<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: wlc monility and EoIp traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wlc-monility-and-eoip-traffic/m-p/244260#M69719</link>
    <description>&lt;P&gt;- Make sure you are logging this traffic. If you think it hits the default intrazone rule you need to&amp;nbsp;explicitly set it to log traffic.&lt;/P&gt;&lt;P&gt;- If&amp;nbsp;this is a long lasting session, check the session browser to see if you can see it there.&lt;/P&gt;&lt;P&gt;- Try to log at session start as well as session end.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Dec 2018 15:34:38 GMT</pubDate>
    <dc:creator>rodvand_de</dc:creator>
    <dc:date>2018-12-21T15:34:38Z</dc:date>
    <item>
      <title>wlc monility and EoIp traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wlc-monility-and-eoip-traffic/m-p/244216#M69712</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have WLC and anchor-WLC with PA firewall in between, I have rule allowing EoIP and wlc-mobility APPs with application-default service selected, I don't see on monitor tab any single packet logged, even though I know for sure it is there, I was able to see it through PA CLI with debug filter set(EoIP example packet below):&lt;/P&gt;&lt;P&gt;Packet received at fastpath stage&lt;BR /&gt;Packet info: len 118 port 17 interface 264 vsys 1&lt;BR /&gt;wqe index 150956 packet 0x0x7f00173ccdc6&lt;BR /&gt;Packet decoded dump:&lt;BR /&gt;L2: cc:ef:48:37:36:30-&amp;gt;00:50:56:a9:38:d2, type 0x0800&lt;BR /&gt;IP: 10.10.112.10-&amp;gt;10.111.2.10, protocol 97&lt;BR /&gt;version 4, ihl 5, tos 0x00, len 100,&lt;BR /&gt;id 46, frag_off 0x0000, ttl 254, checksum 40711&lt;BR /&gt;L4 binary dump: 16 bytes&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Can someone explain why it is not seen on monitor tab&amp;nbsp; ?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Dec 2018 11:48:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wlc-monility-and-eoip-traffic/m-p/244216#M69712</guid>
      <dc:creator>evdanil</dc:creator>
      <dc:date>2018-12-21T11:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: wlc monility and EoIp traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wlc-monility-and-eoip-traffic/m-p/244260#M69719</link>
      <description>&lt;P&gt;- Make sure you are logging this traffic. If you think it hits the default intrazone rule you need to&amp;nbsp;explicitly set it to log traffic.&lt;/P&gt;&lt;P&gt;- If&amp;nbsp;this is a long lasting session, check the session browser to see if you can see it there.&lt;/P&gt;&lt;P&gt;- Try to log at session start as well as session end.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Dec 2018 15:34:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wlc-monility-and-eoip-traffic/m-p/244260#M69719</guid>
      <dc:creator>rodvand_de</dc:creator>
      <dc:date>2018-12-21T15:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: wlc monility and EoIp traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wlc-monility-and-eoip-traffic/m-p/244321#M69739</link>
      <description>&lt;P&gt;Well, I have an explicit rule for internal WLC and anchor WLC with "cisco-wlc-mobility" and "etherip" app and service default setting, i enabled loggin at the start of the session and at the end of the session. I see all kind of management traffic -&amp;nbsp; ping/ssh/snmp - whatever is allowed on the same rule, but as I said previously I dont see any single packet logged for etherip and udp 16666.&lt;/P&gt;&lt;P&gt;I removed internal WLC from mobility group at anchor WLC, and added it back - to re-establish the traffic flows, so I consequently saw control/data path down and then they went up, still no single packet appeared for etherip nor mobility in monitor tab.. I am lost. For me it looks like a bug, this is 7.1.20 version of PAN-OS. i dont beleive that traffic flow should hit inter-zone rule, because I have specific rule on top of the rulebase, is there a way to find out in CLI which rule hits the traffic flow ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Dec 2018 01:00:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wlc-monility-and-eoip-traffic/m-p/244321#M69739</guid>
      <dc:creator>evdanil</dc:creator>
      <dc:date>2018-12-22T01:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: wlc monility and EoIp traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wlc-monility-and-eoip-traffic/m-p/244333#M69741</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you looked in the "session browser" for the session?&amp;nbsp;It will show which rule is being hit.&lt;/P&gt;&lt;P&gt;Otherwise you can "test" the security policy in CLI by using some of the test commands (&lt;A href="https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-cli-quick-start/use-the-cli/test-policy-matches.html#69222" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-cli-quick-start/use-the-cli/test-policy-matches.html#69222&lt;/A&gt;)&lt;/P&gt;</description>
      <pubDate>Sat, 22 Dec 2018 09:44:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wlc-monility-and-eoip-traffic/m-p/244333#M69741</guid>
      <dc:creator>rodvand_de</dc:creator>
      <dc:date>2018-12-22T09:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: wlc monility and EoIp traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wlc-monility-and-eoip-traffic/m-p/244334#M69742</link>
      <description>&lt;P&gt;Yes test shows that protocol 97 and udp/16666 matching same rule as other traffic, only other traffic is logged and these types aren't ;). Very odd, especially udp/16666 which is normal udp traffic and should be logged as any other.. I can understand some issues with protocol 97 as it is not that common..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found 'session browser' and there are both etherip and udp/16666 flows present, I did not figure it out earlier because I was using Panorama and it does not have 'session browser', when I switched to firewall direct I found it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Probably I do not see etherip/mobility on monitor tab because session never ends/start as it is, or I need to disable mobility group for a much longer time for firewall to remove stale session and add log to monitor tab about started mobility session.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Dec 2018 11:13:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wlc-monility-and-eoip-traffic/m-p/244334#M69742</guid>
      <dc:creator>evdanil</dc:creator>
      <dc:date>2018-12-22T11:13:41Z</dc:date>
    </item>
  </channel>
</rss>

