<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with SIP traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-sip-traffic/m-p/255814#M72555</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;In a HA A/P configuration, the passive device has its interfaces shut down and processes no traffic, so the config mismatch is a different issue. As for SIP, could be a lot of things.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you inspecting the traffic with AV/AP/URL, etc.?&lt;/P&gt;&lt;P&gt;What if you disable all inspections on the traffic does it work better?&lt;/P&gt;&lt;P&gt;Are you dropping any traffic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I always start with the 'Unified' logs since they show me if its URL/Threat/Traffic etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Apr 2019 22:05:37 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2019-04-02T22:05:37Z</dc:date>
    <item>
      <title>Problem with SIP traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-sip-traffic/m-p/255793#M72549</link>
      <description>&lt;P&gt;Hello there!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problem with SIP traffic for VoIP. It is a HA cluster that has experienced that problem with the SIP traffic for phone calls. For a number of hours, SIP calls could not be made or received. M&lt;SPAN&gt;ismatches with the config between active and passive firewalls were found.&amp;nbsp;Could that have been the cause for the problem with SIP traffic?&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Is it possible to find out why inbound and outbound SIP calls have failed for those hours? I mean, which logs should I look at?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 19:59:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-sip-traffic/m-p/255793#M72549</guid>
      <dc:creator>Bittereinder</dc:creator>
      <dc:date>2019-04-02T19:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with SIP traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-sip-traffic/m-p/255814#M72555</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;In a HA A/P configuration, the passive device has its interfaces shut down and processes no traffic, so the config mismatch is a different issue. As for SIP, could be a lot of things.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you inspecting the traffic with AV/AP/URL, etc.?&lt;/P&gt;&lt;P&gt;What if you disable all inspections on the traffic does it work better?&lt;/P&gt;&lt;P&gt;Are you dropping any traffic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I always start with the 'Unified' logs since they show me if its URL/Threat/Traffic etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 22:05:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-sip-traffic/m-p/255814#M72555</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-04-02T22:05:37Z</dc:date>
    </item>
  </channel>
</rss>

