<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Virtual Wire silently discarding packets directed to ip addresses of a L3 interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-silently-discarding-packets-directed-to-ip/m-p/9320#M6827</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem has been eliminated in version 4.0.5.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Sep 2011 10:08:53 GMT</pubDate>
    <dc:creator>cnrpisa</dc:creator>
    <dc:date>2011-09-07T10:08:53Z</dc:date>
    <item>
      <title>Virtual Wire silently discarding packets directed to ip addresses of a L3 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-silently-discarding-packets-directed-to-ip/m-p/9314#M6821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a PA-4020 with PanOS 4.0.3. Policies are mailnly applied to traffic flowing through two parallel Virtual Wires. I have also defined some L3 interfaces , in order to set up some SSL-VPNs. I have noticed that packets whose destination IP address is the IP address of an L3 interface are not allowed to go through the Virtual Wires, even if my policies permit their transit. There is non trace of the discarded packets in the logs. I suspect this is a bug. Did others experiment the same problem?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jul 2011 12:24:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-silently-discarding-packets-directed-to-ip/m-p/9314#M6821</guid>
      <dc:creator>cnrpisa</dc:creator>
      <dc:date>2011-07-20T12:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Wire silently discarding packets directed to ip addresses of a L3 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-silently-discarding-packets-directed-to-ip/m-p/9315#M6822</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You going to need to provide some topology information. Your description sounds as though you have two L3 interfaces in parallel with two sets of vwire interfaces. If you are convinced this is a bug it will require a case be opened with technical support so that it can be reproduced and a bug generated so that it can be fixed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2011 16:54:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-silently-discarding-packets-directed-to-ip/m-p/9315#M6822</guid>
      <dc:creator>pkruse</dc:creator>
      <dc:date>2011-07-26T16:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Wire silently discarding packets directed to ip addresses of a L3 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-silently-discarding-packets-directed-to-ip/m-p/9316#M6823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've enclosed a picture showing my setup. In the situation described in the picture, pings sent from 146.48.99.254 to 146.48.99.251 time out. All other pings from 146.48.99.254 to other addresses in subnet 146.48.96.0/22 succeed. If the virtual wire is bypassed, 146.48.99.254 can ping also 146.48.99.251.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My intention was to use 146.48.99.251 as a gateway for an SSL-VPN. I have found a work-around, so I can survive even with this strange behaviour of the PA-4020.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before submitting a case, I would like to know if my planned setup was wrong.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2011 18:04:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-silently-discarding-packets-directed-to-ip/m-p/9316#M6823</guid>
      <dc:creator>cnrpisa</dc:creator>
      <dc:date>2011-07-26T18:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Wire silently discarding packets directed to ip addresses of a L3 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-silently-discarding-packets-directed-to-ip/m-p/9317#M6824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;cnrpisa wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've enclosed a picture showing my setup. In the situation described in the picture, pings sent from 146.48.99.254 to 146.48.99.251 time out. All other pings from 146.48.99.254 to other addresses in subnet 146.48.96.0/22 succeed. If the virtual wire is bypassed, 146.48.99.254 can ping also 146.48.99.251.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My intention was to use 146.48.99.251 as a gateway for an SSL-VPN. I have found a work-around, so I can survive even with this strange behaviour of the PA-4020.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before submitting a case, I would like to know if my planned setup was wrong.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cnrpisa,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a managment profile that allows ping applied to interface e1/1.96 on the PA-4020?&amp;nbsp; It sounds like this is the problem based on the information you've provided.&amp;nbsp; Remember, the firewall's interface will not reply to pings without a management profile that allows ping applied to that interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Jared&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jul 2011 02:01:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-silently-discarding-packets-directed-to-ip/m-p/9317#M6824</guid>
      <dc:creator>jdavis</dc:creator>
      <dc:date>2011-07-27T02:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Wire silently discarding packets directed to ip addresses of a L3 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-silently-discarding-packets-directed-to-ip/m-p/9318#M6825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The management profile of Ethernet1/1.96 is OK. The proof is that when I bypass the Virtual Wire by connecting the M7i directly to the LAN switch all pings succeed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jul 2011 06:56:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-silently-discarding-packets-directed-to-ip/m-p/9318#M6825</guid>
      <dc:creator>cnrpisa</dc:creator>
      <dc:date>2011-07-27T06:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Wire silently discarding packets directed to ip addresses of a L3 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-silently-discarding-packets-directed-to-ip/m-p/9319#M6826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does your monitor show the ping? Can you see the session from the CLI?&lt;/P&gt;&lt;P&gt;"show session all filter source xxx.xxx.xxx.xxx application ping"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Aug 2011 20:48:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-silently-discarding-packets-directed-to-ip/m-p/9319#M6826</guid>
      <dc:creator>pkruse</dc:creator>
      <dc:date>2011-08-08T20:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Wire silently discarding packets directed to ip addresses of a L3 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-silently-discarding-packets-directed-to-ip/m-p/9320#M6827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem has been eliminated in version 4.0.5.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2011 10:08:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-silently-discarding-packets-directed-to-ip/m-p/9320#M6827</guid>
      <dc:creator>cnrpisa</dc:creator>
      <dc:date>2011-09-07T10:08:53Z</dc:date>
    </item>
  </channel>
</rss>

