Big-IQ Network Issues
Weird issue
Our networking team migrated our Palo Alto FW out of the datacenter, but kept the configurations/rules/etc the same. However, after the migration we have been seeing wierd network issues.
Environment: F5 BIg-IQ HA Pair. Inline so all servers/services using the F5 use it as a gateway on a private IP address. All services use SNAT.
For external public subnets, the Palo Alto is their gateways.
After the move we can initiate and establish sessions with servers behind the F5. Services and servers access is normal and we can use them as adverstised. However, some servers require a external authentication system (CAS) and the server behind the F5 cannot initate a connection to that server. During troubleshooting, we realized that the servers could not ping the gateway. Our networking team sees route neighboring between F5, HP Switch and Palo Alto. We can ping and access http between systems on the private subnet, so it is not an issue with the servers.
Also we have not made any changes to the F5 days prior to the FW Migration, and the only change since is to reboot the F5 HA pair.
Any suggestions on where to start looking in the F5 to see what may be causing the problem.