<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TCP SYN with data attack block by the firewall but increase the latency of data traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-syn-with-data-attack-block-by-the-firewall-but-increase-the/m-p/565776#M114385</link>
    <description>&lt;P&gt;Hi Support,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We recently notice have latency in our network , when we investigate found a lot threat logs from TCP SYN with data has been block by firewall as we have DDOS protection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question is below:&lt;/P&gt;
&lt;P&gt;1. does this attack affect the performance of the firewall resources?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Do we have a setting that can drop the threat without consume the resource of firewall?&lt;/P&gt;
&lt;P&gt;3.&amp;nbsp;In addition, is there a best case recommendation for securing untrust zones?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Wed, 15 Nov 2023 07:58:40 GMT</pubDate>
    <dc:creator>Fariq_Zaidi</dc:creator>
    <dc:date>2023-11-15T07:58:40Z</dc:date>
    <item>
      <title>TCP SYN with data attack block by the firewall but increase the latency of data traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-syn-with-data-attack-block-by-the-firewall-but-increase-the/m-p/565776#M114385</link>
      <description>&lt;P&gt;Hi Support,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We recently notice have latency in our network , when we investigate found a lot threat logs from TCP SYN with data has been block by firewall as we have DDOS protection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question is below:&lt;/P&gt;
&lt;P&gt;1. does this attack affect the performance of the firewall resources?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Do we have a setting that can drop the threat without consume the resource of firewall?&lt;/P&gt;
&lt;P&gt;3.&amp;nbsp;In addition, is there a best case recommendation for securing untrust zones?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 07:58:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-syn-with-data-attack-block-by-the-firewall-but-increase-the/m-p/565776#M114385</guid>
      <dc:creator>Fariq_Zaidi</dc:creator>
      <dc:date>2023-11-15T07:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: TCP SYN with data attack block by the firewall but increase the latency of data traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-syn-with-data-attack-block-by-the-firewall-but-increase-the/m-p/565799#M114389</link>
      <description>&lt;P&gt;1. It should not in and by itself, unless you are receiving so many of these packets it could constitute a DoS attack. in your case there doesn't seem to be an enormous amount&lt;/P&gt;
&lt;P&gt;2. Only if you are somehow able to isolate the source IP (or country, subnet, network,....) and block these sources directly. in your case, it all seems to originate from one source, so go ahead and block that if you don't know who or what this source is&lt;/P&gt;
&lt;P&gt;3. yes, take a look here:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/best-practices/dos-and-zone-protection-best-practices" target="_blank"&gt;https://docs.paloaltonetworks.com/best-practices/dos-and-zone-protection-best-practices&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in the ICMP screenshot, what does the start and end arrow indicate? just the start/end of latency or some other event?&lt;/P&gt;
&lt;P&gt;what does your '&lt;SPAN class="s1"&gt;&lt;FONT face="terminal,monaco"&gt;&amp;gt; show running resource-monitor&lt;/FONT&gt;' and '&lt;FONT face="terminal,monaco"&gt;&amp;gt; show session info&lt;/FONT&gt;' look like during that period?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="s1"&gt;do you have packet buffer protection enabled on your zones?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 11:06:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-syn-with-data-attack-block-by-the-firewall-but-increase-the/m-p/565799#M114389</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-11-15T11:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: TCP SYN with data attack block by the firewall but increase the latency of data traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-syn-with-data-attack-block-by-the-firewall-but-increase-the/m-p/565806#M114390</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/225107"&gt;@Fariq_Zaidi&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to clarify - the "TCP Syn with data" thread logs you see are not caused by the flood protection.&lt;/P&gt;
&lt;P&gt;Those logs indicate dropped TCP SYN packets that contain data, meaning source is trying to send some data before TCP-3way-handshake is completed. This setting is again controlled by Zone Protection profile, but not as flood protection, but TCP drop - &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/network/network-network-profiles/network-network-profiles-zone-protection/packet-based-attack-protection/tcp-drop" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/network/network-network-profiles/network-network-profiles-zone-protection/packet-based-attack-protection/tcp-drop&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClT5CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClT5CAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Having in mind that this is inbound traffic (from public source) it could be expected to see alot of such attempts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can check the count of dropped packets per zone with following command:&lt;/P&gt;
&lt;PRE class="ckeditor_codeblock"&gt;&amp;gt; show zone-protection zone untrust &lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 11:16:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-syn-with-data-attack-block-by-the-firewall-but-increase-the/m-p/565806#M114390</guid>
      <dc:creator>A_Astardzhiev</dc:creator>
      <dc:date>2023-11-15T11:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: TCP SYN with data attack block by the firewall but increase the latency of data traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-syn-with-data-attack-block-by-the-firewall-but-increase-the/m-p/565918#M114406</link>
      <description>&lt;P&gt;Hi Reaper,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the ICMP , showing the latency during the event happen and consist with the logs tcp sync with data has been drop.&amp;nbsp; That why we concern if this the cause the latency happen.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i attach the show running resource monitor and session info (Doc log)&amp;nbsp; and Yes we have enable the packet buffer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 04:13:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-syn-with-data-attack-block-by-the-firewall-but-increase-the/m-p/565918#M114406</guid>
      <dc:creator>Fariq_Zaidi</dc:creator>
      <dc:date>2023-11-16T04:13:36Z</dc:date>
    </item>
  </channel>
</rss>

