<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trouble routing VXLAN traffic as it enters the outside interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-vxlan-traffic-as-it-enters-the-outside-interface/m-p/376846#M89339</link>
    <description>&lt;P&gt;That is helpful, thank you. I am beginning to think that this is an issue on the Fortigate side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Although the strange thing is that it looks like the packets are emerging from the Fortigate side "in tact" and the Palo is just dropping them. Here is an example ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a test phone that I put a static IP onto, 10.50.80.10. It's on VLAN 580. Then I have a phone server on the Palo Alto side, 10.10.70.10. I ran a packet trace on the Palo, filtering for the phone IP. It seems that the packets are assembled with the correct VLAN and the correct VXLAN VNI of 1001. But they are dropped, and as noted the Tunnel Inspection is not being performed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a case open with support - but not getting any feedback after the first 24 hours. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="droppppped.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29354i51318447CF22156D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="droppppped.png" alt="droppppped.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 31 Dec 2020 13:27:56 GMT</pubDate>
    <dc:creator>SteveBallantyne</dc:creator>
    <dc:date>2020-12-31T13:27:56Z</dc:date>
    <item>
      <title>Trouble routing VXLAN traffic as it enters the outside interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-vxlan-traffic-as-it-enters-the-outside-interface/m-p/376767#M89330</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;&lt;P&gt;I am attempting to create a VXLAN over IPSec solution between my PA-3250 and a remote Fortinet FortiGate 61E. I have managed to get things configured correctly on the FortiGate (I think) as I am seeing the traffic entering on the Palo side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using Tunnel Inspection on the Palo side and it appears to be set up correctly. In the Monitor &amp;gt; Tunnel Inspection on the Palo, the traffic can be seen there. Even though when I click the magnifier to take a deeper look on the flow the "Tunnel Inspection" checkbox is NOT checked, which seems strange to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a security rule for phone traffic and I am seeing that traffic pop into my standard Palo Monitor &amp;gt; Traffic &amp;gt; Logs. But the applications are all coming up "Incomplete". I am also not able to ping back and forth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it appears everything works - with the exception of the routing. And I am not sure how to fix that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone here done multiple VLAN's over a VNI using VXLAN over IPSec? If so - how did you get your traffic to *route* correctly?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 19:33:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-vxlan-traffic-as-it-enters-the-outside-interface/m-p/376767#M89330</guid>
      <dc:creator>SteveBallantyne</dc:creator>
      <dc:date>2020-12-30T19:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble routing VXLAN traffic as it enters the outside interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-vxlan-traffic-as-it-enters-the-outside-interface/m-p/376828#M89335</link>
      <description>&lt;P&gt;you should focus on establishing vxlan connectivity before looking into tunnel inspection&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;your sessions coming up as 'incomplete' means the vxlan 'tunnel' (VTEP) is not being set up properly between your local and remote switch, which makes tunnel inspection impossible&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you're not able to ping: make sure routing is set up properly into the ipsec tunnel interface for the remote subnet&lt;/P&gt;&lt;P&gt;then make sure security rules are set from your local zone to the tunnel zone, and vice versa, as needed (to the firewall vxlan/VTEP are UDP packets flowing back and forth over the ipsec tunnel)&lt;/P&gt;&lt;P&gt;once basic connectivity is verified, make sure both ends are able to establish the vxlan/VTEP connectivity&lt;/P&gt;&lt;P&gt;once that is established look into setting up tunnel inspection&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Dec 2020 08:33:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-vxlan-traffic-as-it-enters-the-outside-interface/m-p/376828#M89335</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-12-31T08:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble routing VXLAN traffic as it enters the outside interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-vxlan-traffic-as-it-enters-the-outside-interface/m-p/376846#M89339</link>
      <description>&lt;P&gt;That is helpful, thank you. I am beginning to think that this is an issue on the Fortigate side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Although the strange thing is that it looks like the packets are emerging from the Fortigate side "in tact" and the Palo is just dropping them. Here is an example ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a test phone that I put a static IP onto, 10.50.80.10. It's on VLAN 580. Then I have a phone server on the Palo Alto side, 10.10.70.10. I ran a packet trace on the Palo, filtering for the phone IP. It seems that the packets are assembled with the correct VLAN and the correct VXLAN VNI of 1001. But they are dropped, and as noted the Tunnel Inspection is not being performed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a case open with support - but not getting any feedback after the first 24 hours. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="droppppped.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29354i51318447CF22156D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="droppppped.png" alt="droppppped.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Dec 2020 13:27:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-vxlan-traffic-as-it-enters-the-outside-interface/m-p/376846#M89339</guid>
      <dc:creator>SteveBallantyne</dc:creator>
      <dc:date>2020-12-31T13:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble routing VXLAN traffic as it enters the outside interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-vxlan-traffic-as-it-enters-the-outside-interface/m-p/376851#M89341</link>
      <description>&lt;P&gt;I just got off of a Zoom session with PA support. They did some further digging into the session flows via the CLI and came to the conclusion that my packets are coming into the Palo, but the return path is broken on the FortiGate side of things.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the session is never fully establishing (no ACK), the tunnel inspection is not kicking into gear. That is, the *intent* to inspect is there, but the conversation is one-way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have already engaged FortiNet support - now it's a waiting game. I will share some information and configuration examples if we can ever sort this out, as I couldn't find a lot of useful documentation on their side. And I know there are many customers out there with Palo's in the main office, and "baby firewalls" at their remote sites.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Dec 2020 15:43:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-routing-vxlan-traffic-as-it-enters-the-outside-interface/m-p/376851#M89341</guid>
      <dc:creator>SteveBallantyne</dc:creator>
      <dc:date>2020-12-31T15:43:42Z</dc:date>
    </item>
  </channel>
</rss>

