<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with incomplete application in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-incomplete-application/m-p/32670#M23932</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jared,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think any session based firewall will &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; match the ICMP session based on ICMP Identifier, and the ICMP Sequence, to create the sessions. Hence, ideally there will be no default port for ICMP protocol, ultimately it will be "ANY".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 May 2014 02:02:11 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-05-13T02:02:11Z</dc:date>
    <item>
      <title>Problem with incomplete application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-incomplete-application/m-p/32667#M23929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the same problem with incomplete application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!Public zone! &amp;lt;====&amp;gt; PAN Firewall &amp;lt;====&amp;gt; INSIDE Firewall &amp;lt;-----&amp;gt; Server IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have nated Server IP to Public ip, and configure rule like the below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Name: (Ping) ; Src zone: (public); Src: (any); Dst zone: (any) ; Dst (any); Appliccation: (icmp, ping) ; Action: (ALLOW);&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I monitor traffic on PAN Firewall, I saw the traffic : Application is INCOMPLETE and action is ALLOW corresponding to the above "Ping" rule, and on my INSIDE Firewall, I also saw the traffic with the same public IP address to my server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I real don't know why is traffic pass into my INSIDE Firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me to deny all of incomplete traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks so much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2014 01:40:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-incomplete-application/m-p/32667#M23929</guid>
      <dc:creator>Register_Security</dc:creator>
      <dc:date>2014-05-13T01:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with incomplete application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-incomplete-application/m-p/32668#M23930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you permit ping on "any" service/port?&amp;nbsp; You should never use "any" for service/port on incoming rules.&amp;nbsp; You should only use "application-default" or a specified port.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2014 01:46:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-incomplete-application/m-p/32668#M23930</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2014-05-13T01:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with incomplete application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-incomplete-application/m-p/32669#M23931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's looking like a routing issue for me. Let me know if &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;i&lt;/SPAN&gt; understand it correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NAT Policy&lt;/STRONG&gt;&lt;STRONG&gt;:&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt;Source-zone=Public Zone, &lt;/P&gt;&lt;P&gt;Destination-zone= Public zone&lt;/P&gt;&lt;P&gt;Destination IP address: Public IP address&lt;/P&gt;&lt;P&gt;NAT destination translation= Private address of the Server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Security Policy:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Source-zone=Public Zone, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Destination-zone= Inside Zone &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;LAN)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Routing:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;a) Default gateway on PAN FW pointing towards Public zone ISP router.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;b) Server's Private IP address &amp;gt;&amp;gt;&amp;gt;pointing towards next hop to INSIDE FW&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2014 01:56:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-incomplete-application/m-p/32669#M23931</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-13T01:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with incomplete application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-incomplete-application/m-p/32670#M23932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jared,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think any session based firewall will &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; match the ICMP session based on ICMP Identifier, and the ICMP Sequence, to create the sessions. Hence, ideally there will be no default port for ICMP protocol, ultimately it will be "ANY".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2014 02:02:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-incomplete-application/m-p/32670#M23932</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-13T02:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with incomplete application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-incomplete-application/m-p/32671#M23933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Hulk, I wonder how I block all of incomplete application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi Jared,&lt;/P&gt;&lt;P&gt;I don't know where to configure application-default, please shared your idea in this case.&lt;/P&gt;&lt;P&gt;Thanks so much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2014 02:41:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-incomplete-application/m-p/32671#M23933</guid>
      <dc:creator>Register_Security</dc:creator>
      <dc:date>2014-05-13T02:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with incomplete application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-incomplete-application/m-p/32672#M23934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please post a screenshot of the security policy that permits ping. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2014 04:22:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-incomplete-application/m-p/32672#M23934</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2014-05-13T04:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with incomplete application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-incomplete-application/m-p/32673#M23935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;for me it's look like a routing issue or something avoid the return of ping echo.&lt;/P&gt;&lt;P&gt;if you you want to deny incomplete flow, you need to let pass the first packet icmp in your case and wait for an response that cross again the firewall to be define as ping application however if the response is not seen then the flow will be categorize as incomplete. &lt;/P&gt;&lt;P&gt;in fact you cannot block incomplete flaw in your case unless you deny ping application or if you resolve your routing issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2014 08:54:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-incomplete-application/m-p/32673#M23935</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2014-05-13T08:54:36Z</dc:date>
    </item>
  </channel>
</rss>

