Security Policy not HIT after work for 1 month

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Security Policy not HIT after work for 1 month

L1 Bithead

I got setup 6 AWS VPC with direct connect connection to on prem panorama, which is working fine for a month, and now suddently all 5 VPC disconnected from panorama in the same time.


i checked the BGP and IKE all established, i can ping the panorama IP, and make sure the right security policy with specific ssl and panorama application allowed.


my session browser showing it hit the clean up rule on the bottom, never hit my panorama-access rule.


anyone face this before?


my pcap showing re-transmission on DROP phase.



L1 Bithead

ok after a while, my senior advice me to put 1 specific rule with TCP 3978 and application is any, then my traffic start hit my OLD RULE.


super strange.


i can see my panorama session on my session browser now.


What does your old rule actually look like, and more specifically what was the specified applications and services? 

If I would have to take a guess right off hand, your existing rule that was working was only doing so because the session was already established over tcp/3978, and the rule you've specified is reliant on the traffic being seen as a particular application. Once that session dropped and the traffic had to go through and actually establish itself again, there was nothing that was actually allowing the traffic over 3978, and therefore the application was never identified and you hit your cleanup rule. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!