<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Seeing alot of drops on incoming interface to palo, trying to understand if this is normal. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/seeing-alot-of-drops-on-incoming-interface-to-palo-trying-to/m-p/1222055#M123414</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Along with the above advise, check the Unified logs, they will tell you why the traffic was blocked. If you are not hosting any services that require access from the internet, I would put in a DENY ALL incoming policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 26 Feb 2025 20:14:38 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2025-02-26T20:14:38Z</dc:date>
    <item>
      <title>Seeing alot of drops on incoming interface to palo, trying to understand if this is normal.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/seeing-alot-of-drops-on-incoming-interface-to-palo-trying-to/m-p/1221764#M123375</link>
      <description>&lt;P&gt;New to palo's.&amp;nbsp; I did search the topics and didnt find anything.&lt;/P&gt;
&lt;P&gt;Is it normal to see drop on the incoming interface to the firewall?&amp;nbsp; Are the drops caused by policy?&lt;/P&gt;
&lt;P&gt;Also, what is a drop from flow state check?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;packets dropped 69498455&lt;BR /&gt;packets dropped by flow state check 14915663&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 13:36:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/seeing-alot-of-drops-on-incoming-interface-to-palo-trying-to/m-p/1221764#M123375</guid>
      <dc:creator>D.Tamburin</dc:creator>
      <dc:date>2025-02-24T13:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: Seeing alot of drops on incoming interface to palo, trying to understand if this is normal.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/seeing-alot-of-drops-on-incoming-interface-to-palo-trying-to/m-p/1221835#M123388</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1156642319"&gt;@D.Tamburin&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can use packet capture and refer the global counter to verify the drops but it's cpu intensive, ensure that you are doing it during maintenance window to avoid any unforeseen.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVOCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVOCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008V0lCAE" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008V0lCAE&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 03:40:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/seeing-alot-of-drops-on-incoming-interface-to-palo-trying-to/m-p/1221835#M123388</guid>
      <dc:creator>mshekh</dc:creator>
      <dc:date>2025-02-25T03:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Seeing alot of drops on incoming interface to palo, trying to understand if this is normal.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/seeing-alot-of-drops-on-incoming-interface-to-palo-trying-to/m-p/1221892#M123393</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1156642319"&gt;@D.Tamburin&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Depending on your policy it can be expected behavior.&lt;/P&gt;
&lt;P&gt;Are you dropping or denying traffic ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The difference being that a drop is silent where you simply discard the packet and don't tell anyone about it.&amp;nbsp; A deny on the other hand sends a notification to the sender that something happened and their packet was rejected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are some posts that explain the difference between drop and deny:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/td-p/206863" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/td-p/206863&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/community-blogs/what-a-difference-a-deny-makes/ba-p/188811" target="_blank"&gt;https://live.paloaltonetworks.com/t5/community-blogs/what-a-difference-a-deny-makes/ba-p/188811&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/195187"&gt;@mshekh&lt;/a&gt;&amp;nbsp;explained you can also check with global counters and filter on the the 'drop' action.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here's a video explaining the process on how to go about troubleshooting silent drops on the firewall using global counters:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=lwYLS-dSq7I" target="_blank"&gt;https://www.youtube.com/watch?v=lwYLS-dSq7I&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 08:59:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/seeing-alot-of-drops-on-incoming-interface-to-palo-trying-to/m-p/1221892#M123393</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-02-25T08:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: Seeing alot of drops on incoming interface to palo, trying to understand if this is normal.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/seeing-alot-of-drops-on-incoming-interface-to-palo-trying-to/m-p/1222055#M123414</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Along with the above advise, check the Unified logs, they will tell you why the traffic was blocked. If you are not hosting any services that require access from the internet, I would put in a DENY ALL incoming policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 20:14:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/seeing-alot-of-drops-on-incoming-interface-to-palo-trying-to/m-p/1222055#M123414</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-02-26T20:14:38Z</dc:date>
    </item>
  </channel>
</rss>

