<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: an issue occure with asymmetric route in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/an-issue-occure-with-asymmetric-route/m-p/310483#M80393</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132748"&gt;@black1983&lt;/a&gt;Hi, can you please check if traffic coming on public IP of ISP3 is coming on correct interface of firewall and doing proper NAT ?&lt;/P&gt;&lt;P&gt;Please check same using test security-policy and test NAT commands through cli.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2020 02:26:24 GMT</pubDate>
    <dc:creator>SutareMayur</dc:creator>
    <dc:date>2020-02-11T02:26:24Z</dc:date>
    <item>
      <title>an issue occure with asymmetric route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/an-issue-occure-with-asymmetric-route/m-p/310377#M80366</link>
      <description>&lt;P&gt;HI;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have PaloAlto FW and I have 3 ISPs and I'm using default route ( statically ) with this value ISP1 distance 5 ( Interface X), ISP2 distance 9 and ISP3 distance 15 ( Interface Y) and I've server with NAT IP using ISP3 subnet.&lt;/P&gt;&lt;P&gt;the server is reachable from global internet but the users who are using ISP3 they are unable to reach it after some tshoot we have done using trace route we found the following.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is the issue ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NOTE:&lt;/P&gt;&lt;P&gt;we cant apply the following&lt;/P&gt;&lt;P&gt;1- PBF&lt;/P&gt;&lt;P&gt;2- we can't update route table statically for each user&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trace route from NATed server using ISP3 subnet toward user using ISP3 :&lt;/P&gt;&lt;P&gt;Server --&amp;gt; Palo Alto outside interface(X)--&amp;gt; ISP1 --&amp;gt;ISP3--&amp;gt; ISP3 USER&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trace route from&amp;nbsp;user using ISP3&amp;nbsp; toward NATed server using ISP3 subnet :&lt;/P&gt;&lt;P&gt;USER--&amp;gt;ISP3 --&amp;gt; WAN Router--&amp;gt; Palo Alto outside interface(Y)--&amp;gt; drop&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trace route from NATed server using ISP3 subnet toward global Internet :&lt;/P&gt;&lt;P&gt;Server --&amp;gt; Palo Alto outside interface(X)--&amp;gt; ISP1 --&amp;gt; Global Internet --&amp;gt; 8.8.8.8 (example)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trace route from global user&amp;nbsp; toward NATed server using ISP3:&lt;/P&gt;&lt;P&gt;Global User --&amp;gt; Global Internet --&amp;gt; ISP3--&amp;gt; reach to NATed server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 11:58:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/an-issue-occure-with-asymmetric-route/m-p/310377#M80366</guid>
      <dc:creator>black1983</dc:creator>
      <dc:date>2020-02-10T11:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: an issue occure with asymmetric route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/an-issue-occure-with-asymmetric-route/m-p/310483#M80393</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132748"&gt;@black1983&lt;/a&gt;Hi, can you please check if traffic coming on public IP of ISP3 is coming on correct interface of firewall and doing proper NAT ?&lt;/P&gt;&lt;P&gt;Please check same using test security-policy and test NAT commands through cli.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 02:26:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/an-issue-occure-with-asymmetric-route/m-p/310483#M80393</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-11T02:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: an issue occure with asymmetric route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/an-issue-occure-with-asymmetric-route/m-p/310579#M80422</link>
      <description>&lt;P&gt;yes the incoming traffic comes thru correct interface&amp;nbsp; (Y) whatever the source is local ISP3 or Global internet users but the different is global users thy can browse it and their traffic goes out thru ISP1 interface (X) ( asymmetrically ) !! and ISP3 users can't browse it since the FW is dropping the packet ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, why do global users can browse it with asymmetric routes while local ISP3 users can't do it ?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 11:16:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/an-issue-occure-with-asymmetric-route/m-p/310579#M80422</guid>
      <dc:creator>black1983</dc:creator>
      <dc:date>2020-02-11T11:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: an issue occure with asymmetric route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/an-issue-occure-with-asymmetric-route/m-p/310621#M80440</link>
      <description>&lt;P&gt;Can you explain what you mean by different distance for each route? Do you mean administrative distance?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 15:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/an-issue-occure-with-asymmetric-route/m-p/310621#M80440</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2020-02-11T15:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: an issue occure with asymmetric route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/an-issue-occure-with-asymmetric-route/m-p/310695#M80451</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132748"&gt;@black1983&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible for your to explain it with the help of diagram ? Wanted to understand topology properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Mayur&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 03:06:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/an-issue-occure-with-asymmetric-route/m-p/310695#M80451</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-12T03:06:26Z</dc:date>
    </item>
  </channel>
</rss>

