<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: why drop rst packet in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/567479#M2183</link>
    <description>&lt;P&gt;After discussing the business model with the customer, it is believed that the reason for the Firewall to discard RST messages is Challenge ACK。&lt;/P&gt;
&lt;P&gt;Refer to this kb：&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boBJCAY。" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boBJCAY。&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;gt;configure&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #set deviceconfig setting tcp allow-challenge-ack yes&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #commit&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #exit&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, the customer has a question, what are the risks to the firewall when executing this cli？&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;how to respone this question ？&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Nov 2023 03:20:11 GMT</pubDate>
    <dc:creator>Felixcao</dc:creator>
    <dc:date>2023-11-29T03:20:11Z</dc:date>
    <item>
      <title>why drop rst packet</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/567150#M2165</link>
      <description>&lt;P&gt;The customer is capturing packets on the firewall.&lt;/P&gt;
&lt;P&gt;Check the files in the receive stage and find that the firewall has dropped the rst message sent by the client in the session.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="receive.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55425i825501AF2B937BB7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="receive.jpg" alt="receive.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drop.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55426i7EFA86D122C758E2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="drop.jpg" alt="drop.jpg" /&gt;&lt;/span&gt;Please refer to the screenshot for the file reference. Can someone tell me why the pa-firewall dropped this rst packet&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 07:32:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/567150#M2165</guid>
      <dc:creator>Felixcao</dc:creator>
      <dc:date>2023-11-27T07:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: why drop rst packet</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/567152#M2166</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76688"&gt;@Felixcao&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check the global counters. The following link explain how to sue packet capture filter for the global counters - &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you follow the steps from the link, what is the output?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 07:46:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/567152#M2166</guid>
      <dc:creator>A_Astardzhiev</dc:creator>
      <dc:date>2023-11-27T07:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: why drop rst packet</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/567153#M2167</link>
      <description>&lt;P&gt;[2023/11/24 11:21:39] admin01@5260-02(active-secondary)&amp;gt; show counter global filter packet-filter yes delta yes&lt;BR /&gt;[2023/11/24 11:21:39] &lt;BR /&gt;[2023/11/24 11:21:39] Global counters:&lt;BR /&gt;[2023/11/24 11:21:39] Elapsed time since last sampling: 3.448 seconds&lt;BR /&gt;[2023/11/24 11:21:39] &lt;BR /&gt;[2023/11/24 11:21:39] --------------------------------------------------------------------------------&lt;BR /&gt;[2023/11/24 11:21:39] Total counters shown: 0&lt;BR /&gt;[2023/11/24 11:21:39] --------------------------------------------------------------------------------&lt;BR /&gt;[2023/11/24 11:21:39] &lt;BR /&gt;[2023/11/24 11:22:03] admin01@5260-02(active-secondary)&amp;gt; show counter global filter packet-filter yes delta yes&lt;BR /&gt;[2023/11/24 11:22:03] &lt;BR /&gt;[2023/11/24 11:22:03] Global counters:&lt;BR /&gt;[2023/11/24 11:22:03] Elapsed time since last sampling: 0.127 seconds&lt;BR /&gt;[2023/11/24 11:22:03] &lt;BR /&gt;[2023/11/24 11:22:03] --------------------------------------------------------------------------------&lt;BR /&gt;[2023/11/24 11:22:03] Total counters shown: 0&lt;BR /&gt;[2023/11/24 11:22:03] --------------------------------------------------------------------------------&lt;BR /&gt;[2023/11/24 11:22:03] &lt;BR /&gt;[2023/11/24 11:22:09] admin01@5260-02(active-secondary)&amp;gt; show counter global filter packet-filter yes delta yes&lt;BR /&gt;[2023/11/24 11:22:09] &lt;BR /&gt;[2023/11/24 11:22:09] Global counters:&lt;BR /&gt;[2023/11/24 11:22:09] Elapsed time since last sampling: 1.924 seconds&lt;/P&gt;
&lt;P&gt;no any&amp;nbsp;counter global output.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 07:49:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/567153#M2167</guid>
      <dc:creator>Felixcao</dc:creator>
      <dc:date>2023-11-27T07:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: why drop rst packet</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/567157#M2168</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76688"&gt;@Felixcao&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The command will return only information in real-time (no historical data). Which means you need to setup the capture and reproduce the issue by generating traffic that is matching your filters.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The lack of any counters means that there is no session that is currently passing over the firewall that is matching your filter.&lt;/P&gt;
&lt;P&gt;It looks like you are running active-active, so either the traffic is not matching your filter, or you are capturing on the wrong firewall, or just there is no traffic&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 07:56:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/567157#M2168</guid>
      <dc:creator>A_Astardzhiev</dc:creator>
      <dc:date>2023-11-27T07:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: why drop rst packet</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/567173#M2170</link>
      <description>&lt;P&gt;Hi, Aleksandar:&lt;/P&gt;
&lt;P&gt;Thank you very much for your enthusiastic reply.&lt;/P&gt;
&lt;P&gt;The lack of any counters means that there is no session that is currently passing over the firewall that is matching your filter.&lt;BR /&gt;--------There should be no problem. After turning off the packet capture stop filtering condition, output a count of global traffic&lt;/P&gt;
&lt;P&gt;It looks like you are running active-active, so either the traffic is not matching your filter, or you are capturing on the wrong firewall, or just there is no traffic&lt;/P&gt;
&lt;P&gt;--------Yes, actvie active mode. The customer confirmed that the operation was done on the correct wall&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 09:58:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/567173#M2170</guid>
      <dc:creator>Felixcao</dc:creator>
      <dc:date>2023-11-27T09:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: why drop rst packet</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/567330#M2178</link>
      <description>&lt;P&gt;From&amp;nbsp;counter global output,&amp;nbsp;suspect root cause is&amp;nbsp;tcp_drop_out_of_wnd&amp;nbsp; ?&lt;/P&gt;
&lt;P&gt;[2023/11/27 18:21:33] admin01@5260-02(active-secondary)&amp;gt; show counter global filter packet-filter yes delta yes&lt;BR /&gt;[2023/11/27 18:21:34] &lt;BR /&gt;[2023/11/27 18:21:34] Global counters:&lt;BR /&gt;[2023/11/27 18:21:34] Elapsed time since last sampling: 0.744 seconds&lt;BR /&gt;[2023/11/27 18:21:34] &lt;BR /&gt;[2023/11/27 18:21:34] name value rate severity category aspect description&lt;BR /&gt;[2023/11/27 18:21:34] --------------------------------------------------------------------------------&lt;BR /&gt;[2023/11/27 18:21:34] pkt_outstanding 13 17 info packet pktproc Outstanding packet to be transmitted&lt;BR /&gt;[2023/11/27 18:21:34] pkt_alloc 14 18 info packet resource Packets allocated&lt;BR /&gt;[2023/11/27 18:21:34] session_allocated 1 1 info session resource Sessions allocated&lt;BR /&gt;[2023/11/27 18:21:34] session_installed 1 1 info session resource Sessions installed&lt;BR /&gt;[2023/11/27 18:21:34] flow_np_pkt_xmt 10 13 info flow offload Packets transmitted to offload processor&lt;BR /&gt;[2023/11/27 18:21:34] flow_host_pkt_xmt 10 13 info flow mgmt Packets transmitted to control plane&lt;BR /&gt;[2023/11/27 18:21:34] flow_host_vardata_rate_limit_ok 10 13 info flow mgmt Host vardata not sent: rate limit ok&lt;BR /&gt;[2023/11/27 18:21:34] flow_fpga_rcv_fastpath 2 2 info flow offload fpga packets for fastpath received&lt;BR /&gt;[2023/11/27 18:21:34] flow_fpp_sess_bind_notify 1 1 info flow offload Sess bind notification to FPP&lt;BR /&gt;[2023/11/27 18:21:34] appid_override 1 1 info appid pktproc Application identified by override rule&lt;BR /&gt;[2023/11/27 18:21:34] tcp_drop_out_of_wnd 1 1 warn tcp resource out-of-window packets dropped&lt;BR /&gt;[2023/11/27 18:21:34] ha_msg_sent 3 4 info ha system HA: messages sent&lt;BR /&gt;[2023/11/27 18:21:34] ha_session_setup_msg_sent 1 1 info ha pktproc HA: session setup messages sent&lt;BR /&gt;[2023/11/27 18:21:34] ha_session_update_msg_sent 1 1 info ha pktproc HA: session update messages sent&lt;BR /&gt;[2023/11/27 18:21:35] ha_aa_session_setup_msg_sent 1 1 info ha pktproc HA: A/A session setup messages sent&lt;BR /&gt;[2023/11/27 18:21:35] ha_aa_session_setup_local 1 1 info ha aa Active/Active: setup session on local device&lt;BR /&gt;[2023/11/27 18:21:35] --------------------------------------------------------------------------------&lt;BR /&gt;[2023/11/27 18:21:35] Total counters shown: 16&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 06:52:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/567330#M2178</guid>
      <dc:creator>Felixcao</dc:creator>
      <dc:date>2023-11-28T06:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: why drop rst packet</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/567479#M2183</link>
      <description>&lt;P&gt;After discussing the business model with the customer, it is believed that the reason for the Firewall to discard RST messages is Challenge ACK。&lt;/P&gt;
&lt;P&gt;Refer to this kb：&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boBJCAY。" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boBJCAY。&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;gt;configure&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #set deviceconfig setting tcp allow-challenge-ack yes&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #commit&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #exit&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, the customer has a question, what are the risks to the firewall when executing this cli？&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;how to respone this question ？&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 03:20:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/567479#M2183</guid>
      <dc:creator>Felixcao</dc:creator>
      <dc:date>2023-11-29T03:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: why drop rst packet</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/584432#M3028</link>
      <description>&lt;P&gt;Did this fix the issue? The article you provided is for RSTs when the sequence ID is different. Your sequence ID's are the same.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2024 22:40:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-drop-rst-packet/m-p/584432#M3028</guid>
      <dc:creator>jamessciortino</dc:creator>
      <dc:date>2024-04-21T22:40:37Z</dc:date>
    </item>
  </channel>
</rss>

