<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Guest  Mobility Anchor  Controller Tunnels are down when placed behind Palo Alto firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-mobility-anchor-controller-tunnels-are-down-when/m-p/221136#M63721</link>
    <description>Hi All,&lt;BR /&gt;&lt;BR /&gt;The issue was that the vlans were not allowed in the virtual wire. Once I allowed the vlans everything worked fine. Thanks for the valuable replies guys.&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Mon, 09 Jul 2018 07:24:04 GMT</pubDate>
    <dc:creator>shabeeb</dc:creator>
    <dc:date>2018-07-09T07:24:04Z</dc:date>
    <item>
      <title>Cisco Guest  Mobility Anchor  Controller Tunnels are down when placed behind Palo Alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-mobility-anchor-controller-tunnels-are-down-when/m-p/220023#M63489</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a pair of Cisco controllers setup as mobility anchor controllers,&amp;nbsp; which will basically initiate EoIP tunnel between them. Recently we have placed a Palo Alto 5250 firewalls between the controllers through virtual wire interfaces. The physical connectivity is as follows&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco Controller 1 ----&amp;gt; Palo Alto VWire-IN -------&amp;gt; Palo Alto VWire-Out -----&amp;gt; Cisco Controller 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is that after placing the Palo Alto firewall , the tunnel between the controllers is not coming up. I have all allowed the traffic in both directions. There is no rule blocking the traffic. Please let me know if anyone had the similar issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shabeeb&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jul 2018 07:35:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-mobility-anchor-controller-tunnels-are-down-when/m-p/220023#M63489</guid>
      <dc:creator>shabeeb</dc:creator>
      <dc:date>2018-07-01T07:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Guest  Mobility Anchor  Controller Tunnels are down when placed behind Palo Alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-mobility-anchor-controller-tunnels-are-down-when/m-p/220208#M63542</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75862"&gt;@shabeeb&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I would wireshark both ends and look and see if the Palo is manipulating the packets in some way. That's about the only thing I can think of that would be breaking this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/31426"&gt;@tac.in&lt;/a&gt;&amp;nbsp;makes a really good point; you are allowing the traffic with service and application set to 'any' right? I always assume that in a v-wire configuration that is how the rule is built, however that is sometimes something that people can run into.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jul 2018 18:28:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-mobility-anchor-controller-tunnels-are-down-when/m-p/220208#M63542</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-03T18:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Guest  Mobility Anchor  Controller Tunnels are down when placed behind Palo Alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-mobility-anchor-controller-tunnels-are-down-when/m-p/220323#M63566</link>
      <description>&lt;P&gt;Hi Shabeeb,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please try changing service from application-defaults to any. The tunnel might be on other ports other than default ports .&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jul 2018 09:47:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-mobility-anchor-controller-tunnels-are-down-when/m-p/220323#M63566</guid>
      <dc:creator>tac.in</dc:creator>
      <dc:date>2018-07-03T09:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Guest  Mobility Anchor  Controller Tunnels are down when placed behind Palo Alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-mobility-anchor-controller-tunnels-are-down-when/m-p/221136#M63721</link>
      <description>Hi All,&lt;BR /&gt;&lt;BR /&gt;The issue was that the vlans were not allowed in the virtual wire. Once I allowed the vlans everything worked fine. Thanks for the valuable replies guys.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 09 Jul 2018 07:24:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-guest-mobility-anchor-controller-tunnels-are-down-when/m-p/221136#M63721</guid>
      <dc:creator>shabeeb</dc:creator>
      <dc:date>2018-07-09T07:24:04Z</dc:date>
    </item>
  </channel>
</rss>

