<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packet Deny even if there is an allow rule in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/packet-deny-even-if-there-is-an-allow-rule/m-p/455466#M607</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/204251"&gt;@jguffroy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also check this url&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHJCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Sat, 25 Dec 2021 22:45:36 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2021-12-25T22:45:36Z</dc:date>
    <item>
      <title>Packet Deny even if there is an allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/packet-deny-even-if-there-is-an-allow-rule/m-p/454942#M593</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we're encountred an issue with SAAS service, we created a security rule&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jguffroy_0-1640167686948.png" style="width: 836px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38305i8E73EB9BCC93BB7C/image-dimensions/836x138/is-moderation-mode/true?v=v2" width="836" height="138" role="button" title="jguffroy_0-1640167686948.png" alt="jguffroy_0-1640167686948.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but randomly we had issue during connection into the application, after packet capture, I saw a lot of tcp retransmission and client reset&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jguffroy_1-1640167824901.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38306iAAC15F3F5A1992F4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="jguffroy_1-1640167824901.png" alt="jguffroy_1-1640167824901.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;When I checked the panorama logs I saw that the rule is not matched and flow is denied but I dont understand why because the security rule should be enough permissive.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jguffroy_2-1640167920421.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38307iB56C281CE944C36F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="jguffroy_2-1640167920421.png" alt="jguffroy_2-1640167920421.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Did you already encountred this issue ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for your feedback&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 10:12:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/packet-deny-even-if-there-is-an-allow-rule/m-p/454942#M593</guid>
      <dc:creator>jguffroy</dc:creator>
      <dc:date>2021-12-22T10:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Deny even if there is an allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/packet-deny-even-if-there-is-an-allow-rule/m-p/455456#M605</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/204251"&gt;@jguffroy&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on screen shot you supplied it is not clear what the root cause is. Would it be possible to navigate in the log to very left side and click on magnifying glass, get session ID from denied and allowed log, then navigate to Firewall's CLI and check/compare details of each session?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show session id &amp;lt;session id&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Sat, 25 Dec 2021 22:36:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/packet-deny-even-if-there-is-an-allow-rule/m-p/455456#M605</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-12-25T22:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Deny even if there is an allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/packet-deny-even-if-there-is-an-allow-rule/m-p/455463#M606</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/204251"&gt;@jguffroy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have FQDN as destination address then that can be issue if IP changes on the url and PA it is not refreshed.&lt;/P&gt;
&lt;P&gt;Default FQDN timer is 30 mins.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can click on Destination address under address and then click on FQDN to see which IP it resolves and compare it with the&lt;/P&gt;
&lt;P&gt;deny rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also refresh the fqdn so it learns the new ip of the fqdn&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sat, 25 Dec 2021 22:43:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/packet-deny-even-if-there-is-an-allow-rule/m-p/455463#M606</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2021-12-25T22:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Deny even if there is an allow rule</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/packet-deny-even-if-there-is-an-allow-rule/m-p/455466#M607</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/204251"&gt;@jguffroy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also check this url&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHJCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sat, 25 Dec 2021 22:45:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/packet-deny-even-if-there-is-an-allow-rule/m-p/455466#M607</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2021-12-25T22:45:36Z</dc:date>
    </item>
  </channel>
</rss>

