<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I see the session information (interface and ip details) of dropped packets because of ip spoof protection? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-the-session-information-interface-and-ip-details/m-p/28299#M20676</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Emma,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As well as my knowledge. if you are getting logs, use below command in putty show session all and show session id (.......). if you are not able to find out any thing then try to packet capture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope its help full.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 Apr 2015 05:05:13 GMT</pubDate>
    <dc:creator>Satish</dc:creator>
    <dc:date>2015-04-07T05:05:13Z</dc:date>
    <item>
      <title>How can I see the session information (interface and ip details) of dropped packets because of ip spoof protection?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-the-session-information-interface-and-ip-details/m-p/28298#M20675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Emma&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Apr 2015 21:56:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-the-session-information-interface-and-ip-details/m-p/28298#M20675</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2015-04-03T21:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see the session information (interface and ip details) of dropped packets because of ip spoof protection?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-the-session-information-interface-and-ip-details/m-p/28299#M20676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Emma,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As well as my knowledge. if you are getting logs, use below command in putty show session all and show session id (.......). if you are not able to find out any thing then try to packet capture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope its help full.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Apr 2015 05:05:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-the-session-information-interface-and-ip-details/m-p/28299#M20676</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2015-04-07T05:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see the session information (interface and ip details) of dropped packets because of ip spoof protection?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-the-session-information-interface-and-ip-details/m-p/28300#M20677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It logs as a counter on the interface,&amp;nbsp; show counter interface ethernet1/1.&lt;/P&gt;&lt;P&gt;For a detailed log you need to make a debug , follow this document &lt;A href="https://live.paloaltonetworks.com/docs/DOC-2542"&gt;Packet Based Troubleshooting - Configuring Packet Captures and Debug Logs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And you get something like that,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet received at ingress stage&lt;/P&gt;&lt;P&gt;Packet info: len 78 port 36 interface 269 vsys 1&lt;/P&gt;&lt;P&gt;&amp;nbsp; wqe index 266614 packet 0x0x8000000419b930e2&lt;/P&gt;&lt;P&gt;Packet decoded dump:&lt;/P&gt;&lt;P&gt;L2:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3c:08:f6:2d:e6:c0-&amp;gt;00:1b:17:00:02:24, VLAN 319 (0x8100 0x013f), type 0x0800&lt;/P&gt;&lt;P&gt;IP:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 213.4.35.220-&amp;gt;176.12.86.33, protocol 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; version 4, ihl 5, tos 0x00, len 60,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; id 605, frag_off 0x0000, ttl 122, checksum 16214&lt;/P&gt;&lt;P&gt;ICMP:&amp;nbsp;&amp;nbsp; type 8, code 0, checksum 19796, id 1, seq 7&lt;/P&gt;&lt;P&gt;Flow lookup, key word0 0x1000700100100 word1 0&lt;/P&gt;&lt;P&gt;No active flow found, enqueue to create session&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 213.4.35.220-&amp;gt;176.12.86.33, protocol 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; version 4, ihl 5, tos 0x00, len 60,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; id 606, frag_off 0x0000, ttl 122, checksum 16213&lt;/P&gt;&lt;P&gt;ICMP:&amp;nbsp;&amp;nbsp; type 8, code 0, checksum 19795, id 1, seq 8&lt;/P&gt;&lt;P&gt;Session setup: vsys 1&lt;/P&gt;&lt;P&gt;Packet dropped, IP spoof on interface ethernet1/21.319&lt;/P&gt;&lt;P&gt;Packet dropped, Session setup failed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Apr 2015 09:02:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-the-session-information-interface-and-ip-details/m-p/28300#M20677</guid>
      <dc:creator>GobiernodeNavarra</dc:creator>
      <dc:date>2015-04-07T09:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see the session information (interface and ip details) of dropped packets because of ip spoof protection?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-the-session-information-interface-and-ip-details/m-p/28301#M20678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Emma&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 00:54:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-the-session-information-interface-and-ip-details/m-p/28301#M20678</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2015-04-08T00:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see the session information (interface and ip details) of dropped packets because of ip spoof protection?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-the-session-information-interface-and-ip-details/m-p/28302#M20679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/27563"&gt;EmmaF&lt;/A&gt; what were you attempting to troubleshoot with the counters?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Apr 2015 00:15:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-the-session-information-interface-and-ip-details/m-p/28302#M20679</guid>
      <dc:creator>yarinbenado</dc:creator>
      <dc:date>2015-04-16T00:15:29Z</dc:date>
    </item>
  </channel>
</rss>

