<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Traffic with no data (???) is denied in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-with-no-data-is-denied/m-p/24257#M17681</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PA 2050 device that is configured to allow specified traffic (multiple rules) and one rule that deny all other traffic (at the bottom).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When looking at the "Deny all" rule, I can see a lot of packets that should be allowed by specific rules above that are denied with no data (see screenshot bellow). Is it normal ? And what does it mean that some packets have no bytes received and no bytes sent ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Laurent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Dec 2011 11:10:29 GMT</pubDate>
    <dc:creator>ldormond</dc:creator>
    <dc:date>2011-12-09T11:10:29Z</dc:date>
    <item>
      <title>Traffic with no data (???) is denied</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-with-no-data-is-denied/m-p/24257#M17681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PA 2050 device that is configured to allow specified traffic (multiple rules) and one rule that deny all other traffic (at the bottom).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When looking at the "Deny all" rule, I can see a lot of packets that should be allowed by specific rules above that are denied with no data (see screenshot bellow). Is it normal ? And what does it mean that some packets have no bytes received and no bytes sent ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Laurent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Dec 2011 11:10:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-with-no-data-is-denied/m-p/24257#M17681</guid>
      <dc:creator>ldormond</dc:creator>
      <dc:date>2011-12-09T11:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic with no data (???) is denied</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-with-no-data-is-denied/m-p/24258#M17682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that is normal behavior.&amp;nbsp; Your PA2050 will drop all packets that do not meet your explicitly allowed rules.&amp;nbsp; Those packets may be the 1st SYN packet of a TCP handshake where the byte count is recorded as zero.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An explanation can be found here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/docs/DOC-1549"&gt;https://live.paloaltonetworks.com/docs/DOC-1549&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Dec 2011 11:41:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-with-no-data-is-denied/m-p/24258#M17682</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2011-12-13T11:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic with no data (???) is denied</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-with-no-data-is-denied/m-p/24259#M17683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answer, however if you look at the "application" collumn, you can see that this is not one of the three definition tht you provided me, but "unknown-tcp".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Furthermore, as I said in my first post above, there are explicit specific rules for this traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Laurent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Dec 2011 15:33:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-with-no-data-is-denied/m-p/24259#M17683</guid>
      <dc:creator>ldormond</dc:creator>
      <dc:date>2011-12-13T15:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic with no data (???) is denied</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-with-no-data-is-denied/m-p/24260#M17684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Laurent...My previous post was to answer the app=not-applicable where&amp;nbsp; the bytes=zero.&amp;nbsp; Unknown-tcp means the TCP traffic does not match any of our AppID signatures so the application is unknown.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tthe traffic must have matched the&amp;nbsp; TCP/UDP ports for your explicit rules but it does not match the&amp;nbsp; applications that you specifically defined in those rules.&amp;nbsp; However, the PA device does not have an app signature for the traffic and classified it as unknown-tcp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Dec 2011 17:59:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-with-no-data-is-denied/m-p/24260#M17684</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2011-12-13T17:59:24Z</dc:date>
    </item>
  </channel>
</rss>

