<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Symmetric return with ECMP not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/symmetric-return-with-ecmp-not-working/m-p/387540#M90391</link>
    <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139715"&gt;@VarunRao&lt;/a&gt;&lt;BR /&gt;For more information. See&lt;BR /&gt;1. How to Configure Symmetric Return - &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF5CAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF5CAK&lt;/A&gt;&lt;BR /&gt;2. How to Implement ECMP - &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF8CAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF8CAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Dec 2021 00:23:47 GMT</pubDate>
    <dc:creator>domtack</dc:creator>
    <dc:date>2021-12-02T00:23:47Z</dc:date>
    <item>
      <title>Symmetric return with ECMP not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/symmetric-return-with-ecmp-not-working/m-p/387511#M90387</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have dual ISP setup, and to load-balance the traffic we are using ECMP with static routes, and it works fine for the internet bound connections and traffic gets load-balanced.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We however face issues with connection to our VPN servers in the DMZ. They are used by remote users to create a RA-VPN tunnel with the VPN servers from internet. The users have to try atleast 4-5 times before they get a successful connection with the VPN servers. We suspect it is because the VPN server have a public IP published on internet, which is a ISP2 public range. The return packet is getting load balanced too , towards ISP1 and cause assymmetric routing and ISP2 doesnt like it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to ensure the return packet goes through ISP2 only? We ahve tried PBF but doesnt seem to work. We ahve also enabled symmetric return option in ECMP, and confused why it doesn't seem to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a TAC case open, but no engineer has any idea or shown any willingness to go deeper.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the topology.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VarunRao_0-1614133551857.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30037i9A73AB37AC5F2A31/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="VarunRao_0-1614133551857.png" alt="VarunRao_0-1614133551857.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 02:26:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/symmetric-return-with-ecmp-not-working/m-p/387511#M90387</guid>
      <dc:creator>VarunRao</dc:creator>
      <dc:date>2021-02-24T02:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: Symmetric return with ECMP not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/symmetric-return-with-ecmp-not-working/m-p/387530#M90390</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139715"&gt;@VarunRao&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Do you actually have logs showing return traffic is attempting to route via ISP1 instead of ISP2 with symmetric return enabled? If so, then that's all TAC should need to actually start digging into the issue and making sure you have it configured correctly, that it's being identified as server to client return traffic, ect. Usually issues like this is because it's not being identified as server to client traffic properly like it should, or that it's simply been misconfigured.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also just to throw it out there, have you checked the release notes for 9.1 and verified that you aren't hitting any of the ECMP issues addressed in later releases? I know that there's been a few addressed issues in later builds related to ECMP, and 9.1.3 is pretty early in the 9.1 release.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 04:45:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/symmetric-return-with-ecmp-not-working/m-p/387530#M90390</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-02-24T04:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: Symmetric return with ECMP not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/symmetric-return-with-ecmp-not-working/m-p/387540#M90391</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139715"&gt;@VarunRao&lt;/a&gt;&lt;BR /&gt;For more information. See&lt;BR /&gt;1. How to Configure Symmetric Return - &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF5CAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF5CAK&lt;/A&gt;&lt;BR /&gt;2. How to Implement ECMP - &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF8CAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF8CAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 00:23:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/symmetric-return-with-ecmp-not-working/m-p/387540#M90391</guid>
      <dc:creator>domtack</dc:creator>
      <dc:date>2021-12-02T00:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: Symmetric return with ECMP not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/symmetric-return-with-ecmp-not-working/m-p/387660#M90405</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The configuration for ECMP was all fine and TAC did take captures, where we did see issues caused by ecmp, it tried to sdn reply packets through the load-balancing. TAC although doesn't know why it is happening. Still under investigation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using version 9.0.11.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 22:30:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/symmetric-return-with-ecmp-not-working/m-p/387660#M90405</guid>
      <dc:creator>VarunRao</dc:creator>
      <dc:date>2021-02-24T22:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Symmetric return with ECMP not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/symmetric-return-with-ecmp-not-working/m-p/449086#M100894</link>
      <description>&lt;P&gt;The configuration for ECMP was all fine and TAC did take captures, where we did see issues caused by ecmp, it tried to sdn reply packets through the load-balancing. TAC although doesn't know why it is happening. Still under investigation&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are using version 9.0.11.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 00:22:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/symmetric-return-with-ecmp-not-working/m-p/449086#M100894</guid>
      <dc:creator>ciana_lenevy</dc:creator>
      <dc:date>2021-12-02T00:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: Symmetric return with ECMP not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/symmetric-return-with-ecmp-not-working/m-p/540263#M110826</link>
      <description>&lt;P&gt;Hi there. Was there ever a resolution to this? We are seeing this behavior with many applications, especially ones that are setting cookies. Some vendors we had to inform of the 2nd ISP subnet range to make sure that traffic is being allowed. Please let me know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 23:21:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/symmetric-return-with-ecmp-not-working/m-p/540263#M110826</guid>
      <dc:creator>BradBieth</dc:creator>
      <dc:date>2023-04-26T23:21:16Z</dc:date>
    </item>
  </channel>
</rss>

