<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Traffic Log - What's the difference between the &amp;quot;Type&amp;quot; field and the &amp;quot;action&amp;quot; field in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-what-s-the-difference-between-the-quot-type-quot/m-p/573712#M2483</link>
    <description>&lt;P&gt;While investigating and navigating in the Traffic Log, I noticed for some traffic the &lt;STRONG&gt;Type&lt;/STRONG&gt; is &lt;STRONG&gt;Drop&lt;/STRONG&gt; and the &lt;STRONG&gt;Action&lt;/STRONG&gt; is &lt;STRONG&gt;Deny&lt;/STRONG&gt;, While in some traffic, the &lt;STRONG&gt;Type&lt;/STRONG&gt; is &lt;STRONG&gt;Deny&lt;/STRONG&gt; and the &lt;STRONG&gt;Action&lt;/STRONG&gt; is &lt;STRONG&gt;Reset&lt;/STRONG&gt; &lt;STRONG&gt;Both.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="1.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56700iFE011394C78D244D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Traffic Log.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56701i453E61699039B4EB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Traffic Log.png" alt="Traffic Log.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Security Policy Rule is configured with the &lt;STRONG&gt;Deny &lt;/STRONG&gt;Action without Security Profiles.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56702iFFDC499858517874/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How to explain this behavior in the Traffic Logs?&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jan 2024 21:30:53 GMT</pubDate>
    <dc:creator>rmeddane</dc:creator>
    <dc:date>2024-01-19T21:30:53Z</dc:date>
    <item>
      <title>Traffic Log - What's the difference between the "Type" field and the "action" field</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-what-s-the-difference-between-the-quot-type-quot/m-p/573712#M2483</link>
      <description>&lt;P&gt;While investigating and navigating in the Traffic Log, I noticed for some traffic the &lt;STRONG&gt;Type&lt;/STRONG&gt; is &lt;STRONG&gt;Drop&lt;/STRONG&gt; and the &lt;STRONG&gt;Action&lt;/STRONG&gt; is &lt;STRONG&gt;Deny&lt;/STRONG&gt;, While in some traffic, the &lt;STRONG&gt;Type&lt;/STRONG&gt; is &lt;STRONG&gt;Deny&lt;/STRONG&gt; and the &lt;STRONG&gt;Action&lt;/STRONG&gt; is &lt;STRONG&gt;Reset&lt;/STRONG&gt; &lt;STRONG&gt;Both.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="1.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56700iFE011394C78D244D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Traffic Log.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56701i453E61699039B4EB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Traffic Log.png" alt="Traffic Log.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Security Policy Rule is configured with the &lt;STRONG&gt;Deny &lt;/STRONG&gt;Action without Security Profiles.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56702iFFDC499858517874/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How to explain this behavior in the Traffic Logs?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 21:30:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-what-s-the-difference-between-the-quot-type-quot/m-p/573712#M2483</guid>
      <dc:creator>rmeddane</dc:creator>
      <dc:date>2024-01-19T21:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Log - What's the difference between the "Type" field and the "action" field</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-what-s-the-difference-between-the-quot-type-quot/m-p/573714#M2484</link>
      <description>&lt;TABLE class="table colsep rowsep  table-striped"&gt;
&lt;TBODY class="tbody"&gt;
&lt;TR class="row rowsep"&gt;
&lt;TD class="entry"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Type (type)&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD class="entry relcol"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Specifies the type of log; value is TRAFFIC.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="row rowsep"&gt;
&lt;TD class="entry"&gt;
&lt;DIV&gt;
&lt;DIV id="idbe18d2d4-9eb8-4966-bec8-df3a6de70e66_id175GA900V5Z" class="p"&gt;
&lt;DIV&gt;Threat/Content Type (subtype)&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD class="entry relcol"&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Subtype of traffic log; values are start, end, drop, and deny&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Start—session started&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;End—session ended&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Drop—session dropped before the application is identified and there is no rule that allows the session.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Deny—session dropped after the application is identified and there is a rule to block or no rule that allows the session.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="table colsep rowsep  table-striped"&gt;
&lt;TBODY class="tbody"&gt;
&lt;TR class="row rowsep"&gt;
&lt;TD class="entry"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Action (action)&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD class="entry relcol"&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Action taken for the session; possible values are:&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;allow—session was allowed by policy&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;deny—session was denied by policy&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;drop—session was dropped silently&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;drop ICMP—session was silently dropped with an ICMP unreachable message to the host or application&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;reset both—session was terminated and a TCP reset is sent to both the sides of the connection&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;reset client—session was terminated and a TCP reset is sent to the client&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;reset server—session was terminated and a TCP reset is sent to the server&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Fri, 19 Jan 2024 21:38:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-what-s-the-difference-between-the-quot-type-quot/m-p/573714#M2484</guid>
      <dc:creator>msyeedrafiqi</dc:creator>
      <dc:date>2024-01-19T21:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Log - What's the difference between the "Type" field and the "action" field</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-what-s-the-difference-between-the-quot-type-quot/m-p/573770#M2485</link>
      <description>&lt;P&gt;I read it in the admin guide, but according to the log output: Why some traffic the &lt;STRONG&gt;Type&lt;/STRONG&gt; is &lt;STRONG&gt;Drop&lt;/STRONG&gt; and the &lt;STRONG&gt;Action&lt;/STRONG&gt; is &lt;STRONG&gt;Deny&lt;/STRONG&gt;, While in some traffic, the &lt;STRONG&gt;Type&lt;/STRONG&gt; is &lt;STRONG&gt;Deny&lt;/STRONG&gt; and the &lt;STRONG&gt;Action&lt;/STRONG&gt; is &lt;STRONG&gt;Reset&lt;/STRONG&gt; &lt;STRONG&gt;Both. &lt;/STRONG&gt;While the security policy rule is configured with the action &lt;STRONG&gt;Deny&lt;/STRONG&gt;.?&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jan 2024 06:41:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-what-s-the-difference-between-the-quot-type-quot/m-p/573770#M2485</guid>
      <dc:creator>rmeddane</dc:creator>
      <dc:date>2024-01-20T06:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Log - What's the difference between the "Type" field and the "action" field</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-what-s-the-difference-between-the-quot-type-quot/m-p/573786#M2488</link>
      <description>&lt;P&gt;This is also mentioned in the admin guide:&lt;/P&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Drop—session dropped before the application is identified and there is no rule that allows the session.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV class="p"&gt;Deny—session dropped after the application is identified and there is a rule to block or no rule that allows the session.&lt;BR /&gt;&lt;BR /&gt;About the reset, The palo alto firewall only sends tcp reset if the traffic is identified as threat.&lt;BR /&gt;&lt;BR /&gt;About the reset both: I think it will happen during SSL forward proxy were the firewall intercept the tcp handshake and so it will sent tcp reset to the client and the server.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sat, 20 Jan 2024 15:29:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-what-s-the-difference-between-the-quot-type-quot/m-p/573786#M2488</guid>
      <dc:creator>msyeedrafiqi</dc:creator>
      <dc:date>2024-01-20T15:29:12Z</dc:date>
    </item>
  </channel>
</rss>

