emails stop working

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

emails stop working

L1 Bithead

hi all, i recently replace my palo alto 820 with new model 440, all is working fine however my emails from inside to outside stop working. my emails are on seperate zone on the dmz and i have barracuda. there is a nat policy.

however when i set back the old one everything works properly.

Does anyone have an idea about what is causing the issue

 

7 REPLIES 7

Cyber Elite
Cyber Elite

Is this for emails coming from the Palo itself or from clients that is no longer working? Assuming we're referring to the Palo, are both models running the same PAN-OS versions? Also verify that the service route for email is still the same from the old one to the new one. If you use a relay of some kind you may need to add the specific IP address so may be easier to have the same mgmt IP on the new one.

 

Assuming you're referring to emails from users, are you using the same device groups and templates (assuming managed by Panorama) on the new device as you were the old? 

i am talking to the emails from users, and concerning the configuration it is the same one i have imported the same configuration to the new palo alto. i didn't change anything

Cyber Elite
Cyber Elite

Do you see the traffic in the monitor logs? Whether allowed or denied. 

yes it is allowed, but the reason of end is incomplete or aged out

Cyber Elite
Cyber Elite

You may need to do some additional testing live and check the global counters to see if any specific reason is thrown. How to check global counters for a specific source and destinat... - Knowledge Base - Palo Alto Netw...

 

I would also verify that the NAT rules and routing (whether dynamic or static) are still identical between the two as you may not be sending it to the right place or translating it to the correct IP.  

Cyber Elite
Cyber Elite

Hello,

My guess is that there is a missing or misconfiguration in one of the following: Virtual router, security policy, NAT policy.

 

Regards,

L1 Bithead

I would still check the App ID versions - there have been some changes in the exchange traffic (of course, if these App IDs are different on the older and newer PN).

Greetings
  • 2204 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!