Firewall PA doesn't process network traffic.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Firewall PA doesn't process network traffic.

L0 Member

Hi everyone! First, sorry 'cause my English is not good.

My issue don't let me sleep. My firewall (PA-3410 v11.0.0-h1) doesn't process traffic, I can't do ping at other interface than MGMT. The Monitor is clear!.

MiguelAndrade_0-1712612607211.png

The only thing I have observed is that the traffic reaches the MAC interface, but the CPU counter does not increase.

MiguelAndrade_1-1712612767047.png

After a few minutes sending ICMP and HTTPS traffic, it shows this:

MiguelAndrade_2-1712612913428.png

Any idea?

3 REPLIES 3

Cyber Elite
Cyber Elite

@Miguel-Andrade,

Do you have an interface management profile that would allow you to ping interfaces? By default, the firewall isn't going to have ICMP active on an interface address. Likewise the intrazone-default policy doesn't have logging enabled by default (nor does the interzone-default policy), so you may simply not be passing any traffic that would actually be logged. Without knowing how you've configured your security rulebase it's impossible to know if that's a real issue or not.

 

 

Yes I do.

MiguelAndrade_0-1712613806214.png

Inter-zone traffic doesn't show it. Logs at the policy are enable. It's not the first time it's happened to me, I still haven't solved the previous case.

MiguelAndrade_0-1712614170895.png

 

L6 Presenter

Is there a reason why you're running PAN-OS version 11.0.X?  If there's not a specific feature that's in 11.0.X and you can run 10.2.X my suggestion would be downgrade to 10.2.7hx or 10.2.8.  If you need to run 11.0, I would run the latest preferred version of 11.0.  Especially with the new 3400 platform I've ran into a bunch of weird issues.

  • 828 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!