I’m facing an issue with L3 int which is configured on Palo Alto firewall

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

I’m facing an issue with L3 int which is configured on Palo Alto firewall

L1 Bithead

Hi Team,

I’m encountering an issue with Poly devices on VLAN 20, which is routed through the firewall with its L3 interface configured. The devices successfully pair at first time with Teams but  after a reboot they fail to maintain pairing afterward, despite having a rule that allows all traffic from the VLAN 20 .

 

Interestingly, when these devices are moved to VLAN 10 (behind the core), they work without any issues.

Note: They are not losing any Hardware connectivity and working fine on same port with Vlan 10 which is behind the core switch 

 

Has anyone faced a similar issue or have any recommendations? Your input would be greatly appreciated.

5 REPLIES 5

L6 Presenter

@Hassan958 wrote:

Hi Team,

I’m encountering an issue with Poly devices on VLAN 20, which is routed through the firewall with its L3 interface configured. The devices successfully pair at first time with Teams but  after a reboot they fail to maintain pairing afterward, despite having a rule that allows all traffic from the VLAN 20 .

 

Interestingly, when these devices are moved to VLAN 10 (behind the core), they work without any issues.

Note: They are not losing any Hardware connectivity and working fine on same port with Vlan 10 which is behind the core switch 

 

Has anyone faced a similar issue or have any recommendations? Your input would be greatly appreciated.


What do the traffic logs show for traffic on this VLAN?

Cyber Elite
Cyber Elite

Hello,

Check the unified logs to see what is getting blocked.

 

Regards,

I can see traffic from that VLAN, and everything is set to allow only.

No deny logs so far

Cyber Elite
Cyber Elite

Hello,

Since its Teams, check your outbound policies to make sure that all traffic is allowed to O365. I use External Dynamic Lists in my policies to make this more dynamic for me. Just make sure to choose the correct lists.

OtakarKlier_0-1735323930316.png

https://saasedl.paloaltonetworks.com/feeds/

 

Regards,

  • 275 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!