Symmetric return on L2 subinterface fails after some time

L0 Member

Symmetric return on L2 subinterface fails after some time

We are running the latest PanOS 8.1 version on a PA3050 and we want to make use of symmetric return. In general this is working just fine, but it seems we are triggering a corner case. We can successfully initiate an SSH session (i.e. key exchange, authentication etc. work like a charm), but after 4-5 characters on the prompt, the session freezes. So far we have found that the freeze is caused by VLAN tags not being present in the outgoing return packets.



Client behind Router connected to PA on ethernet1/2.410 wants to connect to server connected to PA on ethernet1/2.835.

Without PBF the client is in another VLAN directly connected to the same PA, but we have found that this doesn't matter. It does matter that the client is not directly connected to the same VLAN -- i.e. traffic originated by (also matching the PBF rule) works flawlessly.


We have a PBF like that:

<entry name="return">
      <entry name=""/>

I.e. no-pbf for the forward section and symmetric return via the router.


Has anyone ever come accross this issue? Any idea why after some time the VLAN tag 410 is just dropped from return packets?


What bugs me the most: The session is running like a charm ... until after the handshake (application detection?) and only then the VLAN tags goes missing.


Thanks for ideas,



PS: So far the first level support was not very helpful with this issue.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!