<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PANOS 4.0.8 - How to determine cause of DROP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panos-4-0-8-how-to-determine-cause-of-drop/m-p/20553#M15011</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very basic configuration, an any any rule and a PAT rule for nat... trust and untrust zones and a default route and an internal summary route... what is happening is that from a traffic log perspective its being ALLOWED, from a NAT perspective I can see the session built with two flows for each direction successfully and they go ACTIVE. However, the return traffic never comes back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I found when trying to dump pcaps on the box is that the traffic post-nat shows up in the DROP stage. However nothing in the default logs shows any drops at all caused from a policy perspective (again policy is very boilerplate)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any way I can get more information on what is causing it to end up in DROP? additional dataplane debugs or something?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Josh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Dec 2011 22:37:18 GMT</pubDate>
    <dc:creator>joshstout</dc:creator>
    <dc:date>2011-12-29T22:37:18Z</dc:date>
    <item>
      <title>PANOS 4.0.8 - How to determine cause of DROP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-4-0-8-how-to-determine-cause-of-drop/m-p/20553#M15011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very basic configuration, an any any rule and a PAT rule for nat... trust and untrust zones and a default route and an internal summary route... what is happening is that from a traffic log perspective its being ALLOWED, from a NAT perspective I can see the session built with two flows for each direction successfully and they go ACTIVE. However, the return traffic never comes back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I found when trying to dump pcaps on the box is that the traffic post-nat shows up in the DROP stage. However nothing in the default logs shows any drops at all caused from a policy perspective (again policy is very boilerplate)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any way I can get more information on what is causing it to end up in DROP? additional dataplane debugs or something?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Josh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Dec 2011 22:37:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-4-0-8-how-to-determine-cause-of-drop/m-p/20553#M15011</guid>
      <dc:creator>joshstout</dc:creator>
      <dc:date>2011-12-29T22:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 4.0.8 - How to determine cause of DROP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-4-0-8-how-to-determine-cause-of-drop/m-p/20554#M15012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Drop counters are your friend:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; Set a filter to control what traffic is counted&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set filter match &amp;lt;criteria&amp;gt;&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set filter on &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Show the drop counters (absolute or relative to last time command was run) &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;show counter global packet-filter yes | match drop&lt;/P&gt;&lt;P&gt;show counter global filter severity drop packet-filter yes delta yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Dec 2011 23:07:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-4-0-8-how-to-determine-cause-of-drop/m-p/20554#M15012</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-12-29T23:07:36Z</dc:date>
    </item>
  </channel>
</rss>

