<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zone Protection - Reject Non-SYN TCP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reject-non-syn-tcp/m-p/23241#M16938</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I hope that PA uses "best match" which would mean that zone setting overrules the global setting (which I guess is confirmed by the zone protection who has not only yes/no but also global as a valid setting).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your case that non syn packets are allowed when they arrive at the specific zone.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Jun 2012 07:24:41 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-06-27T07:24:41Z</dc:date>
    <item>
      <title>Zone Protection - Reject Non-SYN TCP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reject-non-syn-tcp/m-p/23238#M16935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everyone!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've configured a zone protection profile with SYN Flood protection and SYN Cookies enabled. In the same profile I've set the option "Reject Non-SYN TCP" to "no". I've applied this profile to my untrust zone and run a commit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I run the CLI command &lt;EM&gt;show session info&lt;/EM&gt; i noticed that under session setup TCP - reject non-SYN first packet is set to True. Why is there a mismatch between the GUI and the CLI, and which one can I trust (I usually trust the CLI)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exerpt from CLI command &lt;EM&gt;show session info&lt;/EM&gt;:&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Session setup&lt;/P&gt;&lt;P&gt;&amp;nbsp; TCP - reject non-SYN first packet:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; True&lt;/P&gt;&lt;P&gt;&amp;nbsp; Hardware session offloading:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; True&lt;/P&gt;&lt;P&gt;&amp;nbsp; IPv6 firewalling:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; False&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sturla&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 06:27:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reject-non-syn-tcp/m-p/23238#M16935</guid>
      <dc:creator>sturla</dc:creator>
      <dc:date>2012-06-27T06:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - Reject Non-SYN TCP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reject-non-syn-tcp/m-p/23239#M16936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Export the running-config.xml and verify it there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;network profiles -&amp;gt; zone-protection-profile can contain:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tcp-reject-non-syn {global | no | yes}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;+ tcp-reject-non-syn — Reject non-SYN TCP packet for session setup&lt;/P&gt;&lt;P&gt;global — Use global setting&lt;/P&gt;&lt;P&gt;no — Accept non-SYN TCP&lt;/P&gt;&lt;P&gt;yes — Reject non-SYN TCP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The global setting is found in deviceconfig -&amp;gt; session:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tcp-reject-non-syn {no | yes}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;+ tcp-reject-non-syn — Reject non-SYN TCP packet for session setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and is handled by the "set session" command (if you are in CLI).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My guess is that "show session info" will display the global value and not your custom zone-specific setting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 06:42:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reject-non-syn-tcp/m-p/23239#M16936</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-06-27T06:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - Reject Non-SYN TCP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reject-non-syn-tcp/m-p/23240#M16937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If global setting is set to reject non syn packets and zone setting is set to allow non syn packets then which setting comes into effect ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 06:49:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reject-non-syn-tcp/m-p/23240#M16937</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-06-27T06:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - Reject Non-SYN TCP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reject-non-syn-tcp/m-p/23241#M16938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I hope that PA uses "best match" which would mean that zone setting overrules the global setting (which I guess is confirmed by the zone protection who has not only yes/no but also global as a valid setting).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your case that non syn packets are allowed when they arrive at the specific zone.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 07:24:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reject-non-syn-tcp/m-p/23241#M16938</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-06-27T07:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - Reject Non-SYN TCP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reject-non-syn-tcp/m-p/23242#M16939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your answer!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was not aware of a global setting for this. Where is the global setting for this located in the GUI? I'm not able to find it.&lt;/P&gt;&lt;P&gt;/S&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 08:07:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reject-non-syn-tcp/m-p/23242#M16939</guid>
      <dc:creator>sturla</dc:creator>
      <dc:date>2012-06-27T08:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - Reject Non-SYN TCP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reject-non-syn-tcp/m-p/23243#M16940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seems like it isnt available through GUI, according to admin guide 4.1 (looking at zone protection settings):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Global—Use system-wide setting that is assigned through the CLI.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 08:47:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-reject-non-syn-tcp/m-p/23243#M16940</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-06-27T08:47:28Z</dc:date>
    </item>
  </channel>
</rss>

