<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question About Multicast Not Receiving, IP Flood (URGENT ACTION REQUIRED) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-multicast-not-receiving-ip-flood-urgent-action/m-p/271565#M74841</link>
    <description>&lt;P&gt;Hi Otakar,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When we enabled our LAN interface to be part of multicasting&amp;nbsp; other IP flood threats get started and same is drops in zone protection in critical category and which also spike up my data plane CPU by 10 %&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also we removed zone protection from LAN zone and enabled multicast , then our firewall goes on toss i.e. it disturb my CPU as well as other protocol like BGP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In customer environment they have configured Dos policy from WAN to LAN zone, and also Zone protection profile for LAN zone as well as WAN zone ..?? (Is this a recomended way for using both Dos and Zone protection profile ?)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sethupathi M&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jun 2019 07:11:07 GMT</pubDate>
    <dc:creator>Sethupathi</dc:creator>
    <dc:date>2019-06-20T07:11:07Z</dc:date>
    <item>
      <title>Question About Multicast Not Receiving, IP Flood (URGENT ACTION REQUIRED)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-multicast-not-receiving-ip-flood-urgent-action/m-p/270508#M74720</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;we have done multicast configuration and we are unable to receive multicast through firewall PA-3060. Also whenever we did add our LAN interface into multicast configuration “ other IP flood” critical threat gets started into that particular LAN as shown below. Kindly help me to resolved the same.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Scenario as below,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1st network diagram.png" style="width: 710px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20402i2C215543E6621157/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1st network diagram.png" alt="1st network diagram.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;Requirement as per diagram: PA-3060 WAN interface should receive multicast traffic via ae1.3013 interface and should forward the same to LAN subnet i.e.ae2.3 interface&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;EM&gt;&lt;FONT color="#339966"&gt;As per above scenario which interface should I add the RP typeae1.3013 or ae2.3 ..??&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;We have done following configuration.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2nd.png" style="width: 666px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20403iE6C18A167F6E8164/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2nd.png" alt="2nd.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3rd.png" style="width: 699px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20406iACA75A63FDAAFE9E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3rd.png" alt="3rd.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4th.png" style="width: 691px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20405iFD0879D0874A0E5C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="4th.png" alt="4th.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5th.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20404i2D5CE974BBE60FB2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="5th.png" alt="5th.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;Whenever we did configure ae2.3 in multicast configuration other IP flood started in OFT-LAN subnet and dataplane CPU spike up.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="6th.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20408i8FC87D20E39AAC3C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="6th.png" alt="6th.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7th.png" style="width: 707px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20409iE9A3738932375F59/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="7th.png" alt="7th.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8th.png" style="width: 316px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20407i19C3BA7F59AE012D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="8th.png" alt="8th.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;EM&gt;Should I increes the SYN alarm rate or disable the SYN in zone protection here? (IS THAT CORRECT?)&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;NOTE: we have&amp;nbsp;PA-3060 modal with PAN-OS&amp;nbsp;8.0.16&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please provide your valuable suggestion here to fix an issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sethupathi M&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2019 11:12:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-multicast-not-receiving-ip-flood-urgent-action/m-p/270508#M74720</guid>
      <dc:creator>Sethupathi</dc:creator>
      <dc:date>2019-06-17T11:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: Question About Multicast Not Receiving, IP Flood (URGENT ACTION REQUIRED)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-multicast-not-receiving-ip-flood-urgent-action/m-p/270538#M74724</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone provide your valuable suggestion here please.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sethupathi M&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2019 13:52:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-multicast-not-receiving-ip-flood-urgent-action/m-p/270538#M74724</guid>
      <dc:creator>Sethupathi</dc:creator>
      <dc:date>2019-06-17T13:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: Question About Multicast Not Receiving, IP Flood (URGENT ACTION REQUIRED)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-multicast-not-receiving-ip-flood-urgent-action/m-p/270856#M74768</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help us here, The DOS Protection&amp;nbsp; profile is configured form WAN Zone to LAN Zone, And Zone protection profile is configured for LAN Zone. Is that a cause its getting an Other IP Flood.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sethupathi M&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2019 11:11:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-multicast-not-receiving-ip-flood-urgent-action/m-p/270856#M74768</guid>
      <dc:creator>Sethupathi</dc:creator>
      <dc:date>2019-06-18T11:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: Question About Multicast Not Receiving, IP Flood (URGENT ACTION REQUIRED)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-multicast-not-receiving-ip-flood-urgent-action/m-p/270933#M74779</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Try disabling the Zone protection profile and see if that helps, since its on the internal zone (its usually on the external but internal is not wrong either).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it helps then its the zone protection profile causing the issue and you just need to make adjustments there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2019 14:35:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-multicast-not-receiving-ip-flood-urgent-action/m-p/270933#M74779</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-06-18T14:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: Question About Multicast Not Receiving, IP Flood (URGENT ACTION REQUIRED)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-multicast-not-receiving-ip-flood-urgent-action/m-p/271565#M74841</link>
      <description>&lt;P&gt;Hi Otakar,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When we enabled our LAN interface to be part of multicasting&amp;nbsp; other IP flood threats get started and same is drops in zone protection in critical category and which also spike up my data plane CPU by 10 %&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also we removed zone protection from LAN zone and enabled multicast , then our firewall goes on toss i.e. it disturb my CPU as well as other protocol like BGP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In customer environment they have configured Dos policy from WAN to LAN zone, and also Zone protection profile for LAN zone as well as WAN zone ..?? (Is this a recomended way for using both Dos and Zone protection profile ?)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sethupathi M&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 07:11:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-multicast-not-receiving-ip-flood-urgent-action/m-p/271565#M74841</guid>
      <dc:creator>Sethupathi</dc:creator>
      <dc:date>2019-06-20T07:11:07Z</dc:date>
    </item>
  </channel>
</rss>

