<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP-RST-FROM-CLIENT and TCS-RST-FROM-SERVER in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/565389#M114342</link>
    <description>&lt;P&gt;Does anyone really have a solution for this? So far, I have not seen any concrete solution. I put a device that communicates with an online server with no problem.&amp;nbsp; I insert the PA FW between that line of traffic, all of a sudden, we get tcp-rst from the server or vice-versa. What causes the problem and do we solve it is what everyone is seeking as a guide or repsonse. I think most technical people understand how tcp works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Nov 2023 16:07:53 GMT</pubDate>
    <dc:creator>ATECH</dc:creator>
    <dc:date>2023-11-13T16:07:53Z</dc:date>
    <item>
      <title>TCP-RST-FROM-CLIENT and TCS-RST-FROM-SERVER</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/346864#M86556</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As captioned in subject, would like to get some clarity on the &lt;STRONG&gt;tcp-rst-from-client&lt;/STRONG&gt; and &lt;STRONG&gt;tcp-rst-from-server &lt;/STRONG&gt;session end reasons on monitor traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even with successful communication between User's source IP and Dst IP, we are seeing&amp;nbsp;&lt;STRONG&gt;tcp-rst-from-client&lt;/STRONG&gt;&amp;nbsp;, which is raising some queries for me personally. Are both these reasons are normal , If not, then how to distinguish whether this reason is due to some communication problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Googled this also, but probably i am not able to reach the most relevant available information article. Thought better to take advise here on community.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 13:38:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/346864#M86556</guid>
      <dc:creator>Jimmy20</dc:creator>
      <dc:date>2020-09-04T13:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: TCP-RST-FROM-CLIENT and TCS-RST-FROM-SERVER</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/346891#M86559</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/144686"&gt;@Jimmy20&lt;/a&gt;, Normally these are the session end reasons. Now depending on the type like TCP-RST-FROM-CLIENT or TCP-RST-FROM-SERVER, it tells you who is sending TCP reset and session gets terminated. It does not mean that firewall is blocking the traffic. It means session got created between client-to-server but it got terminated from any of the end (client or server) and depending on who sent the TCP reset, you will see session end result under traffic logs. And once the session is terminated, it is getting reestablish with new traffic request and&amp;nbsp; thats why not seeing as such problems with the traffic flow.&lt;/P&gt;&lt;P&gt;If you want to know more about it, you can take packet capture on the firewall.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 14:12:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/346891#M86559</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-09-04T14:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: TCP-RST-FROM-CLIENT and TCS-RST-FROM-SERVER</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/346910#M86560</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L6-Presenter lia-component-message-view-widget-author-username"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521" target="_self"&gt;&lt;SPAN class=""&gt;SutareMayur,&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L6-Presenter lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Thanks for reply, What you replied is known to me. But i was searching for - '"Can we consider communication between source and dest if session end reason is&amp;nbsp;TCP-RST-FROM-CLIENT or TCS-RST-FROM-SERVER , bçoz as i mentioned in initial post i can see&amp;nbsp;TCP-RST-FROM-CLIENT for a succesful transaction even, However&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L6-Presenter lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;it shuld&amp;nbsp; be '"tcp-fin" or something except&amp;nbsp;&amp;nbsp;TCP-RST-FROM-CLIENT. if it is reseted by client or server why it is considered as sucessfull.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 15:51:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/346910#M86560</guid>
      <dc:creator>Jimmy20</dc:creator>
      <dc:date>2020-09-04T15:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: TCP-RST-FROM-CLIENT and TCS-RST-FROM-SERVER</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/346988#M86567</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/144686"&gt;@Jimmy20&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TCP RST flag may be sent by either of the end (client/server) because of fatal error. So if you take example of&amp;nbsp; TCP RST flag,&amp;nbsp; client trying to connect server on port which is unavailable at that moment on the server.&lt;/P&gt;&lt;P&gt;Now for successful connections without any issues from either of the end, you will see TCP-FIN flag.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now in case, for a moment particular server went unavailable then RST will happen and user even don't&amp;nbsp; know about this situation and initiated new request again And at that time may be that server became available and after that connection was successful. So In this&amp;nbsp; case, if you compare sessions, you will find RST for first session and 2nd should be TCP-FIN. So like this, there are multiple situations where you will see such logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 18:30:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/346988#M86567</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-09-04T18:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: TCP-RST-FROM-CLIENT and TCS-RST-FROM-SERVER</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/385495#M90156</link>
      <description>&lt;P&gt;Just wanted to let you know that I have created a blog for this:&lt;/P&gt;
&lt;P&gt;&lt;A id="link_3" class="page-link lia-link-navigation lia-custom-event" href="https://live.paloaltonetworks.com/t5/blogs/dotw-tcp-resets-from-client-and-server-aka-tcp-rst-from-client/ba-p/378526" target="_blank"&gt;DOTW: TCP Resets from Client and Server aka TCP-RST-FROM-Client&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 20:47:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/385495#M90156</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2021-02-11T20:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: TCP-RST-FROM-CLIENT and TCS-RST-FROM-SERVER</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/565389#M114342</link>
      <description>&lt;P&gt;Does anyone really have a solution for this? So far, I have not seen any concrete solution. I put a device that communicates with an online server with no problem.&amp;nbsp; I insert the PA FW between that line of traffic, all of a sudden, we get tcp-rst from the server or vice-versa. What causes the problem and do we solve it is what everyone is seeking as a guide or repsonse. I think most technical people understand how tcp works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 16:07:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/565389#M114342</guid>
      <dc:creator>ATECH</dc:creator>
      <dc:date>2023-11-13T16:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: TCP-RST-FROM-CLIENT and TCS-RST-FROM-SERVER</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/565444#M114353</link>
      <description>&lt;P&gt;Palo don't send those resets. Palo only observes that either side sent TCP RST to close connection.&lt;/P&gt;
&lt;P&gt;To your claim "&lt;SPAN&gt;I think most technical people understand how tcp works" I would reply that "except developers who think that it is easier to end session with TCP RST compared to 4way handshake" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 01:30:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/565444#M114353</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-14T01:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: TCP-RST-FROM-CLIENT and TCS-RST-FROM-SERVER</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/1247657#M125977</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6645"&gt;@ATECH&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The TCP RST flag can be transmitted by either endpoint (client or server) due to a critical error. For instance, consider the scenario where a client attempts to connect to a server on a port that is currently unavailable on the server.&lt;/P&gt;
&lt;P&gt;In contrast, for successful connections without any complications from either endpoint, the TCP-FIN flag will be observed.&lt;/P&gt;
&lt;P&gt;However, if a particular server becomes unavailable for a brief period, an RST will occur, and the user may be unaware of this situation, subsequently initiating a new request. At that moment, the server may have become available again, leading to a successful connection. In this scenario, if you compare the sessions, you will observe an RST for the first session and a TCP-FIN for the second. Thus, there are numerous situations in which such logs can be encountered.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Feb 2026 11:50:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-rst-from-client-and-tcs-rst-from-server/m-p/1247657#M125977</guid>
      <dc:creator>charlessilver112</dc:creator>
      <dc:date>2026-02-07T11:50:11Z</dc:date>
    </item>
  </channel>
</rss>

