<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic UDP issues after network outage in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/udp-issues-after-network-outage/m-p/293497#M77584</link>
    <description>&lt;P&gt;We're experiencing multiple issues with udp-based applications after network outages. A common problem is that udp tracking sessions (I assume from ALG) in PA for DHCP create issues and clients are unable to attain IP-address. This error must be manually solved by clearing sessions. We've also seen this error for other udp applications.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question is: Are the configuration steps we can take to alleviate our problems with udp tracking sessions getting invalid in PA?&lt;/P&gt;</description>
    <pubDate>Mon, 21 Oct 2019 11:17:32 GMT</pubDate>
    <dc:creator>Trond.Olsen</dc:creator>
    <dc:date>2019-10-21T11:17:32Z</dc:date>
    <item>
      <title>UDP issues after network outage</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/udp-issues-after-network-outage/m-p/293497#M77584</link>
      <description>&lt;P&gt;We're experiencing multiple issues with udp-based applications after network outages. A common problem is that udp tracking sessions (I assume from ALG) in PA for DHCP create issues and clients are unable to attain IP-address. This error must be manually solved by clearing sessions. We've also seen this error for other udp applications.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question is: Are the configuration steps we can take to alleviate our problems with udp tracking sessions getting invalid in PA?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2019 11:17:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/udp-issues-after-network-outage/m-p/293497#M77584</guid>
      <dc:creator>Trond.Olsen</dc:creator>
      <dc:date>2019-10-21T11:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: UDP issues after network outage</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/udp-issues-after-network-outage/m-p/295290#M77808</link>
      <description>&lt;P&gt;Hello there&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not aware of an ALG for DHCP.&amp;nbsp;&amp;nbsp; UDP has a global time out of 30 secs, by default.&lt;/P&gt;&lt;P&gt;Here is a screen capture of what DHCP looks like on my FW.&lt;/P&gt;&lt;P&gt;Note the start time and receive time (receive time is when the log was received to the traffic log, which logs at session end)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="x-grid3-row  x-grid3-row-first "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Session ID&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;38741&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Action&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;allow&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Action Source&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;from-policy&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Application&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;dhcp&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Rule&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;Internal&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Rule UUID&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;6270e459-1170-4495-a10d-2822cd36b2f5&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Session End Reason&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;aged-out&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Category&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;any&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Device SN&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;IP Protocol&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;udp&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row  x-grid3-row-over"&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Log Action&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Generated Time&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;2019/10/30 15:00:02&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Start Time&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;2019/10/30 14:59:30&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Receive Time&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;2019/10/30 15:00:02&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Elapsed Time(sec)&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;0&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row  x-grid3-row-last "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Tunnel Type&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;N/A&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So unless someone has manipulated the global timers, or it is anomoly in the software, 30 secs is reasonable max time a UDP is maintained.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is different for SIP which has an ALG.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 21:31:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/udp-issues-after-network-outage/m-p/295290#M77808</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-10-30T21:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: UDP issues after network outage</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/udp-issues-after-network-outage/m-p/295361#M77821</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;In logs and sessions browser the dhcp sessions between ip gateways (remote locations) and dhcp servers are often long running, up to 1-2 weeks. So I'm pretty sure the dhcp application is dependent on more than the udp timeout. It seems unlikely that we should receive continuous dhcp relay traffic from the gateways.&lt;/P&gt;&lt;P&gt;Our config for dhcp application seems standard also:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clipboard_image_0.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22010i2B1EF16E652C635E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="clipboard_image_0.png" alt="clipboard_image_0.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also checked ou firewall timeouts which seems to be default:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Session timeout
TCP default timeout: 3600 secs
TCP session timeout before SYN-ACK received: 5 secs
TCP session timeout before 3-way handshaking: 10 secs
TCP half-closed session timeout: 120 secs
TCP session timeout in TIME_WAIT: 15 secs
TCP session delayed ack timeout: 250 millisecs
TCP session timeout for unverified RST: 30 secs
UDP default timeout: 30 secs
ICMP default timeout: 6 secs
SCTP default timeout: 3600 secs
SCTP timeout before INIT-ACK received: 5 secs
SCTP timeout before COOKIE received: 60 secs
SCTP timeout before SHUTDOWN received: 30 secs
other IP default timeout: 30 secs
Captive Portal session timeout: 30 secs
Session timeout in discard state:
  TCP: 90 secs, UDP: 60 secs, SCTP: 60 secs, other IP protocols: 60 secs&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Thu, 31 Oct 2019 09:16:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/udp-issues-after-network-outage/m-p/295361#M77821</guid>
      <dc:creator>Trond.Olsen</dc:creator>
      <dc:date>2019-10-31T09:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: UDP issues after network outage</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/udp-issues-after-network-outage/m-p/295501#M77839</link>
      <description>&lt;P&gt;Trond,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you show a screen capture showing a DHCP session that has been in your Session Browser for more than 2 minutes?&lt;/P&gt;&lt;P&gt;You may need to do a "show session ID xxxxx" from the CLI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not able to confirm your issue.&amp;nbsp; DHCP is just and only 4 UDP packet exchange.&lt;/P&gt;&lt;P&gt;When I go into my Session Browser and look for DHCP, I get none, meaning, I have zero sessions that are in the session table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But even when I look at a UDP session (DNS in my example), this is what I see&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;start time : Thu Oct 31 12:10:36 2019&lt;BR /&gt;timeout : 30 sec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we are missing some details... &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please advise.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 16:13:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/udp-issues-after-network-outage/m-p/295501#M77839</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-10-31T16:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: UDP issues after network outage</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/udp-issues-after-network-outage/m-p/295622#M77865</link>
      <description>&lt;P&gt;Here's an example of traffic currently in session today. These are all from gateways doing DHCP relay (IP information has been removed).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clipboard_image_0.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22021i6EB1BC4BB27C45A3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="clipboard_image_0.png" alt="clipboard_image_0.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2019 07:32:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/udp-issues-after-network-outage/m-p/295622#M77865</guid>
      <dc:creator>Trond.Olsen</dc:creator>
      <dc:date>2019-11-01T07:32:13Z</dc:date>
    </item>
  </channel>
</rss>

