<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Fragmented SIP traffic gets silently dropped in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/532728#M960</link>
    <description>&lt;P&gt;Hi guys,&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;PA-5250,&amp;nbsp;9.1.14&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;Can you help me with this one, please?&lt;BR /&gt;&lt;BR /&gt;PA does not like fragmented SIP INVITE packets, and we can see them in the drop queue:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="d_r.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48286iC0FAF5EE159D444C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="d_r.PNG" alt="d_r.PNG" /&gt;&lt;/span&gt;No traffic, threat or URL filtering logs were created (expected, I believe).&amp;nbsp;&lt;BR /&gt;Why is it doing that?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;myky&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Mar 2023 08:02:29 GMT</pubDate>
    <dc:creator>MykyUk</dc:creator>
    <dc:date>2023-03-02T08:02:29Z</dc:date>
    <item>
      <title>Fragmented SIP traffic gets silently dropped</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/532728#M960</link>
      <description>&lt;P&gt;Hi guys,&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;PA-5250,&amp;nbsp;9.1.14&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;Can you help me with this one, please?&lt;BR /&gt;&lt;BR /&gt;PA does not like fragmented SIP INVITE packets, and we can see them in the drop queue:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="d_r.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48286iC0FAF5EE159D444C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="d_r.PNG" alt="d_r.PNG" /&gt;&lt;/span&gt;No traffic, threat or URL filtering logs were created (expected, I believe).&amp;nbsp;&lt;BR /&gt;Why is it doing that?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;myky&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 08:02:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/532728#M960</guid>
      <dc:creator>MykyUk</dc:creator>
      <dc:date>2023-03-02T08:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: Fragmented SIP tarffic gets silently dropped</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/532729#M961</link>
      <description>&lt;P&gt;Do you have Zone Protection applied to zone this traffic comes from?&lt;/P&gt;
&lt;P&gt;If you add filter to "Monitor &amp;gt; Packet Capture" to capture traffic from&amp;nbsp;10.125.3.23 and then run following command in cli what is output? Can you identify based on couters what caused packet drops?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; show counter global filter delta yes packet-filter yes&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 17:52:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/532729#M961</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-03-01T17:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: Fragmented SIP tarffic gets silently dropped</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/532894#M970</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;.&lt;BR /&gt;Long time!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;At one point, I thought that my PA skills completely got rusty, as I believe I have checked that earlier.&amp;nbsp;&lt;BR /&gt;There is no ZPP applied; we got only a basic one on the untrusted zone:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MykyUk_0-1677742692924.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48355iBF6A660CB0E87FC8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MykyUk_0-1677742692924.png" alt="MykyUk_0-1677742692924.png" /&gt;&lt;/span&gt;&lt;BR /&gt;thanks,&lt;/P&gt;
&lt;P&gt;myky&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 08:13:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/532894#M970</guid>
      <dc:creator>MykyUk</dc:creator>
      <dc:date>2023-03-02T08:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Fragmented SIP traffic gets silently dropped</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/532941#M972</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/276706"&gt;@MykyUk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this case "show counter global filter delta yes packet-filter yes" is best next step figuring out why they are dropped.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 13:14:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/532941#M972</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-03-02T13:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: Fragmented SIP traffic gets silently dropped</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/532953#M974</link>
      <description>&lt;P&gt;Got yah, yes will arrange testing today and update this thread. Thanks! myky&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 14:12:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/532953#M974</guid>
      <dc:creator>MykyUk</dc:creator>
      <dc:date>2023-03-02T14:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: Fragmented SIP traffic gets silently dropped</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/532965#M976</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;have you seen this before:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fr.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48371iFC5FE055E8F27016/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="fr.PNG" alt="fr.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;I have a feeling it might be a TAC case.&lt;BR /&gt;&lt;BR /&gt;thanks,&lt;BR /&gt;myky&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 15:15:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/532965#M976</guid>
      <dc:creator>MykyUk</dc:creator>
      <dc:date>2023-03-02T15:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: Fragmented SIP traffic gets silently dropped</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/532986#M977</link>
      <description>&lt;P&gt;re-run it again; PA is clearly not happy:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MykyUk_0-1677776358357.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48374iB574AB896AF5ABE4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MykyUk_0-1677776358357.png" alt="MykyUk_0-1677776358357.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MykyUk_1-1677776386993.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48375i4303F1C5F1BAE730/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MykyUk_1-1677776386993.png" alt="MykyUk_1-1677776386993.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 16:59:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/532986#M977</guid>
      <dc:creator>MykyUk</dc:creator>
      <dc:date>2023-03-02T16:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Fragmented SIP traffic gets silently dropped</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/533571#M997</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;correction:&lt;BR /&gt;SSD was replaced, and when we failback traffic, the issue returned.&lt;BR /&gt;Eventually, TAC confirmed that we hit the following bug:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV&gt;&lt;STRONG&gt;PAN-194395&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;Fixed an issue where the firewall dropped all decrypted outbound (SSL Forward Proxy) HTTP/2 traffic after you upgraded to PAN-OS 9.1.14, which caused websites that used HTTP/2 to become inaccessible.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Same issue, old discussion:&lt;BR /&gt;&lt;A href="https://www.reddit.com/r/paloaltonetworks/comments/vzrann/panos_9114_software_buffer_depletion/" target="_blank"&gt;https://www.reddit.com/r/paloaltonetworks/comments/vzrann/panos_9114_software_buffer_depletion/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The bug description is way off.&lt;BR /&gt;&lt;BR /&gt;thanks, myky&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 18:12:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fragmented-sip-traffic-gets-silently-dropped/m-p/533571#M997</guid>
      <dc:creator>MykyUk</dc:creator>
      <dc:date>2023-03-16T18:12:44Z</dc:date>
    </item>
  </channel>
</rss>

