<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Destination mac in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240151#M68807</link>
    <description>&lt;P&gt;Is the firewall configured as dhcp relay or as a dhcp server for that vlan?&amp;nbsp;&amp;nbsp;I wonder if try to use debug flow basic may give it bit more insight of what the firewall is doing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clf1CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clf1CAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Nov 2018 16:11:50 GMT</pubDate>
    <dc:creator>nextgenhappines</dc:creator>
    <dc:date>2018-11-16T16:11:50Z</dc:date>
    <item>
      <title>Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240135#M68792</link>
      <description>&lt;P&gt;I was having issues with DHCP being blocked, so I can a packet capture from the PA to see if I could tell was was blocking the DHCP traffic and if it could possbile be the PA. It shows the mac address of the interface on the PA as the source and then its lists a mac address that I cannot identify as the destination. So if anyone has any ideas of how to figure out what that destination mac belongs too I would appreicate it. The PA has to be reading it from somewhere&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 14:32:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240135#M68792</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-11-16T14:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240138#M68795</link>
      <description>&lt;P&gt;DHCP has following steps:&lt;/P&gt;&lt;P&gt;Discover (client sends packet with it's own source mac to destination mac&amp;nbsp;&lt;SPAN&gt;FF:FF:FF:FF:FF:FF).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Offer (DHCP servers reply with their source mac and destination mac is client mac address.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Request&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Acnowledge&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So looks like Offer packet got dropped.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You have to check switch mac address table to identify switchport client mac is connected to.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you know what switches you have so we can help you with command?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would start with&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;show mac-address-table&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;or&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;show mac-address-table | include xxxx (replace xxxx with client mac)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 14:47:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240138#M68795</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-11-16T14:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240141#M68798</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Yeah it doesn't get past the discover, but we have already search the switches and the core switches no sign of that address in any of the mac address-table so where did the PA get it&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 15:15:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240141#M68798</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-11-16T15:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240142#M68799</link>
      <description>&lt;P&gt;Just out of curious, which stage of the capture are you reviewing?&amp;nbsp; Also, can you share that mac address?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 15:19:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240142#M68799</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2018-11-16T15:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240143#M68800</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23897"&gt;@nextgenhappines&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I am sharing from the drop traffic&amp;nbsp; and the mac address appears as destination (00:70:76:69:66:00) from the PA during the DHCP discover.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 15:27:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240143#M68800</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-11-16T15:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240147#M68803</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;To allow DHCP between zones, you need an inbound policy and outbound. The Client makes hte request, indound. Then the server gets the request and sends a reply, the outbound component. So its sources from each, client and server, thus you need a policy to allow traffic both ways.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 15:58:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240147#M68803</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-11-16T15:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240148#M68804</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;It has been working for a few years and suddenly stopped working, so we did some packet captures and now trying to hunt down why the 1 vlan quit working correctly&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 16:01:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240148#M68804</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-11-16T16:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240149#M68805</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If the firewall is not blocking any traffic, need to look at everything else.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the ip helper on the vlan&lt;/P&gt;&lt;P&gt;verify the dhcp server is seeing the requests, you can enable logging&lt;/P&gt;&lt;P&gt;verify the reply packet is getting set back via the firewall logs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 16:03:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240149#M68805</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-11-16T16:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240151#M68807</link>
      <description>&lt;P&gt;Is the firewall configured as dhcp relay or as a dhcp server for that vlan?&amp;nbsp;&amp;nbsp;I wonder if try to use debug flow basic may give it bit more insight of what the firewall is doing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clf1CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clf1CAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 16:11:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240151#M68807</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2018-11-16T16:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240152#M68808</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23897"&gt;@nextgenhappines&lt;/a&gt;&lt;/P&gt;&lt;P&gt;At the time this packet capture was taken it was being used as a DHCP relay server, to get it to work we are nowing serving DHCP to that vlan using the PA. I will take a look at the link, course we would have to take the work around off, to do the testing so I need to schedule a time. So the mac address I have as a destination where is it getting that? Could it be bogus?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 16:18:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240152#M68808</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-11-16T16:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240153#M68809</link>
      <description>&lt;P&gt;I can't verify it..&amp;nbsp; If I have to take a guess it maybe the internal mac addresses between the data planes and management planes in the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 16:21:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240153#M68809</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2018-11-16T16:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240162#M68812</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23897"&gt;@nextgenhappines&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I did not know there could be a mac address between the dataplane and the management plane, never really thought about it&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 17:01:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240162#M68812</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-11-16T17:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240178#M68815</link>
      <description>&lt;P&gt;If you now serve IPs from PA do you see this mac in firewall?&lt;/P&gt;&lt;P&gt;show dhcp server lease interface all&lt;/P&gt;&lt;P&gt;show dhcp server lease interface all | match xxxx&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 19:10:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240178#M68815</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-11-16T19:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240188#M68823</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23897"&gt;@nextgenhappines&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it called the control plane?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 20:44:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240188#M68823</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-11-16T20:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240192#M68826</link>
      <description>&lt;P&gt;Control Plane and Management Plane is one and the same. Some Palo documentation uses one some other name &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 21:01:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240192#M68826</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-11-16T21:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240193#M68827</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thanks I thought that would be the case, so that is my mystery mac address, so should it be listing that management plan and not the mac address of the server that the PA is trying to relay it too,&amp;nbsp; it lists the destination IP for the DHCP server correctly but gives the mac address of the management plane as the destination not the mac of the DHCP server&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 21:05:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240193#M68827</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-11-16T21:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240196#M68829</link>
      <description>&lt;P&gt;Those internal mac addresses are not listed on the management plane.&amp;nbsp; If you still have the packets with all the other stages (recevie, transmit, firewall and drop).&amp;nbsp; Check on the other capture if that mystery mac address is present.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 21:10:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240196#M68829</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2018-11-16T21:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240197#M68830</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23897"&gt;@nextgenhappines&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I only have the drop, so does that mean that the management plane is failing to pass the traffic on , it show the IP address of the DHCP server in the capture but then list the managemen plane and the destination mac, that doesn't seem right, LOL&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 21:16:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240197#M68830</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-11-16T21:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240202#M68835</link>
      <description>&lt;P&gt;It is diificult to determine the cause without additiional&amp;nbsp;information.&amp;nbsp; It could due to many thing, for example, security policy block and others.&amp;nbsp; &amp;nbsp;It will be helpful to have a debug flow basic and show counter global filter packet-filter yes delta yes output to provide more information.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this the only dhcp relay configured on the firewall?&amp;nbsp; Do you have a network diagram that can provide additional information about the setup.&amp;nbsp; &amp;nbsp; Also, as others already said, any packet captures or logs on the DHCP server end?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 22:01:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240202#M68835</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2018-11-16T22:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: Destination mac</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240203#M68836</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;support sent me a doc&lt;SPAN class="im"&gt;&lt;BR /&gt;based on that he says the management plane is something completely different from the control plane. I think it shows the are one and the same&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="im"&gt;&amp;nbsp;&lt;A href="https://media.paloaltonetworks.com/documents/Single_Pass_Parallel_Processing_Architecture.pdf" target="_blank"&gt;https://media.paloaltonetworks.com/documents/Single_Pass_Parallel_Processing_Architecture.pdf&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 22:11:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/destination-mac/m-p/240203#M68836</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-11-16T22:11:41Z</dc:date>
    </item>
  </channel>
</rss>

