<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check TCP sequense number in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/check-tcp-sequense-number/m-p/18325#M13358</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it has. The new command is:&lt;/P&gt;&lt;P&gt;# set deviceconfig setting tcp asymmetric-path bypass&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You'll need to follow that with a commit for it to take effect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Greg &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Dec 2012 17:30:53 GMT</pubDate>
    <dc:creator>gwesson</dc:creator>
    <dc:date>2012-12-12T17:30:53Z</dc:date>
    <item>
      <title>Check TCP sequense number</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-tcp-sequense-number/m-p/18321#M13354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if PA box could default check ﻿﻿﻿﻿TCP sequense number ... have CLI cmd to ﻿tigger this checking&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff Jin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ﻿&lt;BR /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Oct 2011 12:26:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-tcp-sequense-number/m-p/18321#M13354</guid>
      <dc:creator>JeffJin</dc:creator>
      <dc:date>2011-10-14T12:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Check TCP sequense number</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-tcp-sequense-number/m-p/18322#M13355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure if this is what you're looking for but here are some tcp settings options. This is through the configure mode to make it persistent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#set deviceconfig setting tcp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bypass-exceed-oo-queue&amp;nbsp;&amp;nbsp; whether to skip inspection of session if out-of-order packets limit is exceeded&lt;/P&gt;&lt;P&gt;drop-out-of-wnd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; drop/allow out of window packets, also control enable/disable TCP sequence number check for FIN/RST&lt;/P&gt;&lt;P&gt;favor-new-seg&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; whether to favor new segments when overlapping happens&lt;/P&gt;&lt;P&gt;out-of-sync&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; actions for out of sync tcp sessions (ACK is out of sync with TCP sliding window tracking)&lt;/P&gt;&lt;P&gt;urgent-data&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; clear urgent flag in TCP header &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Renato&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Oct 2011 13:54:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-tcp-sequense-number/m-p/18322#M13355</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2011-10-14T13:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Check TCP sequense number</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-tcp-sequense-number/m-p/18323#M13356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCP sequence number checking is enabled by default.You can turn it off if you wish using the command above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Oct 2011 15:08:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-tcp-sequense-number/m-p/18323#M13356</guid>
      <dc:creator>mrajdev</dc:creator>
      <dc:date>2011-10-14T15:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Check TCP sequense number</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-tcp-sequense-number/m-p/18324#M13357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I cannot find command for drop-out-of-wnd parametar in PAN-OS 4.1 and 5.0&lt;/P&gt;&lt;P&gt;Is this command changed?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 15:19:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-tcp-sequense-number/m-p/18324#M13357</guid>
      <dc:creator>igor_mamuzic</dc:creator>
      <dc:date>2012-12-12T15:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Check TCP sequense number</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-tcp-sequense-number/m-p/18325#M13358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it has. The new command is:&lt;/P&gt;&lt;P&gt;# set deviceconfig setting tcp asymmetric-path bypass&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You'll need to follow that with a commit for it to take effect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Greg &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 17:30:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-tcp-sequense-number/m-p/18325#M13358</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2012-12-12T17:30:53Z</dc:date>
    </item>
  </channel>
</rss>

