<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to find the reason for packet drop in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-find-the-reason-for-packet-drop/m-p/587160#M117153</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In our Palo Alto the traffic is allowed on the firewall but it is not working. When we did packet capture we found that return traffic in drop stage. To find the cause of the packet drop I have set the filter using&amp;nbsp;&lt;SPAN&gt;&lt;SPAN class="ui-provider ee bjj bjk bjl bjm bjn bjo bjp bjq bjr bjs bjt bju bjv bjw bjx bjy bjz bka bkb bkc bkd bke bkf bkg bkh bki bkj bkk bkl bkm bkn bko bkp bkq"&gt;'Manage Filters' in GUI then use the following command.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider ee bjj bjk bjl bjm bjn bjo bjp bjq bjr bjs bjt bju bjv bjw bjx bjy bjz bka bkb bkc bkd bke bkf bkg bkh bki bkj bkk bkl bkm bkn bko bkp bkq"&gt;debug dataplane packet-diag set filter on&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider ee bjj bjk bjl bjm bjn bjo bjp bjq bjr bjs bjt bju bjv bjw bjx bjy bjz bka bkb bkc bkd bke bkf bkg bkh bki bkj bkk bkl bkm bkn bko bkp bkq"&gt;but I am unable to see any output in the command - &amp;nbsp;show counter global filter packet-filter yes delta yes severity drop&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider ee bjj bjk bjl bjm bjn bjo bjp bjq bjr bjs bjt bju bjv bjw bjx bjy bjz bka bkb bkc bkd bke bkf bkg bkh bki bkj bkk bkl bkm bkn bko bkp bkq"&gt;What should be the approach to find the cause of packet drop by firewall.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 May 2024 20:10:46 GMT</pubDate>
    <dc:creator>network_020</dc:creator>
    <dc:date>2024-05-17T20:10:46Z</dc:date>
    <item>
      <title>Unable to find the reason for packet drop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-find-the-reason-for-packet-drop/m-p/587160#M117153</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In our Palo Alto the traffic is allowed on the firewall but it is not working. When we did packet capture we found that return traffic in drop stage. To find the cause of the packet drop I have set the filter using&amp;nbsp;&lt;SPAN&gt;&lt;SPAN class="ui-provider ee bjj bjk bjl bjm bjn bjo bjp bjq bjr bjs bjt bju bjv bjw bjx bjy bjz bka bkb bkc bkd bke bkf bkg bkh bki bkj bkk bkl bkm bkn bko bkp bkq"&gt;'Manage Filters' in GUI then use the following command.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider ee bjj bjk bjl bjm bjn bjo bjp bjq bjr bjs bjt bju bjv bjw bjx bjy bjz bka bkb bkc bkd bke bkf bkg bkh bki bkj bkk bkl bkm bkn bko bkp bkq"&gt;debug dataplane packet-diag set filter on&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider ee bjj bjk bjl bjm bjn bjo bjp bjq bjr bjs bjt bju bjv bjw bjx bjy bjz bka bkb bkc bkd bke bkf bkg bkh bki bkj bkk bkl bkm bkn bko bkp bkq"&gt;but I am unable to see any output in the command - &amp;nbsp;show counter global filter packet-filter yes delta yes severity drop&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider ee bjj bjk bjl bjm bjn bjo bjp bjq bjr bjs bjt bju bjv bjw bjx bjy bjz bka bkb bkc bkd bke bkf bkg bkh bki bkj bkk bkl bkm bkn bko bkp bkq"&gt;What should be the approach to find the cause of packet drop by firewall.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2024 20:10:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-find-the-reason-for-packet-drop/m-p/587160#M117153</guid>
      <dc:creator>network_020</dc:creator>
      <dc:date>2024-05-17T20:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to find the reason for packet drop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-find-the-reason-for-packet-drop/m-p/587346#M117179</link>
      <description>&lt;P&gt;I would recommend not use "severity drop" on your command.&lt;/P&gt;
&lt;P&gt;Here is one example, as described, there are some counter which is warning with packet drops&lt;/P&gt;
&lt;P&gt;====&lt;/P&gt;
&lt;P&gt;&amp;gt; show counter global name tcp_drop_out_of_wnd&lt;/P&gt;
&lt;P&gt;Name: tcp_drop_out_of_wnd&lt;BR /&gt;Value: 0&lt;BR /&gt;Severity: Warning&lt;BR /&gt;Category: tcp&lt;BR /&gt;Aspect: resource&lt;BR /&gt;Description: out-of-window packets dropped&lt;/P&gt;
&lt;P&gt;====&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 01:06:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-find-the-reason-for-packet-drop/m-p/587346#M117179</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2024-05-21T01:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to find the reason for packet drop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-find-the-reason-for-packet-drop/m-p/587473#M117211</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Check the unified logs in the gui. This should tell you everything you need to know if/where the traffic is getting dropped/blocked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarsds,&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 22:01:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-find-the-reason-for-packet-drop/m-p/587473#M117211</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-05-21T22:01:28Z</dc:date>
    </item>
  </channel>
</rss>

