<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log Subtype in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/log-subtype/m-p/535181#M1054</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in a Firewall&amp;nbsp;a session is defined by two unidirectional flows each uniquely identified by a 6 tuple key: source IP address, destination IP address, source port, destination port, protocol, and source zone. If traffic has match for policy and the action of the policy is set to deny, then there is no further inspection and traffic is blocked with the log recorded as action: "deny" session end reason: "policy-deny".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the case, the policy action is set to allow, then there is further L7 inspection where traffic can be eventually dropped based on further inspection. Here is the&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HCQlCAO" target="_self"&gt;KB&lt;/A&gt;&amp;nbsp;with more details. If you want to deep dive into exact reason for traffic being blocked click on magnifying glass icon on left hand side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
    <pubDate>Mon, 20 Mar 2023 23:29:49 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2023-03-20T23:29:49Z</dc:date>
    <item>
      <title>Log Subtype</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/log-subtype/m-p/535052#M1050</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I need some information on checking the logs. I see few things like END, DENY, SPYWARE, INFORMATION etc and in the action we see it as allowed. But the access will not be working. May i know what this Log Subtype means and what information will it give us in troubleshooting? When it says ALLOW as action then why in Subtype it is Deny. How to troubleshoot these issues?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 12:09:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/log-subtype/m-p/535052#M1050</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2023-03-20T12:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Log Subtype</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/log-subtype/m-p/535181#M1054</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in a Firewall&amp;nbsp;a session is defined by two unidirectional flows each uniquely identified by a 6 tuple key: source IP address, destination IP address, source port, destination port, protocol, and source zone. If traffic has match for policy and the action of the policy is set to deny, then there is no further inspection and traffic is blocked with the log recorded as action: "deny" session end reason: "policy-deny".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the case, the policy action is set to allow, then there is further L7 inspection where traffic can be eventually dropped based on further inspection. Here is the&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HCQlCAO" target="_self"&gt;KB&lt;/A&gt;&amp;nbsp;with more details. If you want to deep dive into exact reason for traffic being blocked click on magnifying glass icon on left hand side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 23:29:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/log-subtype/m-p/535181#M1054</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-03-20T23:29:49Z</dc:date>
    </item>
  </channel>
</rss>

