<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Arp getting time out after 30 min on sub interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/arp-getting-time-out-after-30-min-on-sub-interface/m-p/216099#M62617</link>
    <description>&lt;P&gt;We are facing some starnge issue .&lt;/P&gt;&lt;P&gt;We are having an ISP which is connected to sub interface.&lt;/P&gt;&lt;P&gt;We are trying to repalce it with new one. Same Subnet /29 but different IP. NAT rules also same because same subnet.&lt;/P&gt;&lt;P&gt;The issue we are facing is when new ISP configured , we are getting the ARP entries for ISP gateway on Palo Alto Sub interface however its expiring after 30 min which is normal arp interval.&lt;/P&gt;&lt;P&gt;After 30 min ARP is not learning.&lt;/P&gt;&lt;P&gt;I tried clearing arp. No success.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Last I tried manually configured static ARP on sub interface and Now The sub interface can reach the gateway IP now.&lt;/P&gt;&lt;P&gt;It seems after 30 min interval the Palo Alto is not trying to send the ARP request.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However when I connect my old ISP back it works perfectly. Does some one face similiar issues&lt;/P&gt;</description>
    <pubDate>Thu, 31 May 2018 13:00:50 GMT</pubDate>
    <dc:creator>Roby_Sreejith</dc:creator>
    <dc:date>2018-05-31T13:00:50Z</dc:date>
    <item>
      <title>Arp getting time out after 30 min on sub interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-getting-time-out-after-30-min-on-sub-interface/m-p/216099#M62617</link>
      <description>&lt;P&gt;We are facing some starnge issue .&lt;/P&gt;&lt;P&gt;We are having an ISP which is connected to sub interface.&lt;/P&gt;&lt;P&gt;We are trying to repalce it with new one. Same Subnet /29 but different IP. NAT rules also same because same subnet.&lt;/P&gt;&lt;P&gt;The issue we are facing is when new ISP configured , we are getting the ARP entries for ISP gateway on Palo Alto Sub interface however its expiring after 30 min which is normal arp interval.&lt;/P&gt;&lt;P&gt;After 30 min ARP is not learning.&lt;/P&gt;&lt;P&gt;I tried clearing arp. No success.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Last I tried manually configured static ARP on sub interface and Now The sub interface can reach the gateway IP now.&lt;/P&gt;&lt;P&gt;It seems after 30 min interval the Palo Alto is not trying to send the ARP request.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However when I connect my old ISP back it works perfectly. Does some one face similiar issues&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 13:00:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-getting-time-out-after-30-min-on-sub-interface/m-p/216099#M62617</guid>
      <dc:creator>Roby_Sreejith</dc:creator>
      <dc:date>2018-05-31T13:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: Arp getting time out after 30 min on sub interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-getting-time-out-after-30-min-on-sub-interface/m-p/216201#M62640</link>
      <description>&lt;P&gt;I would double-check your source-NAT policy.&amp;nbsp; When I've seen this happen, it's been because the source-NAT address was inadvertently configured as a subnet entry (x.x.x.x/yy) instead of a single IP address (x.x.x.x).&amp;nbsp; If you include the CIDR mask along with the address, the firewall will think it owns all of the IP addresses in that subnet, including your ISP's address.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 22:25:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-getting-time-out-after-30-min-on-sub-interface/m-p/216201#M62640</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2018-05-31T22:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Arp getting time out after 30 min on sub interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-getting-time-out-after-30-min-on-sub-interface/m-p/216225#M62645</link>
      <description>&lt;P&gt;I have done debug logs and I could not see ant NAT translation logs.&lt;/P&gt;&lt;P&gt;Also Immeditaly, once i connect to different ISP it works fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For this new ISP ,it learns ARP dynamically for first time. But after 30 min it expires then it never learns.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also if you configure static arp in Palo Alto sub interface it works fine&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 07:33:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-getting-time-out-after-30-min-on-sub-interface/m-p/216225#M62645</guid>
      <dc:creator>Roby_Sreejith</dc:creator>
      <dc:date>2018-06-01T07:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: Arp getting time out after 30 min on sub interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-getting-time-out-after-30-min-on-sub-interface/m-p/216284#M62665</link>
      <description>&lt;P&gt;What will happen when arp expire after 30 min. I could not see palo alto sending arp towards ISP&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 14:42:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-getting-time-out-after-30-min-on-sub-interface/m-p/216284#M62665</guid>
      <dc:creator>Roby_Sreejith</dc:creator>
      <dc:date>2018-06-01T14:42:50Z</dc:date>
    </item>
  </channel>
</rss>

