<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto Stopped taking New Policy Traffic. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409754#M92492</link>
    <description>&lt;P&gt;Tired the &amp;lt;commit force&amp;gt; still the problem is same.&lt;/P&gt;</description>
    <pubDate>Fri, 28 May 2021 02:40:42 GMT</pubDate>
    <dc:creator>AmardeepSuri</dc:creator>
    <dc:date>2021-05-28T02:40:42Z</dc:date>
    <item>
      <title>Palo Alto Stopped taking New Policy Traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409435#M92447</link>
      <description>&lt;P&gt;We recently upgraded the Palo Alto version to 9.1.7 on our physical hardware 3200 series. After 02 days we notice that before upgrade all policy rules and NAT works fine. However, The NAT and policy which we created after the upgrade not working. Not traffic or hit shows in monitoring.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We rebooted the PA once still is not fixed. Is it a bug in the current version.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 07:35:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409435#M92447</guid>
      <dc:creator>AmardeepSuri</dc:creator>
      <dc:date>2021-05-27T07:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Stopped taking New Policy Traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409457#M92450</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/182926"&gt;@AmardeepSuri&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's not a lot of info in your post to help you on your way.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is traffic reaching your firewall correctly ? Is it dropped before actually getting logged (check drop counters) ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not aware of a bug describing your issue.&lt;/P&gt;
&lt;P&gt;While PAN-OS 9.1.7 seems fine, know that 9.1.8 is the recommended release at the time of this writing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 27 May 2021 08:40:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409457#M92450</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2021-05-27T08:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Stopped taking New Policy Traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409467#M92453</link>
      <description>&lt;P&gt;Hi, Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I observed packet drop increasing frequently.&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-05-27 142446.jpg" style="width: 659px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34106i8712C7AC4618E40C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-05-27 142446.jpg" alt="Screenshot 2021-05-27 142446.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 08:55:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409467#M92453</guid>
      <dc:creator>AmardeepSuri</dc:creator>
      <dc:date>2021-05-27T08:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Stopped taking New Policy Traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409504#M92455</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/182926"&gt;@AmardeepSuri&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please make sure that the traffic you're investigating is actually reaching your firewall correctly (on the correct interface, etc...).&amp;nbsp; You can confirm this with packet captures (&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you've confirmed that, create a packet filter based on the traffic you're investigating and check the global counter for specific drop counters.&amp;nbsp; If there are any then it's likely they'll give you an indication of why it's being dropped.&lt;/P&gt;
&lt;P&gt;Check out the following KB on how to check for global counters.&amp;nbsp; There's even a use-case example that shows you how to check the drop counters specifically:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 27 May 2021 09:51:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409504#M92455</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2021-05-27T09:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Stopped taking New Policy Traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409557#M92464</link>
      <description>&lt;P&gt;Thanks!,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried packet capture earlier also using all 4 capturing options (drop, receive, transmit, and firewall ). and I enabled pre-match also. But that only showing me drop packet with only mac information no matching IP defined in filters.&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 11:14:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409557#M92464</guid>
      <dc:creator>AmardeepSuri</dc:creator>
      <dc:date>2021-05-27T11:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Stopped taking New Policy Traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409560#M92466</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/182926"&gt;@AmardeepSuri&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;packets dropped on the interface may not reach the dataplane (where packetcaptures are performed)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;disabling pre-parse will effectively cancel out filters as packets are captured before they are parsed (to filter). The drop packets you are seeing may be the mac frames you see in drop stage, are they 'normal' (no malformation?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you may be distracted from your original issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;since NAT does not appear to work, did you make sure the new NAT rules are in the proper order for them to match? rules are evaluated top to bottom with the first positive match being used. this could mean rules further down the rulebase are not hit as a preceding rule is too generic and you will need to reorder your rules&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can check if your rules exist on the dataplane by using the following command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show running nat-rules&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then see if the new rules exist or not&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 11:37:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409560#M92466</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-05-27T11:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Stopped taking New Policy Traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409673#M92476</link>
      <description>&lt;P&gt;Thanks, Reaper.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you suggested the checked the newly created NAT rule. However, I found that in the NAT rules list.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The command you shared not worked. But I tried with &amp;lt;show running nat-rule-ippool rule "Bi-Nat Rule 12-1"&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I would like to update not only the newly created NAT is not working. even an existing policy that allowing traffic from a specific source also not working when we added a new source in that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 17:29:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409673#M92476</guid>
      <dc:creator>AmardeepSuri</dc:creator>
      <dc:date>2021-05-27T17:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Stopped taking New Policy Traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409707#M92482</link>
      <description>&lt;P&gt;In some cases saving a snapshot of the config, a fast factory default reset and again loading the config resolves such issues. If your firewall i in HA this is a thing that the TAC does many times&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before that check for commit errors:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMb2CAG" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMb2CAG&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 19:41:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409707#M92482</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-05-27T19:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Stopped taking New Policy Traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409709#M92484</link>
      <description>&lt;P&gt;Apologies, the correct command is&amp;nbsp;&lt;/P&gt;&lt;P&gt;Show running nat-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try the following:&lt;/P&gt;&lt;P&gt;&amp;gt; Configure&lt;/P&gt;&lt;P&gt;# commit force&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 19:50:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409709#M92484</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-05-27T19:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Stopped taking New Policy Traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409754#M92492</link>
      <description>&lt;P&gt;Tired the &amp;lt;commit force&amp;gt; still the problem is same.&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 02:40:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-stopped-taking-new-policy-traffic/m-p/409754#M92492</guid>
      <dc:creator>AmardeepSuri</dc:creator>
      <dc:date>2021-05-28T02:40:42Z</dc:date>
    </item>
  </channel>
</rss>

