- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.
01-01-2025 04:50 AM
Hello everyone , im seeing a very strange behaviour in my pa-445 version 11.1.4-h7 firewall , where i have an interface on the firewall which is a gateway to my voip devices , the same firewall connects to the voice server through an ipsec tunnel interface , so the traffic flow is like this , voice subnet to firewall and then from firewall to voice server through the tunnel , however on logs i see that the same voice subnet is entering the tunnel interface as "source" & with the "source zone" since its hitting this tunnel interface and ofcourse its denied since the allowed rule is from branch "voice zone" to "hq zone" , however im only seeing this for voice subnet and only on SIP application .
i would really appreciate any help & thanks
01-02-2025 03:22 PM
Hi @Esameldin ,
Just to confirm, are you saying that the SIP traffic from your voice subnet is being incorrectly processed as originating from an unintended zone, rather than the local voice zone? If possible, could you please share screenshots (with IPs blurred out) to help us further investigate the issue?
01-02-2025 08:37 PM
Hello @JayGolf ,
yes the traffic is actually generating from the supposed egress interface , its like sent packets are just coming back to the same interface it left , and on the HQ (destination) firewall i have no such logs so traffic is not being generated from HQ, please refer to the below screenshot
On the below screenshots you will find the ingress and egress interfaces , and also normal legal traffic , & the unusual traffic (as per the routing table when traffic is hitting the HQ interface its redirected back to HQ ) & so its denied by zone policy
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!