Voice traffic insufficatnt when using virtual wire

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Voice traffic insufficatnt when using virtual wire

L1 Bithead

the voice traffic blocked when i use virtual wire it said insufficant data

when i remove palo alto from the traffic everything goes fine

 

2 REPLIES 2

L4 Transporter

Hi,

 

Does your voice traffic use 802.1Q VLAN tags? If so then you will need to implement subinterfaces to handle this traffic, even in vwire deployment.

 

https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/networking/virtual-wire-deployments

 

hope this helps,

Ben

in case of the vlan tags you wouldn't necessarily need to create subinterfaces, enabling vln tags in the vwire should be enough

2016-10-18_13-24-00.png

 

 

also: did this issue start occurring immediately after introducing the vwire and did you wait long enough for it to correct itself?

 

when introducing a vwire, any existing sessions will be blocked as there was never a handshake seen by the firewall and so no session was created to allow the traffic to pass through. eventually all sessions should gracefully reestablish but some applications may take a long time to 'autocorrect'

 

you could try disabling non-syn drop mechanism for a while:

> set session tcp-reject-non-syn no

dont leave this setting disabled for too long, just long enough for sessions to reestablish and you are satisfied everything works, then turn it back on again

 

> set session tcp-reject-non-syn yes

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1832 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!