- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-14-2016 05:33 AM
Hello
I have scenario like firewall is connected to two routers R1 and R2 through eth1/1 and eth1/2 interfaces respectively. From firewall, traffic is going through R1 via eth1/1 interface and return traffic is coming through R2 via eth1/2.
This is asymmetric routing and firewall tcp syn check will fail. My question is that Palo Alto firewall check tcp syn and asymmtric routing based on interface or zone? I mean if both eth1/1 and eth1/2 have same zone then this will not fail tcp syn checking?
Regards,
GR
10-16-2016 02:40 PM
PA session match is based on zone not on interface. So you are correct that if you put both interfaces into the same zone you can still achieve session match and not drop the traffic.
You can see the details of the packet inspection process in this document.
https://live.paloaltonetworks.com/t5/Learning-Articles/Packet-Flow-Sequence-in-PAN-OS/ta-p/56081
10-14-2016 07:05 AM
Hi,
In the ZONE Protection profile (TCP Drop), select Bypass for Asymmetric Path.
Regards,
HA
10-16-2016 04:53 AM
Hi
Thanks for the reply. Just want to know if I put both outoing interfaces interfaces in same zone then firewall will not drop asymmetric traffic?
10-16-2016 02:40 PM
PA session match is based on zone not on interface. So you are correct that if you put both interfaces into the same zone you can still achieve session match and not drop the traffic.
You can see the details of the packet inspection process in this document.
https://live.paloaltonetworks.com/t5/Learning-Articles/Packet-Flow-Sequence-in-PAN-OS/ta-p/56081
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!