<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP 3 way handshake success (telnet) but data doesnt flow through in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-3-way-handshake-success-telnet-but-data-doesnt-flow-through/m-p/485860#M104553</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/196381"&gt;@VLim&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the service set to in rule 1?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Mon, 09 May 2022 17:37:30 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2022-05-09T17:37:30Z</dc:date>
    <item>
      <title>TCP 3 way handshake success (telnet) but data doesnt flow through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-3-way-handshake-success-telnet-but-data-doesnt-flow-through/m-p/485752#M104546</link>
      <description>&lt;P&gt;Information&lt;BR /&gt;Source : 10.1.1.1&lt;BR /&gt;Destination (example) 202.181.200.188&lt;BR /&gt;Destination Port : 8443&lt;/P&gt;&lt;P&gt;Client is running on port based firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issue (Technical not an issue just the firewall behavior) :&lt;/P&gt;&lt;P&gt;3 way hand shake success which mean telnet port 8443 is success but the actual data doesnt go through and with deny log record at traffic log. Client is questioning why TCP hand shake is success.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Rules 1 : Permit 10.1.1.1 destination any application ICMP, PING and traceroute&lt;BR /&gt;Rules 2 : Deny IP ANY ANY&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Based on debug flow the traffic hit the Rules 1 due to PING application as it doesnt have any standard port configure. 3 way hand shake is success but with the debug ( CP-DENY TCP non data packet getting through)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Question 1 :&amp;nbsp; why the telnet is successful ?&lt;/P&gt;&lt;P&gt;Question 2 : where is the 2nd time policy rerun again to recheck the destination port?&lt;BR /&gt;Question 3: where to check policy id based on the debug log (example : first packet policy id 3)&lt;BR /&gt;Question 4 : how to interpret following app id&amp;nbsp;&lt;/P&gt;&lt;P&gt;(2022-05-09 16:37:18.531 +0800 debug: pan_appsig_process_result(pan_app_sigs.c:669): Process app signature [oridus-nettouch] rule [nettouch-1], dir [cts]&lt;BR /&gt;2022-05-09 16:37:18.531 +0800 debug: pan_appsig_process_result(pan_app_sigs.c:695): slot is 0&lt;BR /&gt;2022-05-09 16:37:18.531 +0800 debug: pan_appid_check_header_match(pan_app_sigs.c:299): Header match: app rule [nettouch-1] matches&lt;BR /&gt;2022-05-09 16:37:18.531 +0800 debug: pan_appid_check_string_match(pan_app_sigs.c:528): MATCH_IN_ORDER: app rule [nettouch-1] match&lt;BR /&gt;2022-05-09 16:37:18.531 +0800 debug: pan_appid_process_pkt_done(pan_appid_proc.c:1897): Packets seen by appid: 1&lt;BR /&gt;2022-05-09 16:37:18.531 +0800 debug: pan_appid_process_pkt_done(pan_appid_proc.c:1903): Bytes [cts] seen by appid: 1)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 09:29:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-3-way-handshake-success-telnet-but-data-doesnt-flow-through/m-p/485752#M104546</guid>
      <dc:creator>VLim</dc:creator>
      <dc:date>2022-05-09T09:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: TCP 3 way handshake success (telnet) but data doesnt flow through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-3-way-handshake-success-telnet-but-data-doesnt-flow-through/m-p/485759#M104548</link>
      <description>&lt;P&gt;Hi VLim,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Keep in mind you'll need to add the "telnet" application that security policy also for telnet traffic to match it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Separately, that "CP-DENY TCP non data packet" may imply the next packet after handshake is being blocked as part of Zone Protection or global firewall TCP Settings.&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 09:58:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-3-way-handshake-success-telnet-but-data-doesnt-flow-through/m-p/485759#M104548</guid>
      <dc:creator>KieraMitchell</dc:creator>
      <dc:date>2022-05-09T09:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: TCP 3 way handshake success (telnet) but data doesnt flow through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-3-way-handshake-success-telnet-but-data-doesnt-flow-through/m-p/485762#M104549</link>
      <description>&lt;P&gt;hi Kiera,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually I wanna block the port 8443 but the telnet is successful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 10:27:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-3-way-handshake-success-telnet-but-data-doesnt-flow-through/m-p/485762#M104549</guid>
      <dc:creator>VLim</dc:creator>
      <dc:date>2022-05-09T10:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: TCP 3 way handshake success (telnet) but data doesnt flow through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-3-way-handshake-success-telnet-but-data-doesnt-flow-through/m-p/485860#M104553</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/196381"&gt;@VLim&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the service set to in rule 1?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 17:37:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-3-way-handshake-success-telnet-but-data-doesnt-flow-through/m-p/485860#M104553</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-05-09T17:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: TCP 3 way handshake success (telnet) but data doesnt flow through</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-3-way-handshake-success-telnet-but-data-doesnt-flow-through/m-p/485939#M104559</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/196381"&gt;@VLim&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;It sounds the answer is right there in your question - "traffic hit the Rules 1 due to PING application as it doesnt have any standard port configure"&lt;/P&gt;
&lt;P&gt;- Even that Palo Alto firewall is pretty smart, it doesn't re-invet how networks work .So even if you still allow applications not ports don't forget that how networks works&lt;/P&gt;
&lt;P&gt;- TCP 3-way-hand shake doesn' provide any information about the about the application used or any of the above layers. So how do you expect for the firewall to identify that you want to use facebook on the first TCP SYN -it cannot.&lt;/P&gt;
&lt;P&gt;- Using app-id firewall will need to allow some traffic to pass in order to identify the actuall application. For example web browsing - firewall will allow the TCP hanshake to complete and wait for the firsts packets that transfer actuall data and will see that it countains HTTP GET&lt;/P&gt;
&lt;P&gt;- If you have noticed when creating firewall rule for service (basically ports) you can specify: application-default, any or something specific. Application-default is related to the application signatures that FW is using to identify applications. If you go to Objects -&amp;gt; Applications and open details for any app, you will notice that each app definition contain standard ports. This is what FW expect to be used for such application.&lt;/P&gt;
&lt;P&gt;- So when you allow web browsing app with application-default service, firewall will again need to allow the TCP handshake to establish in order to get the HTTP traffic and identify it as web browsing, &lt;STRONG&gt;but&lt;/STRONG&gt; it will allow only TCP traffic over ports 80 and 8080, because those are the only ports that FW is expecting to be used for web traffic.&lt;/P&gt;
&lt;P&gt;- If you use "any' for service, firewall will allow any session - no matter which port is used, because you simply tell it that you expect given application on any port.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure what debug have you run for the above output, but if you are insterested to go deeper I would suggest you to check this traning on how to run Debug level packet tracing - &lt;A href="https://beacon.paloaltonetworks.com/student/path/1028945?sid=4a4b7cef-fe1b-4109-a308-5f8e3e317138&amp;amp;sid_i=0" target="_blank"&gt;https://beacon.paloaltonetworks.com/student/path/1028945?sid=4a4b7cef-fe1b-4109-a308-5f8e3e317138&amp;amp;sid_i=0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 21:33:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-3-way-handshake-success-telnet-but-data-doesnt-flow-through/m-p/485939#M104559</guid>
      <dc:creator>A_Astardzhiev</dc:creator>
      <dc:date>2022-05-09T21:33:37Z</dc:date>
    </item>
  </channel>
</rss>

