I have opened this with TAC a while ago but I continue having issues with Layer 3 not passing through the untrust/internet interface at random times. I have had this happen 5 to 10 times on different PA-200's. Some have repeated. I was hoping a firmware upgrade to 6.1.3 would finally fix this but yesterday one of my first 6.1.3 units locked up. Layer 2 is fine. I look in my router and the ARP entry for the PAN is in there. I clear ARP table and it repopulates with MAC/IP as the PAN responds correctly.
Rebooting the router doesn't do anything for the PAN to pass Layer 3 again. The only way to get PAN to pass Layer 3 again is a reboot of the PAN itself. We are running LSVPN on all spoke sites for VPN and the only curveball is that my hubs are on older 6.0.5h3 code. Just throwing this out there for discussion in case others have seen it.
I don't have a real solution, but you could try just restarting the routing service instead of the entire PAN device.
>debug routing restart
>debug software restart routed
panos - We have upgrades to 6.1.3 scheduled for this week. Are there any particular fixes in there that would address what I am seeing? I am also working on applying 6.1.3 to all spokes as well. 6.1.2 is not very stable for us. I guess I want to make sure we're not just throwing spaghetti at the wall just because we have a pot of it. I will try anything but if there are some known issues addressed, I'd like to know.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!