/m-p/180377#M55848</link>
      <description>&lt;P&gt;Not sure if l fully understood your&amp;nbsp;question, but for the traffic visibility on VM you must have an active licenses, otherwise no traffic will be shown&amp;nbsp;in the&amp;nbsp;monitor tab.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 19:32:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-traffic-invisible/m-p/180377#M55848</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-10-05T19:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama traffic invisible</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-traffic-invisible/m-p/180386#M55850</link>
      <description>&lt;P&gt;We have License for that. We manage both firewalls through Panorama and also push logs to it.&lt;/P&gt;&lt;P&gt;As both the management interface for PA1 and PAN are in same zone, I do not see traffic for it as it doesnot has to cross firewall. But for the remote site PA2 which is also managed by Panorama (location same as PA1), traffic has to pass though tunnel to PA2's management interface. This traffic should be vissible at both PA1 and PA2, which is not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 342px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11768iA7B5FC28D72B031D/image-dimensions/342x89/is-moderation-mode/true?v=v2" width="342" height="89" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 19:44:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-traffic-invisible/m-p/180386#M55850</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2017-10-05T19:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama traffic invisible</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-traffic-invisible/m-p/180462#M55858</link>
      <description>&lt;P&gt;Traffic inside same zone will match to intrazone-default rule that does not log traffic by default.&lt;/P&gt;&lt;P&gt;Choose intrazone-default rule and click override.&lt;/P&gt;&lt;P&gt;Then you can edit rule settings to enable log at session end.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2017 03:24:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-traffic-invisible/m-p/180462#M55858</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-10-06T03:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama traffic invisible</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-traffic-invisible/m-p/180481#M55861</link>
      <description>&lt;P&gt;Is the session visible in the session table?&lt;/P&gt;
&lt;P&gt;The connection from a firewall back to panorama is a permanent ssl session&lt;/P&gt;
&lt;P&gt;Because it is permanently up, it will not show up in the logs until it is terminated (it is 1 connection for an 'unlinited' amount of time, rather than a bunch of ssl sessions oer time) because logs are generated when a session ends (log at end)&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2017 06:19:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-traffic-invisible/m-p/180481#M55861</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-10-06T06:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama traffic invisible</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-traffic-invisible/m-p/180576#M55881</link>
      <description>&lt;P&gt;So what is the recomended log setting. As malacious traffic session if is able to stay&amp;nbsp;up for long we would not see it.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2017 16:04:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-traffic-invisible/m-p/180576#M55881</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2017-10-06T16:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama traffic invisible</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-traffic-invisible/m-p/180579#M55883</link>
      <description>No need to change anything&lt;BR /&gt;This is only a unique issue with panorama 'call home' connections, this does not normally apply to regular traffic&lt;BR /&gt;If a threat is detected the threat will be logged and if the session is terminated becauer of the threat (in case threat action is reset or drop for example) that will be logged too</description>
      <pubDate>Fri, 06 Oct 2017 16:12:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-traffic-invisible/m-p/180579#M55883</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-10-06T16:12:02Z</dc:date>
    </item>
  </channel>
</rss>

