<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: why would i see traffic on a standby HA PA2020? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/why-would-i-see-traffic-on-a-standby-ha-pa2020/m-p/10400#M7662</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks for your reply bdaussin - do you know if the issue is documented anywhere on this site? I have set the passive box's interfaces to shutdown for now, as this seems to be the only way to be sure of no misdirected traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Feb 2011 10:27:45 GMT</pubDate>
    <dc:creator>LCMember3410</dc:creator>
    <dc:date>2011-02-23T10:27:45Z</dc:date>
    <item>
      <title>why would i see traffic on a standby HA PA2020?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-would-i-see-traffic-on-a-standby-ha-pa2020/m-p/10395#M7657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've just had a couple of PA2020s installed in an Active-Passive HA configuration, running v3.1.7, and I'm trying to diagnose an FTP problem which may or may not be related to the installation. One thing I have discovered is that we're seeing a small amount of traffic (probably less than 1% of the total) on our standby PA2020, but just from a few specific sources. It is all marked as ‘deny’ traffic, which I guess you’d expect on a standby unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We’ve cleared the dynamic arp entries (using &lt;STRONG style=": ; color: black; font-size: 9pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; Arial&amp;amp;quot: ; ,&amp;amp;quot: ; "&gt;clear mac-address-table&lt;/STRONG&gt;&lt;SPAN style=": ; color: black; font-size: 9pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; Arial&amp;amp;quot: ; ,&amp;amp;quot: ; "&gt; &lt;/SPAN&gt;&lt;STRONG style=": ; color: black; font-size: 9pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; Arial&amp;amp;quot: ; ,&amp;amp;quot: ; "&gt;dynamic&lt;/STRONG&gt;&lt;SPAN style=": ; color: black; font-size: 9pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; Arial&amp;amp;quot: ; ,&amp;amp;quot: ; "&gt; &lt;/SPAN&gt;) on our Cisco catalyst switch stack - both PA2020s go into our core stack (into ports in different switches) - which is logically a single switch.&lt;/P&gt;&lt;P&gt;Can anyone explain why we’re seeing any traffic at all on the standby PA? Is there a setting for the ports which we should be using on the switch port(s) to make it ‘HA-friendly’.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Feb 2011 13:36:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-would-i-see-traffic-on-a-standby-ha-pa2020/m-p/10395#M7657</guid>
      <dc:creator>LCMember3410</dc:creator>
      <dc:date>2011-02-18T13:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: why would i see traffic on a standby HA PA2020?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-would-i-see-traffic-on-a-standby-ha-pa2020/m-p/10396#M7658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Matt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What type of traffic is being denied?&amp;nbsp; Is it normal network traffic or could it be BPDU's from the switch trying to do STP?&amp;nbsp; Best practice is to enable portfast on the switch ports connected to the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following command may provide more insight on to the type of packets being dropped:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;show counter global filter severity drop delta yes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Run this command every few seconds for a few times to see which drop counters are incrementing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Feb 2011 16:46:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-would-i-see-traffic-on-a-standby-ha-pa2020/m-p/10396#M7658</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-02-18T16:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: why would i see traffic on a standby HA PA2020?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-would-i-see-traffic-on-a-standby-ha-pa2020/m-p/10397#M7659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've checked through and what we're seeing is almost exclusively&lt;STRONG&gt; FTP traffic&lt;/STRONG&gt; being logged on the standby firewall. Is there something special about the way FTP would be handled by our switches?! (I'm seeing this on both of the interfaces which have automated ftp client activity.) At first I thought this was an ARP issue, but arp tables were cleared several times, and the FTPing systems have been rebooted several times too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We were concerned about denied FTP packets, so we've now set the Passive Link State to 'Shutdown', so this means that I can't monitor for further misdirected packes on the HA peer just at the moment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can confirm that 'spanning tree portfast' is set on the switch ports we are connecting to our PA2020s, so the denied FTP packets remain a mystery :smileyconfused:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Feb 2011 08:27:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-would-i-see-traffic-on-a-standby-ha-pa2020/m-p/10397#M7659</guid>
      <dc:creator>LCMember3410</dc:creator>
      <dc:date>2011-02-21T08:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: why would i see traffic on a standby HA PA2020?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-would-i-see-traffic-on-a-standby-ha-pa2020/m-p/10398#M7660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure what could be causing this.&amp;nbsp; It might be a good idea to open a Support case, but I don't see any reason why the Palo Alto firewall would be causing this.&amp;nbsp; My hunch is something upstream.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Feb 2011 22:17:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-would-i-see-traffic-on-a-standby-ha-pa2020/m-p/10398#M7660</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-02-21T22:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: why would i see traffic on a standby HA PA2020?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-would-i-see-traffic-on-a-standby-ha-pa2020/m-p/10399#M7661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there is a known issue on the HA feature. We have the same issue. At the moment, it's not fixed with release3.1.7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Feb 2011 13:12:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-would-i-see-traffic-on-a-standby-ha-pa2020/m-p/10399#M7661</guid>
      <dc:creator>bdaussin</dc:creator>
      <dc:date>2011-02-22T13:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: why would i see traffic on a standby HA PA2020?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-would-i-see-traffic-on-a-standby-ha-pa2020/m-p/10400#M7662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks for your reply bdaussin - do you know if the issue is documented anywhere on this site? I have set the passive box's interfaces to shutdown for now, as this seems to be the only way to be sure of no misdirected traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Feb 2011 10:27:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-would-i-see-traffic-on-a-standby-ha-pa2020/m-p/10400#M7662</guid>
      <dc:creator>LCMember3410</dc:creator>
      <dc:date>2011-02-23T10:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: why would i see traffic on a standby HA PA2020?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-would-i-see-traffic-on-a-standby-ha-pa2020/m-p/10401#M7663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;﻿&lt;BR /&gt;??&amp;nbsp; How about the other end switch, shouldn’t it be expecting BPDUS and put it in blocking state. Do you have any commands and documents layer 2 traffic and operations on PA and also HA link states If passing all bpdu without processing - Is it also applicable for BPDUs from un-trusted side? Thanks ﻿&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Aug 2011 02:59:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-would-i-see-traffic-on-a-standby-ha-pa2020/m-p/10401#M7663</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-08-17T02:59:05Z</dc:date>
    </item>
  </channel>
</rss>

