<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/252211#M71710</link>
    <description>&lt;P&gt;For sure no i don't keep such setting, but i did that for testing purpose it was "True" i put it "False" to check if issue will get resolved but it didn't. Is it possible that A10 device makes such issue? maybe its SFPs are not compatible with the new PA ethernet ports?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Mar 2019 20:11:21 GMT</pubDate>
    <dc:creator>SamerKiwan</dc:creator>
    <dc:date>2019-03-04T20:11:21Z</dc:date>
    <item>
      <title>PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251671#M71563</link>
      <description>&lt;P&gt;Dear experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am moving from PA3050 to PA3220. I did export the current configurations from the old PA3050 and imported to the new PA3220, i committed successfully, but when i migrate cables from old device to the new one i get random issue! like some zones are not reachable, like i have ping to internet and telnet and traceroute but i can't browse!, like i can't ping some destinations. WEIRD! its the SAME configuration and OS versions are the same on both devices plus, i did download and install latest content version on both devices before moving the exporting the config file.xml.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NOTE: when i move to old PA3050 all work properly!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One more thing, we have A10 (SSL Interception) connected to PA from external side and StormShield (AS core firewall).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;REALLY WOULD APPRECIATE YOUR HELP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 14:54:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251671#M71563</guid>
      <dc:creator>SamerKiwan</dc:creator>
      <dc:date>2019-02-28T14:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251771#M71579</link>
      <description>&lt;P&gt;Maybe asymmetric routing? Traffic like ping doesn't need a 3-way handshake to work through the PA but internet browsing would. Maybe the syn-ack isn't going through the PA?&lt;/P&gt;&lt;P&gt;Did anything else change when you moved to the new firewall?&lt;/P&gt;&lt;P&gt;Is there anything in the logs showing this traffic dropping?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 16:29:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251771#M71579</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-02-28T16:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251779#M71581</link>
      <description>&lt;P&gt;NO, i checked through all dvices, no single drop in any.. plus i cleared ARP in PA and in neighbor devices and still not working, i noticed that i can't ping from PA interface to the other end which is a switch. i have no idea why would this happen...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 16:38:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251779#M71581</guid>
      <dc:creator>SamerKiwan</dc:creator>
      <dc:date>2019-02-28T16:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251780#M71582</link>
      <description>&lt;P&gt;What do the ARP entries on the PA and switch show for each other? Are they correct?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 16:47:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251780#M71582</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-02-28T16:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251781#M71583</link>
      <description>&lt;P&gt;Its showing the correct ARP, PA MAC address matching the correct IP. On the other hand, why would be an asymetric routing if nothing changed in the network except changing the device.? that's the point here.. whenever i switch cable to the old device all work properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 16:50:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251781#M71583</guid>
      <dc:creator>SamerKiwan</dc:creator>
      <dc:date>2019-02-28T16:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251783#M71584</link>
      <description>&lt;P&gt;Is there asymmetry in your network? There is a setting on the PA to bypass the dropping of traffic where the full handshake isn't seen. Was that set on the old firewall?&lt;/P&gt;&lt;P&gt;If you do '&lt;SPAN&gt;show session info' ,there's a section for Session Setup that will tell you the current value of this setting. Default is True, meaning it will drop the traffic. If it's set to False, then the full handshake isn't needed to permit traffic.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 16:59:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251783#M71584</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-02-28T16:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251786#M71585</link>
      <description>&lt;P&gt;You mean its a setting in the Zone protection? I created a zone protection.. --&amp;gt;Packet based attack protection--&amp;gt;"reject non SYN TCP" i put it to "NO" and the Asymmetric Path to "Bypass"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that correct?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 17:09:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251786#M71585</guid>
      <dc:creator>SamerKiwan</dc:creator>
      <dc:date>2019-02-28T17:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251787#M71586</link>
      <description>&lt;P&gt;No, it's a command line entry. At the CLI, you enter 'show session info'. Then look for the section called 'Session setup'.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 17:19:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251787#M71586</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-02-28T17:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251788#M71587</link>
      <description>&lt;P&gt;Ah i didn't, but i will check this and get back to you. One more thing, would this affect the other zones as well ? i mean would this affect the DMZ zone ? or only this would affect internet connectivity.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 17:25:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251788#M71587</guid>
      <dc:creator>SamerKiwan</dc:creator>
      <dc:date>2019-02-28T17:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251789#M71588</link>
      <description>&lt;P&gt;Ah i didn't, but i will check this and get back to you. One more thing, would this affect the other zones as well ? i mean would this affect the DMZ zone ? or only this would affect internet connectivity.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 17:26:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251789#M71588</guid>
      <dc:creator>SamerKiwan</dc:creator>
      <dc:date>2019-02-28T17:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251790#M71589</link>
      <description>&lt;P&gt;It's a global setting so any asymmetric traffic would be affected.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 17:28:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251790#M71589</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-02-28T17:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251791#M71590</link>
      <description>&lt;P&gt;Ah okay, but this global setting shouldn't be included in the config file that i exported from the old PA3050 ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 17:33:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251791#M71590</guid>
      <dc:creator>SamerKiwan</dc:creator>
      <dc:date>2019-02-28T17:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251792#M71591</link>
      <description>It’s probably included but I don’t know for sure.</description>
      <pubDate>Thu, 28 Feb 2019 17:54:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251792#M71591</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-02-28T17:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251793#M71592</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/90262"&gt;@SamerKiwan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;So the configuration on your 3050 and your PA-3220 is&amp;nbsp;&lt;EM&gt;going&lt;/EM&gt; to be different in a few ways. Things I would verify:&lt;/P&gt;&lt;P&gt;1) On the PA-3220 are you using interfaces 17 through 20, and if so have you actually verified the interface is set to the proper speed if you are using SFP instead of SFP+?&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Importing a configuration like that can cause some issues if things don't 100% import properly. I would pull the PA-3050 and the PA-3220 configurations and verify that they are actually similar by running a compare.&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) What do you see on the logs when you are attempting to browse? Resets or age-out responses?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 18:08:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251793#M71592</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-02-28T18:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251794#M71593</link>
      <description>&lt;P&gt;Okay, Thank you very much for your responses. I will check and update you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 18:09:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251794#M71593</guid>
      <dc:creator>SamerKiwan</dc:creator>
      <dc:date>2019-02-28T18:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251803#M71596</link>
      <description>1) i am using ports 1-12&lt;BR /&gt;2) I didnt compare through config audit i will do so&lt;BR /&gt;3)i see resets, but all actions are allowed..</description>
      <pubDate>Thu, 28 Feb 2019 18:24:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/251803#M71596</guid>
      <dc:creator>SamerKiwan</dc:creator>
      <dc:date>2019-02-28T18:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/252113#M71678</link>
      <description>&lt;P&gt;@&lt;SPAN class=""&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733" target="_self"&gt;rmfalconer&lt;/A&gt;&amp;nbsp;what is the setting exact name of the asymetric routing ? below is my session settings&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Session setup&lt;BR /&gt;TCP - reject non-SYN first packet: False&lt;BR /&gt;Hardware session offloading: True&lt;BR /&gt;Hardware UDP session offloading: True&lt;BR /&gt;IPv6 firewalling: True&lt;BR /&gt;Strict TCP/IP checksum: True&lt;BR /&gt;Strict TCP RST sequence: True&lt;BR /&gt;Reject TCP small initial window: False&lt;BR /&gt;ICMP Unreachable Packet Rate: 200 pps&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 08:23:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/252113#M71678</guid>
      <dc:creator>SamerKiwan</dc:creator>
      <dc:date>2019-03-04T08:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/252114#M71679</link>
      <description>&lt;P&gt;@&lt;SPAN class=""&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480" target="_self"&gt;BPry&lt;/A&gt;&amp;nbsp;I checked configuration syntax its exactly the same.. :S any other suggestions ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 08:39:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/252114#M71679</guid>
      <dc:creator>SamerKiwan</dc:creator>
      <dc:date>2019-03-04T08:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/252210#M71709</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The setting that shows that asymmetry is permitted is "TCP - reject non-SYN first packet: False"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is this on both firewalls?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Are you absolutely sure that this is a setting you want enabled? It's definitely not best practice to enable. Do you know why you have flows bypassing the firewall?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 19:50:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/252210#M71709</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-03-04T19:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE HELP.. same config but not working! from PA 3050 to PA 3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/252211#M71710</link>
      <description>&lt;P&gt;For sure no i don't keep such setting, but i did that for testing purpose it was "True" i put it "False" to check if issue will get resolved but it didn't. Is it possible that A10 device makes such issue? maybe its SFPs are not compatible with the new PA ethernet ports?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 20:11:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-same-config-but-not-working-from-pa-3050-to-pa-3220/m-p/252211#M71710</guid>
      <dc:creator>SamerKiwan</dc:creator>
      <dc:date>2019-03-04T20:11:21Z</dc:date>
    </item>
  </channel>
</rss>

