<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Non logging issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31781#M23244</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you mean that not logging issue happens for just that 1 client ?and also to just 1 ip ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Jun 2013 14:26:57 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-06-18T14:26:57Z</dc:date>
    <item>
      <title>Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31778#M23241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK a little background first I'm running 4.1 on a 5050 pair in A/P.&amp;nbsp; I have a server that is trying to do 80 and 443 out to a specific address and we have some logging wierdness going on.&amp;nbsp; If we don't have a rule in place allowing the traffic it will not show up with a log entry.&amp;nbsp; If I do a packet capture I see it in the receive stage but not any other stage.&amp;nbsp; At the very least I would expect to see it in the drop stage, also, it isn't showing up in any of the logs or being sent to our syslog server.&amp;nbsp; If I have a rule in place allowing the traffic it will show up in the logs.&amp;nbsp; I have verified that my any,any,deny at the end of the ruleset is logging at both the start and end of the session and I'm still not seeing anything.&amp;nbsp; We are using the Anti-Spyware and Vulnerability protection but it currently is only setup in alert mode so it shouldn't be blocking.&amp;nbsp; Also, I have tried connecting with different ports just to make sure it wasn't a specific application issue and that has no effect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is appreciated.&lt;/P&gt;&lt;P&gt;Kris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 14:09:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31778#M23241</guid>
      <dc:creator>Brinkman</dc:creator>
      <dc:date>2013-06-18T14:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31779#M23242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have security rules for intrazones&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 14:15:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31779#M23242</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-18T14:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31780#M23243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I do not for this zone, but the connection is going from a trusted zone IP to an untrusted zone IP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 14:20:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31780#M23243</guid>
      <dc:creator>Brinkman</dc:creator>
      <dc:date>2013-06-18T14:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31781#M23244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you mean that not logging issue happens for just that 1 client ?and also to just 1 ip ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 14:26:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31781#M23244</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-18T14:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31782#M23245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mean no logs neither in Monitor/Traffic nor in session browser ?&lt;/P&gt;&lt;P&gt;no routing issue ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;v.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 15:25:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31782#M23245</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-06-18T15:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31783#M23246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It will happen from that client to any IP on any port.&amp;nbsp; What it looks like is if that client sends out a SYN and a SYN-ACK never comes back the firewall doesn't log the connection, even if it passed it.&amp;nbsp; As soon as it gets the SYN-ACK back it logs it.&amp;nbsp; Am I misunderstanding the way this should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I don't see anything in monitor/traffic nor the session browser until the SYN-ACK is received back, if I never receive a SYN-ACK I never see an entry.&amp;nbsp; No there aren't any routing issues because in the beginning the one connection was not allowed at the distant end but as soon as they put the access in it came up fine and starting working.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 16:20:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31783#M23246</guid>
      <dc:creator>Brinkman</dc:creator>
      <dc:date>2013-06-18T16:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31784#M23247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you have to see incomplete logs even you send syn.&lt;/P&gt;&lt;P&gt;Can you try to delete all logs and restrart log server ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug software restart log-receiver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 16:27:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31784#M23247</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-18T16:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31785#M23248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK I tried that and no change.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 16:56:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31785#M23248</guid>
      <dc:creator>Brinkman</dc:creator>
      <dc:date>2013-06-18T16:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31786#M23249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The implicit deny rule on a PAN will not generate log entries.&lt;/P&gt;&lt;P&gt;You would need to have an explicit deny rule with logging enabled to see the traffic that is denied.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 17:01:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31786#M23249</guid>
      <dc:creator>jcostello</dc:creator>
      <dc:date>2013-06-18T17:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31787#M23250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yep that's what I have and it's set to log at the start and end of the session.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 17:02:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31787#M23250</guid>
      <dc:creator>Brinkman</dc:creator>
      <dc:date>2013-06-18T17:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31788#M23251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you should better open a case.&lt;/P&gt;&lt;P&gt;should take 2 captures&lt;/P&gt;&lt;P&gt;1- at client interface&lt;/P&gt;&lt;P&gt;2- at Paloalto interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;filter and look if client sends and paloalto receives support will investigate that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 17:04:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31788#M23251</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-18T17:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31789#M23252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The deny all logging can put a strain on the log-receiver (in my experience)&lt;/P&gt;&lt;P&gt;From the CLI try the following command&lt;/P&gt;&lt;P&gt;debug log-receiver statistics&lt;/P&gt;&lt;P&gt;look for entries under Logs discarded (queue full)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 17:06:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31789#M23252</guid>
      <dc:creator>jcostello</dc:creator>
      <dc:date>2013-06-18T17:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31790#M23253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've already verified that the client is sending the packet and I know PA is receiving it.&amp;nbsp; Is this just a case of how the underlying system works where it won't create any log entry until the 3 way handshake is complete.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 17:07:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31790#M23253</guid>
      <dc:creator>Brinkman</dc:creator>
      <dc:date>2013-06-18T17:07:12Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31791#M23254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There aren't any that showed they were discarded.&amp;nbsp; The rate is 112/sec.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 17:09:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31791#M23254</guid>
      <dc:creator>Brinkman</dc:creator>
      <dc:date>2013-06-18T17:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31792#M23255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With the settings of start and end on the logging of all traffic on that deny rule, you will fill the logging queue on the box and it will not be able to process all of the logs.&lt;/P&gt;&lt;P&gt;With something that is denied, it won't wait for the three way handshake to log an entry if logging functioning correctly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 17:10:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31792#M23255</guid>
      <dc:creator>jcostello</dc:creator>
      <dc:date>2013-06-18T17:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31793#M23256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you seeing incomplete traffic associated to another rule?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 17:11:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31793#M23256</guid>
      <dc:creator>jcostello</dc:creator>
      <dc:date>2013-06-18T17:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31794#M23257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was seeing incompletes in the logs with the connection before the distant end opened it up.&amp;nbsp; I'm currently seeing it from another client IP here that I know the other end has yet to add to their firewalls.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 17:14:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31794#M23257</guid>
      <dc:creator>Brinkman</dc:creator>
      <dc:date>2013-06-18T17:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31795#M23258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;are you seeing sessions for the traffic in the session tables?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 17:16:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31795#M23258</guid>
      <dc:creator>jcostello</dc:creator>
      <dc:date>2013-06-18T17:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31796#M23259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt;debug log-receiver statistics &lt;/P&gt;&lt;P&gt;what's your output&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 17:27:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31796#M23259</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-18T17:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Non logging issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31797#M23260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I am, they show up as below(IPs sanitized).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE height="48" style="width: 1220px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;1245412 undecided&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;ACTIVE&amp;nbsp; FLOW&amp;nbsp;&amp;nbsp; 144.100.71.22[60373]/ProdApp/6&amp;nbsp; ("SRC IP"[60373])&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;vsys2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;"DST IP"[8005]/Deep Dark Woods&amp;nbsp; (8.8.8.8[8005])&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 17:27:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/non-logging-issue/m-p/31797#M23260</guid>
      <dc:creator>Brinkman</dc:creator>
      <dc:date>2013-06-18T17:27:37Z</dc:date>
    </item>
  </channel>
</rss>

