<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Identify If there was an allowed traffic from external suspicious IP in Panorama. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-if-there-was-an-allowed-traffic-from-external/m-p/547847#M111883</link>
    <description>&lt;P&gt;tcp-fin means the session was graciously ended, which means the initial connection was allowed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;a session that was blocked will have 'deny' or 'drop' in the action&amp;nbsp;&lt;/P&gt;
&lt;P&gt;'end' in the type is an allowed session, 'drop' or'deny' in the type is a blocked session&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you please provide a screenshot of what you're seeing?&lt;/P&gt;</description>
    <pubDate>Fri, 30 Jun 2023 07:15:07 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2023-06-30T07:15:07Z</dc:date>
    <item>
      <title>How to Identify If there was an allowed traffic from external suspicious IP in Panorama.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-if-there-was-an-allowed-traffic-from-external/m-p/547826#M111881</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;I'm a bit confused to understand the exact process. When monitoring the traffic from an external source ip (malicious one) and checking the logs in Pano see that session end reason was "tc-fin" and type was either "drop or end" with action being "allowed".&lt;/P&gt;
&lt;P&gt;Does this mean that , traffic has been blocked by the firewall or dropped by the firewall ?&lt;BR /&gt;In what cases, can I come to know if the traffic is allowed and a session made by a external suspicious ip towards internal IP&lt;/P&gt;
&lt;P&gt;Please help me in this clarification.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 02:54:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-if-there-was-an-allowed-traffic-from-external/m-p/547826#M111881</guid>
      <dc:creator>Naveen4025</dc:creator>
      <dc:date>2023-06-30T02:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to Identify If there was an allowed traffic from external suspicious IP in Panorama.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-if-there-was-an-allowed-traffic-from-external/m-p/547847#M111883</link>
      <description>&lt;P&gt;tcp-fin means the session was graciously ended, which means the initial connection was allowed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;a session that was blocked will have 'deny' or 'drop' in the action&amp;nbsp;&lt;/P&gt;
&lt;P&gt;'end' in the type is an allowed session, 'drop' or'deny' in the type is a blocked session&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you please provide a screenshot of what you're seeing?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 07:15:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-if-there-was-an-allowed-traffic-from-external/m-p/547847#M111883</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-06-30T07:15:07Z</dc:date>
    </item>
  </channel>
</rss>

