FORW Type Session with Destination Zone captive-portal

FORW Type Session with Destination Zone captive-portal

37090
Created On 09/26/18 13:51 PM - Last Modified 04/16/19 20:52 PM


Symptom


On the PA-7000 platforms, there is one other session type defined in addition to the ones described in Palo Alto Networks Firewall Session Overview. The added session type is Forward (FORW) and is only visible on the CLI or Web GUI:

  • CLI: Run show session all and look for type FORW
  • WebGUI: Navigate to Monitor > Session Browser


Environment


PA-7000

Resolution


Characteristics of the Forward session type:
  • Used internally to deliver traffic
  • Transient only
  • Always have a destination zone "captive-portal"
    Note: This occurs even if Captive Portal is not enabled on the firewall and no zone with the name "captive-portal" has beenĀ created. This does not affect the capacity or proper function of the firewall and may be ignored.

owner: aciobanu



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clu4CAC&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language