- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-29-2024 02:17 AM
Dear Team,
We have 2 * PA-5250 Firewall Appliances configured in Active-Passive and managed by Panorama. PANOS version on both the firewalls and Panorama is PANOS: 10.1.12.
Issue:
I've noticed an inconsistency where the Rule UUID displayed in the Traffic Logs differs from the one shown in the actual Policy. Additionally, the Traffic Logs are associating multiple Rule UUIDs with a single rule. Excluding the correct UUID, various other UUIDs are appearing in the Traffic Logs.
Furthermore, when filtering the Traffic Logs by the correct Rule UUID, no traffic is displayed. However, if I filter by the rule name, traffic logs appear but with alternate UUIDs.
This issue is with the Active Firewall only while there is no issue in the Passive firewall.
For example:
Rule UUID in Policy: 48d8f35d-e9c9-4bed-9bc9-75317067bf7e
Rule UUID in Traffic logs: 7d379199-cccf-42ad-9979-2017e5a959d1
3c79c2c6-88e5-41cd-bc65-99d7b865d63f
e401849b-4eb2-4153-beb4-4d5f3c171048
Thanks in advance,
04-29-2024 12:50 PM
Hello Friend!
04-29-2024 05:44 PM
Hi Jfernandez1,
Thanks for your response. I am aware about this concept, but the issue is not related to this.
Let me rephrase the issue:
For Example:
Rule Name: xyz/abc (Pushed from Panorama to the HA pair (Active/Passive).
Rule UUID visible in the Policy in both the Firewalls: 48d8f35d-e9c9-4bed-9bc9-75317067bf7e
Rule UUIDs visible in the Traffic logs for the same rule in the Active Firewall only:
7d379199-cccf-42ad-9979-2017e5a959d1
3c79c2c6-88e5-41cd-bc65-99d7b865d63f
e401849b-4eb2-4153-beb4-4d5f3c171048
The problem is exclusive to the Active Firewall; the Passive Firewall is functioning without any issues.
Issue is with all the rules configured in Active Firewall not with the specific rule.
I trust this clarification explained the issue clearly.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!