<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA-7000 Not passing syslog traffic to Tufin in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193321#M57963</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/54222"&gt;@netzwerk-admin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If it doesn't work then let us know, but I would assume that this should get things working correctly again.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 28 Dec 2017 15:18:11 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-12-28T15:18:11Z</dc:date>
    <item>
      <title>PA-7000 Not passing syslog traffic to Tufin</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193288#M57952</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a PA-7000 (7.1) and Tufin (for syslog).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The system was previously setup to forward syslog traffic to Tufin.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then all of a sudden, Tufin wasn't receiving any traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I have done so far:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Went through the saved configurations to see when the syslog config was changed.&lt;UL&gt;&lt;LI&gt;From the saved configs, I could not see anything that was changed that affected syslog forwarding.&lt;/LI&gt;&lt;LI&gt;No Palo Alto or Tufin updates were installed.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Rechecked the syslog forwarding configuration (at least 5 times as of this writing).&lt;/LI&gt;&lt;LI&gt;Ran tcpdump on Tufin server&amp;nbsp;&lt;UL&gt;&lt;LI&gt;traffic was not getting to Tufin&lt;/LI&gt;&lt;LI&gt;14:00:54.560060 IP (tos 0x0, ttl 60, id 62901, offset 0, flags [DF], proto UDP (17), length 358)&lt;BR /&gt;10.63.249.5.43067 &amp;gt; tufina01.syslog: [udp sum ok] SYSLOG, length: 330&lt;BR /&gt;Facility user (1), Severity error (3)&lt;BR /&gt;Msg: Dec 28 14:02:06 fw-f-wm-dc-1c.infra.dvag.com 1,2017/12/28 14:02:06,010108000926,SYSTEM,userid,0,2017/12/28 14:02:06,,connect-agent-failure,,0,0,general,high,"TS-Agent Citrix wpsxaaabn02.id(vsys1): Error: Failed to connect to wpsxaaabn02.id(10.61.85.151):5009 details: none",827871,0x0,0,0,0,0,,fw-f-wm-dc-1c&lt;/LI&gt;&lt;LI&gt;As seen above, only system type information is reaching Tufin&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Ran tcpdump on&amp;nbsp; PA-7000&lt;UL&gt;&lt;LI&gt;12:14:03.004652 IP 10.63.249.5.53918 &amp;gt; 10.63.98.59.syslog: SYSLOG user.info, length: 226&lt;BR /&gt;12:14:20.101956 IP 10.63.249.5.35845 &amp;gt; 10.63.98.59.syslog: SYSLOG user.info, length: 227&lt;BR /&gt;12:14:31.557722 IP 10.63.249.5.37782 &amp;gt; 10.63.98.59.syslog: SYSLOG user.info, length: 344&lt;BR /&gt;12:14:31.573796 IP 10.63.249.5.53918 &amp;gt; 10.63.98.59.syslog: SYSLOG user.info, length: 253&lt;BR /&gt;12:14:31.640424 IP 10.63.249.5.35845 &amp;gt; 10.63.98.59.syslog: SYSLOG user.info, length: 242&lt;BR /&gt;12:14:32.604810 IP 10.63.249.5.37782 &amp;gt; 10.63.98.59.syslog: SYSLOG user.info, length: 344&lt;BR /&gt;12:14:32.616503 IP 10.63.249.5.53918 &amp;gt; 10.63.98.59.syslog: SYSLOG user.info, length: 253&lt;BR /&gt;12:14:32.682839 IP 10.63.249.5.35845 &amp;gt; 10.63.98.59.syslog: SYSLOG user.info, length: 242&lt;/LI&gt;&lt;LI&gt;Traffic Monitoring shows that syslog (udp 514) packets are allowed, Session End Reason 'aged-out'&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If someone could push me in the right direction to correct this I would greatly appreciate it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jasper Freeman&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 13:10:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193288#M57952</guid>
      <dc:creator>netzwerk-admin</dc:creator>
      <dc:date>2017-12-28T13:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: PA-7000 Not passing syslog traffic to Tufin</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193310#M57958</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/54222"&gt;@netzwerk-admin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Just out of curiosity have you attempted to restart the management plane since you began experiancing these issues?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 15:11:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193310#M57958</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-12-28T15:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: PA-7000 Not passing syslog traffic to Tufin</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193312#M57960</link>
      <description>&lt;P&gt;No we haven't.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll give it a try next week. Don't want to make any changes on a Friday. Especially before a long weekend.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jasper&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 15:14:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193312#M57960</guid>
      <dc:creator>netzwerk-admin</dc:creator>
      <dc:date>2017-12-28T15:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: PA-7000 Not passing syslog traffic to Tufin</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193321#M57963</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/54222"&gt;@netzwerk-admin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If it doesn't work then let us know, but I would assume that this should get things working correctly again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 15:18:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193321#M57963</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-12-28T15:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: PA-7000 Not passing syslog traffic to Tufin</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193322#M57964</link>
      <description>&lt;P&gt;Well, scratch that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A colleague said the system was restarted 8 days ago because a security bug.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, that answer is yes, the management plane was restarted.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 15:23:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193322#M57964</guid>
      <dc:creator>netzwerk-admin</dc:creator>
      <dc:date>2017-12-28T15:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: PA-7000 Not passing syslog traffic to Tufin</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193323#M57965</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/54222"&gt;@netzwerk-admin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So that would indicate that this issue is at least more than 8 days old, and didn't start with the restart?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A couple things that I would check.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Verify that nobody removed the log-forwarding profile from your security policies. I've seen this happen in the pass with multiple firewall admins.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2)&amp;nbsp;Verify that you can actually get a response from Tufin and that there isn't a routing issue. I would expect the Session End Reason to show as 'aged-out' on Syslog traffic, as the firewall never gets anything to tell it to close the session.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is Tufin functioning for other devices okay?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 15:30:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193323#M57965</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-12-28T15:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: PA-7000 Not passing syslog traffic to Tufin</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193386#M57982</link>
      <description>&lt;P&gt;Yes, Tufin is functioning for other devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just restarted the monitoring for the Palo Alto on Tufin and now I'm seeing that syslog traffic is arriving at the Tufin interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, I'm a little confused. If I execute tcpdump it says it is doing the dump an eth0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; e13itfd@fw-f-wm-dc-1c(active)&amp;gt; tcpdump filter "src 10.63.249.5 and port 514" snaplen 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Press Ctrl-C to stop capturing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Results:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; e13itfd@fw-f-wm-dc-1c(active)&amp;gt; view-pcap mgmt-pcap mgmt.pcap&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 07:33:17.762228 IP 10.63.249.5.43067 &amp;gt; 10.63.98.59.syslog: SYSLOG user.error, length: 330&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 07:34:15.498597 IP 10.63.249.5.46508 &amp;gt; 10.63.98.59.syslog: SYSLOG user.error, length: 316&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 07:35:40.596228 IP 10.63.249.5.38662 &amp;gt; 10.63.98.59.syslog: SYSLOG user.error, length: 316&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 07:37:00.204343 IP 10.63.249.5.43067 &amp;gt; 10.63.98.59.syslog: SYSLOG user.error, length: 330&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 07:37:35.926424 IP 10.63.249.5.46508 &amp;gt; 10.63.98.59.syslog: SYSLOG user.error, length: 330&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 07:37:35.926518 IP 10.63.249.5.38662 &amp;gt; 10.63.98.59.syslog: SYSLOG user.error, length: 329&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 07:37:40.205790 IP 10.63.249.5.43067 &amp;gt; 10.63.98.59.syslog: SYSLOG user.error, length: 330&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 07:39:09.685971 IP 10.63.249.5.37782 &amp;gt; 10.63.98.59.syslog: SYSLOG user.info, length: 265&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 07:39:09.685980 IP 10.63.249.5.35845 &amp;gt; 10.63.98.59.syslog: SYSLOG user.info, length: 277&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What confuses me is that on the Palo Alto I don't see any TRAFFIC labled packets. On Tufin a tcpdump with the src=10.63.249.5 also shows no packets at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I decided to see if there are syslog traffic being sent on the Log Card IP. Tufin is seeing syslog TRAFFIC from the Log Card IP; however, the Palo Alto shows no TRAFFIC at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is confusing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;, thanks for the help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2017 06:58:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193386#M57982</guid>
      <dc:creator>netzwerk-admin</dc:creator>
      <dc:date>2017-12-29T06:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: PA-7000 Not passing syslog traffic to Tufin</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193395#M57983</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/54222"&gt;@netzwerk-admin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;By log card do you mean the SMC?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2017 12:54:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193395#M57983</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-12-29T12:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: PA-7000 Not passing syslog traffic to Tufin</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193397#M57985</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually, it's one of the interface on the NPC-20GQ module.&lt;/P&gt;&lt;P&gt;For example, we have ethernet1/3 (type: Log Card) configured for passing log information to Tufin.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2017 12:59:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-7000-not-passing-syslog-traffic-to-tufin/m-p/193397#M57985</guid>
      <dc:creator>netzwerk-admin</dc:creator>
      <dc:date>2017-12-29T12:59:03Z</dc:date>
    </item>
  </channel>
</rss>

