<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Oracle Replication Failed in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7833#M5786</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Thanks but the problem with pcap andthe cli monitor is that the replication is online process and it will work for hours then it will stop, we don't have a trigger to fire to reproduce the problem , it's just happening daily with no time standard&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 26 Feb 2014 21:49:49 GMT</pubDate>
    <dc:creator>malswealmeen</dc:creator>
    <dc:date>2014-02-26T21:49:49Z</dc:date>
    <item>
      <title>Oracle Replication Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7828#M5781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: arial, helvetica, sans-serif;"&gt;We have a case&amp;nbsp; where the Oracle connection failed during the replication to the DR , the replication process start for one to three hours then it failed ,&amp;nbsp; Oracle admins opened a ticket with oracle support and oracle support recommends to disable&amp;nbsp; the below for oracle application :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: arial, helvetica, sans-serif; font-size: 16px;"&gt;SQLNet fixup protocol&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: arial, helvetica, sans-serif; font-size: 16px;"&gt;Deep Packet Inspection (DPI)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: arial, helvetica, sans-serif; font-size: 16px;"&gt;SQLNet packet inspection&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: arial, helvetica, sans-serif; font-size: 16px;"&gt;SQL Fixup&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: arial, helvetica, sans-serif; font-size: 16px;"&gt;SQL ALG &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: arial, helvetica, sans-serif; font-size: 16px;"&gt;We have disabled the the inspection , but for the ALG I found in admin guide v6&amp;nbsp; that the paloalto&amp;nbsp; functions as an ALG for the following protocols: FTP, SIP, H.323, RTSP, &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 16px; line-height: 1.5em;"&gt;Oracle/SQLNet/TNS, MGCP protocols.but shows how to disable ALG just for SIP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: arial, helvetica, sans-serif; font-size: 16px;"&gt;in the time I have added new custom application to override the oracle default one and added it to application policy so the PA will not affect this application .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: arial, helvetica, sans-serif; font-size: 16px;"&gt;and we are waiting for the result .&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: monospace; font-size: 16px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;will this disable the ALG functionality&amp;nbsp; on the Oracle application?&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Feb 2014 21:32:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7828#M5781</guid>
      <dc:creator>malswealmeen</dc:creator>
      <dc:date>2014-02-23T21:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: Oracle Replication Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7829#M5782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you are correct. If you create a custom application and refer that to a application override policy, the PAN firewall will skip the Layer-7 processing ( content check, ALG)&amp;nbsp; for that traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Feb 2014 22:42:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7829#M5782</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-23T22:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: Oracle Replication Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7830#M5783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the same error with the same ORA number in oracle server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Feb 2014 12:10:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7830#M5783</guid>
      <dc:creator>malswealmeen</dc:creator>
      <dc:date>2014-02-24T12:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: Oracle Replication Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7831#M5784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please use this document to create application override policy.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1071"&gt;How to Create an Application Override Policy&lt;/A&gt;&lt;/P&gt;&lt;P&gt;After creating correct policy please check the session by using below command:&lt;/P&gt;&lt;P&gt;show session all filter source &amp;lt;x.x.x.x&amp;gt; destination &amp;lt;y.y.y.y&amp;gt;&lt;/P&gt;&lt;P&gt;show session id &amp;lt;type appropriate session number from above output&amp;gt;&lt;/P&gt;&lt;P&gt;This output will show &lt;/P&gt;&lt;P&gt;layer7 processing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : completed&lt;/P&gt;&lt;P&gt;application&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : &amp;lt;the name of the custom app that you have created&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Feb 2014 15:15:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7831#M5784</guid>
      <dc:creator>Mystique</dc:creator>
      <dc:date>2014-02-24T15:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: Oracle Replication Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7832#M5785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please enable packet capture on PAN firewall between source and destination IP (bi-directional) to understand who is causing this problem. Also if you are using an application override policy for SQL traffic, could you please increase the time-out value for those custom application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ref Doc: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-2313"&gt;How to Run a Packet Capture&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Feb 2014 17:31:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7832#M5785</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-24T17:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: Oracle Replication Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7833#M5786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Thanks but the problem with pcap andthe cli monitor is that the replication is online process and it will work for hours then it will stop, we don't have a trigger to fire to reproduce the problem , it's just happening daily with no time standard&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Feb 2014 21:49:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7833#M5786</guid>
      <dc:creator>malswealmeen</dc:creator>
      <dc:date>2014-02-26T21:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: Oracle Replication Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7834#M5787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to disable TCP sequence number checking:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set deviceconfig setting tcp asymmetric-path bypass&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; set deviceconfig setting tcp asymmetric-path&lt;/P&gt;&lt;P&gt;&amp;nbsp; bypass&amp;nbsp;&amp;nbsp; bypass inspection for the session that has TCP sliding window tracking errors&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; drop offending packets that violated TCP sliding window tracking, enable TCP sequence number check for FIN/RST&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Feb 2014 14:45:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7834#M5787</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2014-02-27T14:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: Oracle Replication Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7835#M5788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Thanks Anon but will it effect other tcp protocol? In other words can we specify it for oracle only? Or for src and dest only?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Mar 2014 13:14:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7835#M5788</guid>
      <dc:creator>malswealmeen</dc:creator>
      <dc:date>2014-03-01T13:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: Oracle Replication Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7836#M5789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no, this setting will disable the inspection globally for all traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Mar 2014 12:59:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/7836#M5789</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2014-03-03T12:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: Oracle Replication Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/580382#M116246</link>
      <description>&lt;P&gt;hi all, for the same problem, I have created custom application override policy for the port TCP/1521 (Oracle application) along with #&amp;nbsp;&lt;SPAN&gt;set deviceconfig setting tcp asymmetric-path bypass but still connections are failing at validation steps. (replication looks fine). when I bypass the PA FW, replication and validation both working fine.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 11:03:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/oracle-replication-failed/m-p/580382#M116246</guid>
      <dc:creator>swapnkok</dc:creator>
      <dc:date>2024-03-14T11:03:04Z</dc:date>
    </item>
  </channel>
</rss>

