<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to log out-of-state dropped packets ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-log-out-of-state-dropped-packets/m-p/33262#M24365</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Last week we've replaced an FWSM cluster with a PA-5050 cluster. After the migration there were intermittent problems with our CRM application. Allthough we had no used applications but only services in our security policy, the PAN was applying the predefined siebel-crm application time-out of 60 seconds.After increasing the app timeout to 300 seconds the issue was solved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only way to find this out was by taking multiple traces at client and server side, finally we saw the dropped packets in the PAN drop-stage packet-capture. We lost almost a day.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some questions regarding the above :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1° How does it come that dropped out-of-state packets&amp;nbsp; ( in this case of a timed-out session) are not logged ? &lt;BR /&gt;All other firewalls I know of are logging these kind of dropped packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2° How can we see the timed-out sessions ? ( in particular application-timeouts ) There must be a counter somewhere I guess.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be more precise, the dropped out-of-state packets in question were FIN-ACK's from the client to the server.&lt;/P&gt;&lt;P&gt;Since the session was already timed-out on the PAN, the PAN was silently dropping these packets, with any visible trace in the logfiles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks ,&lt;/P&gt;&lt;P&gt;Bart&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Sep 2011 06:52:43 GMT</pubDate>
    <dc:creator>Bart_Jocque</dc:creator>
    <dc:date>2011-09-26T06:52:43Z</dc:date>
    <item>
      <title>How to log out-of-state dropped packets ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-log-out-of-state-dropped-packets/m-p/33262#M24365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Last week we've replaced an FWSM cluster with a PA-5050 cluster. After the migration there were intermittent problems with our CRM application. Allthough we had no used applications but only services in our security policy, the PAN was applying the predefined siebel-crm application time-out of 60 seconds.After increasing the app timeout to 300 seconds the issue was solved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only way to find this out was by taking multiple traces at client and server side, finally we saw the dropped packets in the PAN drop-stage packet-capture. We lost almost a day.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some questions regarding the above :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1° How does it come that dropped out-of-state packets&amp;nbsp; ( in this case of a timed-out session) are not logged ? &lt;BR /&gt;All other firewalls I know of are logging these kind of dropped packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2° How can we see the timed-out sessions ? ( in particular application-timeouts ) There must be a counter somewhere I guess.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be more precise, the dropped out-of-state packets in question were FIN-ACK's from the client to the server.&lt;/P&gt;&lt;P&gt;Since the session was already timed-out on the PAN, the PAN was silently dropping these packets, with any visible trace in the logfiles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks ,&lt;/P&gt;&lt;P&gt;Bart&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2011 06:52:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-log-out-of-state-dropped-packets/m-p/33262#M24365</guid>
      <dc:creator>Bart_Jocque</dc:creator>
      <dc:date>2011-09-26T06:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to log out-of-state dropped packets ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-log-out-of-state-dropped-packets/m-p/33263#M24366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bart,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you try doing a "show counter global | match drop" and check to see which drop counters were increasing?&amp;nbsp; This is one of my favorite troubleshooting commands.&amp;nbsp; From there you can also filter the counters to narrow down whether that is the issue for the flows you are investigting.&amp;nbsp; The counter names are typically pretty self explanitory, though I'm not sure how they would show up in this case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's my cheat sheet:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Set a filter to control what traffic is counted &lt;UL&gt;&lt;LI&gt; debug dataplane packet-diag set filter match &amp;lt;criteria&amp;gt; &lt;/LI&gt;&lt;LI&gt; debug dataplane packet-diag set filter on&amp;nbsp; &lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt; Show the drop counters (absolute or relative to last time command was run) &lt;UL&gt;&lt;LI&gt; show counter global packet-filter yes | match drop &lt;/LI&gt;&lt;LI&gt; show counter global filter severity drop packet-filter yes delta yes&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2011 23:50:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-log-out-of-state-dropped-packets/m-p/33263#M24366</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-09-26T23:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to log out-of-state dropped packets ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-log-out-of-state-dropped-packets/m-p/33264#M24367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kelly,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many many thanks !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Sep 2011 07:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-log-out-of-state-dropped-packets/m-p/33264#M24367</guid>
      <dc:creator>Bart_Jocque</dc:creator>
      <dc:date>2011-09-27T07:12:43Z</dc:date>
    </item>
  </channel>
</rss>

