<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Traffic log action shows allow but session end shows threat in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-action-shows-allow-but-session-end-shows-threat/m-p/510018#M240</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need to know if any traffic log is showing allow and if the session end reason is showing as threat than in that case the traffic is allowed, or it's blocked, and also I need to know why the traffic is showing us threat.&lt;/P&gt;</description>
    <pubDate>Wed, 27 Jul 2022 05:01:03 GMT</pubDate>
    <dc:creator>PPradhan</dc:creator>
    <dc:date>2022-07-27T05:01:03Z</dc:date>
    <item>
      <title>Traffic log action shows allow but session end shows threat</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-action-shows-allow-but-session-end-shows-threat/m-p/510018#M240</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need to know if any traffic log is showing allow and if the session end reason is showing as threat than in that case the traffic is allowed, or it's blocked, and also I need to know why the traffic is showing us threat.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 05:01:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-action-shows-allow-but-session-end-shows-threat/m-p/510018#M240</guid>
      <dc:creator>PPradhan</dc:creator>
      <dc:date>2022-07-27T05:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic log action shows allow but session end shows threat</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-action-shows-allow-but-session-end-shows-threat/m-p/510042#M242</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227481"&gt;@PPradhan&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HCQlCAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HCQlCAO&lt;/A&gt;&amp;nbsp;gives best answer. In nutshell, the log is showing as allowed as it is not blocked by security policy itself (6 tuple), however traffic if processed further by L7 inspection where it is getting block based on threat signature, therefore this session is in the end blocked with end reason threat.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 10:30:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-action-shows-allow-but-session-end-shows-threat/m-p/510042#M242</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-07-27T10:30:50Z</dc:date>
    </item>
  </channel>
</rss>

