I am moving from PA3050 to PA3220. I did export the current configurations from the old PA3050 and imported to the new PA3220, i committed successfully, but when i migrate cables from old device to the new one i get random issue! like some zones are not reachable, like i have ping to internet and telnet and traceroute but i can't browse!, like i can't ping some destinations. WEIRD! its the SAME configuration and OS versions are the same on both devices plus, i did download and install latest content version on both devices before moving the exporting the config file.xml.
NOTE: when i move to old PA3050 all work properly!
One more thing, we have A10 (SSL Interception) connected to PA from external side and StormShield (AS core firewall).
REALLY WOULD APPRECIATE YOUR HELP.
Maybe asymmetric routing? Traffic like ping doesn't need a 3-way handshake to work through the PA but internet browsing would. Maybe the syn-ack isn't going through the PA?
Did anything else change when you moved to the new firewall?
Is there anything in the logs showing this traffic dropping?
Is there asymmetry in your network? There is a setting on the PA to bypass the dropping of traffic where the full handshake isn't seen. Was that set on the old firewall?
If you do 'show session info' ,there's a section for Session Setup that will tell you the current value of this setting. Default is True, meaning it will drop the traffic. If it's set to False, then the full handshake isn't needed to permit traffic.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!