<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NGFW - Panorama registration 3978 : Traffic allowed but RST constantly. in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ngfw-panorama-registration-3978-traffic-allowed-but-rst/m-p/584500#M2297</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was trying to connect a new PA-440 spare device to our existing Panorama infrastructure, when i faced this weird issue as shown in the system logs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's as if the TCP session starts and abruptly ends on port 3978 leading to a never ending loop of success and failure.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Panorama is natted behind a cisco so i went there to see what was going on and found these reiterating RST packets seemingly after each connection attempt from the PA-440 public ip.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not sure why this is happening ? The CISCO rules don't seem to be at fault since the TCP session builds initially however the immediate RST that happens right after is unexplained ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The PA-440 is routed behind a 5G TP-Link Router which doesn't have a fixed IP, so i have to change the corresponding object in the cisco everytime but this is not a problem for now as is it intended as a lab environment for internal testing purposes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm suspecting something doesn't go well because of this router, but i'm not 100% sure, anyone encountered something like this before ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Little update 1 day later :&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I can see the the session "established" and the traffic allowed but constantly reset on what i assume to be the peer side (cisco). Not sure why this could happen.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OELHANCHI_0-1713863049269.png" style="width: 986px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59224iE4EBC7F66D93E625/image-dimensions/986x54/is-moderation-mode/true?v=v2" width="986" height="54" role="button" title="OELHANCHI_0-1713863049269.png" alt="OELHANCHI_0-1713863049269.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OELHANCHI_1-1713863173974.png" style="width: 947px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59225i4FA9524ED22E8FAE/image-dimensions/947x207/is-moderation-mode/true?v=v2" width="947" height="207" role="button" title="OELHANCHI_1-1713863173974.png" alt="OELHANCHI_1-1713863173974.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Apr 2024 09:11:59 GMT</pubDate>
    <dc:creator>O.ELHANCHI</dc:creator>
    <dc:date>2024-04-23T09:11:59Z</dc:date>
    <item>
      <title>NGFW - Panorama registration 3978 : Traffic allowed but RST constantly.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ngfw-panorama-registration-3978-traffic-allowed-but-rst/m-p/584500#M2297</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was trying to connect a new PA-440 spare device to our existing Panorama infrastructure, when i faced this weird issue as shown in the system logs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's as if the TCP session starts and abruptly ends on port 3978 leading to a never ending loop of success and failure.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Panorama is natted behind a cisco so i went there to see what was going on and found these reiterating RST packets seemingly after each connection attempt from the PA-440 public ip.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not sure why this is happening ? The CISCO rules don't seem to be at fault since the TCP session builds initially however the immediate RST that happens right after is unexplained ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The PA-440 is routed behind a 5G TP-Link Router which doesn't have a fixed IP, so i have to change the corresponding object in the cisco everytime but this is not a problem for now as is it intended as a lab environment for internal testing purposes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm suspecting something doesn't go well because of this router, but i'm not 100% sure, anyone encountered something like this before ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Little update 1 day later :&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I can see the the session "established" and the traffic allowed but constantly reset on what i assume to be the peer side (cisco). Not sure why this could happen.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OELHANCHI_0-1713863049269.png" style="width: 986px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59224iE4EBC7F66D93E625/image-dimensions/986x54/is-moderation-mode/true?v=v2" width="986" height="54" role="button" title="OELHANCHI_0-1713863049269.png" alt="OELHANCHI_0-1713863049269.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OELHANCHI_1-1713863173974.png" style="width: 947px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59225i4FA9524ED22E8FAE/image-dimensions/947x207/is-moderation-mode/true?v=v2" width="947" height="207" role="button" title="OELHANCHI_1-1713863173974.png" alt="OELHANCHI_1-1713863173974.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 09:11:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/ngfw-panorama-registration-3978-traffic-allowed-but-rst/m-p/584500#M2297</guid>
      <dc:creator>O.ELHANCHI</dc:creator>
      <dc:date>2024-04-23T09:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW - Panorama registration 3978 : Traffic allowed but RST constantly.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ngfw-panorama-registration-3978-traffic-allowed-but-rst/m-p/585117#M2310</link>
      <description>&lt;P&gt;Had the same issue on an other device during initial device installation phase, it was a different model (PA-220), but i was getting the same RST packets from the panorama side.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The solution was to upgrade to the latest PAN-OS version, to get the recently updated root certificate. Pretty idiotic from me, trying to get a registration before the upgrade.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I suppose the same step would solve it for this device, can't 100% confirm however as i don't have an available license for that model yet, but very likely.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Apr 2024 14:37:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/ngfw-panorama-registration-3978-traffic-allowed-but-rst/m-p/585117#M2310</guid>
      <dc:creator>O.ELHANCHI</dc:creator>
      <dc:date>2024-04-27T14:37:05Z</dc:date>
    </item>
  </channel>
</rss>

