Error:
An unexpected error occurred. Please click Reload to try again.
Error:
An unexpected error occurred. Please click Reload to try again.
Path Monitoring Never Recovers With Strict IP Address Check - Knowledge Base - Palo Alto Networks

Path Monitoring Never Recovers With Strict IP Address Check

16848
Created On 06/18/20 04:40 AM - Last Modified 09/15/20 03:08 AM


Symptom


  • Firewall is dual homed to two ISPs with path monitoring over the primary link:
GUI: Network --> Virtual Routers --> More Runtime Stats:
 
RIB table

Network --> Virtual Router --> Static  Routes:
User-added image
  • Each ISP interface has a Zone Protection profile with 'Strict IP Address Check'
Network --> Zones:
 
Zone Protection

Network --> Zone Protection --> Packet Based Attack Protection:

Zone Protection  Profile
 
  • Primary path fails and is deleted/removed; while the secondary path is flagged as 'Active' and installed in the FIB:
Monitor --> System:
 
System logs

Network --> Virtual Router --> Static  Routes:
 
User-added image
  • Service is restored on the primary link but the primary link never preempts or takes over after the 'Preemptive Hold Time' expires. The RIB does not even get updated and continues to use the secondary link for routing.

 


Environment


  • Any PAN-OS
  • Palo Alto Firewall.
  • Path-monitoring is configured for redundancy/failure scenarios.
  • Zone Protection is in use on both zones with Strict IP Address Check enabled


Cause


Global counter on the filter for the path-monitored source/destination IP indicates that the monitored traffic is being dropped with a reason: Packets dropped: Zone protection option 'strict-ip-check.'
 
admin@PA-VM> debug dataplane packet-diag show setting

--------------------------------------------------------------------------------
Packet diagnosis setting:
--------------------------------------------------------------------------------
Packet filter
  Enabled:                   yes
  Match pre-parsed packet:   no
  Index 1: 10.0.0.1/32[0]->8.8.8.8/32[0], proto 0
           ingress-interface any, egress-interface any, exclude non-IP
  Index 2: 8.8.8.8/32[0]->10.0.0.1/32[0], proto 0
           ingress-interface any, egress-interface any, exclude non-IP
--------------------------------------------------------------------------------

admin@PA-VM> show counter global filter packet-filter yes delta yes

Global counters:
Elapsed time since last sampling: 231.955 seconds

name                                   value     rate severity  category  aspect    description
--------------------------------------------------------------------------------
pkt_recv                                   3        0 info      packet    pktproc   Packets received
flow_dos_pf_strictip                      63        0 drop      flow      dos       Packets dropped: Zone protection option 'strict-ip-check'
flow_tunnel_decap_err                     63        0 drop      flow      tunnel    Packet dropped: tunnel decapsulation error
flow_tunnel_ipsec_esp_encap               77        0 info      flow      tunnel    Packet encapped: IPSec ESP
flow_tunnel_encap_resolve                 77        0 info      flow      tunnel    tunnel structure lookup resolve
--------------------------------------------------------------------------------
Total counters shown: 5
--------------------------------------------------------------------------------

 


Resolution


  1. Disable 'Strict IP Address Check' in the Zone Protection Profile; or
  2. Place the primary and secondary links in two separate virtual routers
Either of these solutions should result in path recovery with the primary path installed as 'Active' route:

Monitor --> System:
 
User-added image

Network --> Virtual Router --> More Runtime Stats:
 
RIB  after recover


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008UUVCA2&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language