<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Internet Outage Occurs After Migration - All Packets Aging-out in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340073#M85370</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am working on a Palo Alto Networks Firewall migration project. I exported and imported the configuration with a few errors that I fixed and when migrating from the old to the new PA-3220 firewalls. All internal communications wtih LDAP and other servers are working and the routing protocols are coming up internally and externally. I can also ping the default gateway of ISP from the outside interface of the new Firewall, but the internet is totally down. I checked the traffic under monitor and found that all the packets are aging-out although they are all allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do have default gateway setup and a default route towards the gateway, I checked the arp and routing table looks fine. What is the issue? anybody please?&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jul 2020 16:11:59 GMT</pubDate>
    <dc:creator>PAN-Bariz2020</dc:creator>
    <dc:date>2020-07-22T16:11:59Z</dc:date>
    <item>
      <title>Internet Outage Occurs After Migration - All Packets Aging-out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340073#M85370</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am working on a Palo Alto Networks Firewall migration project. I exported and imported the configuration with a few errors that I fixed and when migrating from the old to the new PA-3220 firewalls. All internal communications wtih LDAP and other servers are working and the routing protocols are coming up internally and externally. I can also ping the default gateway of ISP from the outside interface of the new Firewall, but the internet is totally down. I checked the traffic under monitor and found that all the packets are aging-out although they are all allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do have default gateway setup and a default route towards the gateway, I checked the arp and routing table looks fine. What is the issue? anybody please?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 16:11:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340073#M85370</guid>
      <dc:creator>PAN-Bariz2020</dc:creator>
      <dc:date>2020-07-22T16:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Outage Occurs After Migration - All Packets Aging-out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340080#M85373</link>
      <description>&lt;P&gt;Did you check your Source NAT policy to make sure that the packets are getting the correct Public IP Address before hitting the Internet?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 16:25:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340080#M85373</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2020-07-22T16:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Outage Occurs After Migration - All Packets Aging-out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340088#M85375</link>
      <description>&lt;P&gt;Yes! Security Policy and NAT rules are working according to the monitor tab. I see packet send but 0 on the packets received.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 16:45:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340088#M85375</guid>
      <dc:creator>PAN-Bariz2020</dc:creator>
      <dc:date>2020-07-22T16:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Outage Occurs After Migration - All Packets Aging-out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340425#M85444</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Hopefully you have this corrected already. However unplug the external interface for a few minutes to see if the ISP can clear their ARP. Or just call them and see if they see traffic and it they can clear the arp tables.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 22:00:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340425#M85444</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-07-23T22:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Outage Occurs After Migration - All Packets Aging-out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340426#M85445</link>
      <description>&lt;P&gt;I did [show arp all] and found the ISP router gateway ip address has a proper arp cache. I also did a traceroute, but found a couple of hopes after the gateway is not being properly resolved, instead of IP address there was *** which indicates arp cache issue at that nodes. It is still not solved, i am following that closely.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 22:04:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340426#M85445</guid>
      <dc:creator>PAN-Bariz2020</dc:creator>
      <dc:date>2020-07-23T22:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Outage Occurs After Migration - All Packets Aging-out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340522#M85457</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/148301"&gt;@PAN-Bariz2020&lt;/a&gt;Check under Source NAT rule if translation type is selected as &lt;STRONG&gt;Dynamic IP And Port &lt;/STRONG&gt;but not Dynamic IP only. This will create issue if other option is selected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2020 14:20:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340522#M85457</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-07-24T14:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Outage Occurs After Migration - All Packets Aging-out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340530#M85460</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Dynamic IP And Port&lt;/STRONG&gt; is selection, some of them also have bi-directional option checked.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2020 15:31:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340530#M85460</guid>
      <dc:creator>PAN-Bariz2020</dc:creator>
      <dc:date>2020-07-24T15:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Outage Occurs After Migration - All Packets Aging-out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340740#M85491</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/148301"&gt;@PAN-Bariz2020&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1&amp;gt;Did&amp;nbsp; you check the traffic logs that traffic is getting natted to public IP address ?&lt;/P&gt;
&lt;P&gt;2&amp;gt;You do not need bi directional option checked if you are only allowing users to access the Internet using Outside Interface IP.&lt;/P&gt;
&lt;P&gt;3&amp;gt;Also check which rule it hits when you can successfully ping and compare it with non working security rule.&lt;/P&gt;
&lt;P&gt;4&amp;gt;Use the test nat command&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;test nat-policy-match protocol 6 from L3-Trust to L3-Untrust source ip&amp;nbsp; destination ip&amp;nbsp; destination-port 443&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 00:10:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/340740#M85491</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-27T00:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Outage Occurs After Migration - All Packets Aging-out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/341511#M85661</link>
      <description>&lt;P&gt;Thank You.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had performed those steps on the first failure and did not found any issue. I believe there might be a VRF issue from the ISP site. I will be able to get back on this next week.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 20:07:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/341511#M85661</guid>
      <dc:creator>PAN-Bariz2020</dc:creator>
      <dc:date>2020-07-30T20:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Outage Occurs After Migration - All Packets Aging-out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/341521#M85663</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/148301"&gt;@PAN-Bariz2020&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the update.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 21:25:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/341521#M85663</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-30T21:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Outage Occurs After Migration - All Packets Aging-out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/342116#M85778</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;It was nothing but ARP cache from the Service Provider side, There was another switch between the Palo Alto Networks Firewall and ISP router. The ARP cache that i was getting on the firewall was from the switch not from the actual ISP router. The issue immediately got fixed upon ARP cache clear.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 00:14:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-outage-occurs-after-migration-all-packets-aging-out/m-p/342116#M85778</guid>
      <dc:creator>PAN-Bariz2020</dc:creator>
      <dc:date>2020-08-05T00:14:27Z</dc:date>
    </item>
  </channel>
</rss>

