<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall Seems to Be resetting SSH Connections in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-seems-to-be-resetting-ssh-connections/m-p/14107#M10359</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This behavior is exactly what happens when something is denied by a rule...are you ABSOLUTELY sure that you have a rule that permits this? Are you seeing anything in the traffic logs? Also, 4.1.8 had some bugs that affected us...if you want to stay in the 4.1 8 block, I recommend 4.1.8HF3 , especially if you're running an HA pair.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Jun 2013 17:55:25 GMT</pubDate>
    <dc:creator>gil_arevalo</dc:creator>
    <dc:date>2013-06-04T17:55:25Z</dc:date>
    <item>
      <title>Firewall Seems to Be resetting SSH Connections</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-seems-to-be-resetting-ssh-connections/m-p/14104#M10356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem with my Palo Alto firewall deployment were the firewall seems to be resetting all connections using port TCP 22 (SSH, SCP, SFTP). I have done packet captures on the ingress interface of the firewall and it shows as if the connection is being reset on the server side. However, packet captures on the egress interface show as if the connection is reset on the client side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone experienced this before, and can anyone help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The set i have is roughly as shown below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client &amp;lt;--------&amp;gt; Palo Alto Firewall &amp;lt;---------&amp;gt; Server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 May 2013 20:39:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-seems-to-be-resetting-ssh-connections/m-p/14104#M10356</guid>
      <dc:creator>pmutambudzi</dc:creator>
      <dc:date>2013-05-24T20:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Seems to Be resetting SSH Connections</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-seems-to-be-resetting-ssh-connections/m-p/14105#M10357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what is your panos version ?&lt;/P&gt;&lt;P&gt;Does This issue happen to only one client - server connection or every client-server connection ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you may try to write an applicetion override for that traffic, defining a new app and make tcp session time-out more than default to see if problem occurs or not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 May 2013 08:56:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-seems-to-be-resetting-ssh-connections/m-p/14105#M10357</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-05-26T08:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Seems to Be resetting SSH Connections</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-seems-to-be-resetting-ssh-connections/m-p/14106#M10358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using version 4.1.8. SSH connections to internal private addresses are working fine. I see the problem when i try to SSH to any device with a public IP that is beyond this one particular firewall. Even sftp (port 22) to addresses on the Internet fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have defined a custom app but the problem persists.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Partson.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 May 2013 17:43:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-seems-to-be-resetting-ssh-connections/m-p/14106#M10358</guid>
      <dc:creator>pmutambudzi</dc:creator>
      <dc:date>2013-05-26T17:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Seems to Be resetting SSH Connections</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-seems-to-be-resetting-ssh-connections/m-p/14107#M10359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This behavior is exactly what happens when something is denied by a rule...are you ABSOLUTELY sure that you have a rule that permits this? Are you seeing anything in the traffic logs? Also, 4.1.8 had some bugs that affected us...if you want to stay in the 4.1 8 block, I recommend 4.1.8HF3 , especially if you're running an HA pair.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2013 17:55:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-seems-to-be-resetting-ssh-connections/m-p/14107#M10359</guid>
      <dc:creator>gil_arevalo</dc:creator>
      <dc:date>2013-06-04T17:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Seems to Be resetting SSH Connections</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-seems-to-be-resetting-ssh-connections/m-p/14108#M10360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am currently running version 4.1.8 h3 and i have a rule that is explicitly allowing the traffic to go through. The traffic log shows the traffic is being allowed through.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 13:09:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-seems-to-be-resetting-ssh-connections/m-p/14108#M10360</guid>
      <dc:creator>pmutambudzi</dc:creator>
      <dc:date>2013-06-13T13:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Seems to Be resetting SSH Connections</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-seems-to-be-resetting-ssh-connections/m-p/14109#M10361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just curious, do you have any threat profiles assigned to the rule allowing this traffic? If yes, is there any threat log being generated for this traffic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 13:26:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-seems-to-be-resetting-ssh-connections/m-p/14109#M10361</guid>
      <dc:creator>goku123</dc:creator>
      <dc:date>2013-06-13T13:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Seems to Be resetting SSH Connections</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-seems-to-be-resetting-ssh-connections/m-p/14110#M10362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I actually do not have any threat prevention licence on this particular firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 13:35:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-seems-to-be-resetting-ssh-connections/m-p/14110#M10362</guid>
      <dc:creator>pmutambudzi</dc:creator>
      <dc:date>2013-06-13T13:35:54Z</dc:date>
    </item>
  </channel>
</rss>

