<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto and Duplicate Packets in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-and-duplicate-packets/m-p/41389#M30422</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think thats expected behaviour regarding volume counting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean thats what I would expect it to do if the PA box were in inline mode (lets say vwire).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCP session 1 sends packets (lets say 100 bytes each): 1, 2, 3, 4, 5, 6 = 600 bytes in total and 6 packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCP session 2 sends packets (duplicates): 1, 1, 2, 2, 3, 3 = also 600 bytes in total and 6 packets which has pass the unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise I think you would also end up with broken stats like regarding bandwidth utilization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets say someone tries to DDoS your setup and send the very same packet 1953125 of them per second (64 byte packets). This would fill up your 1Gbit/s link and I would expect the PA device to show just this that the bandwidth consumed is 1Gbit/s and not 512 bit/s.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Nov 2012 08:59:42 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-11-16T08:59:42Z</dc:date>
    <item>
      <title>Palo Alto and Duplicate Packets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-and-duplicate-packets/m-p/41388#M30421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How does Palo Alto handle Duplicate Packets? In our scenario, we have one interface running in TAP mode.&amp;nbsp; We are using a port aggregator to shove spans/taps from multiple locations in our network to this one TAP mode interface.&amp;nbsp; Doing this, the PA should be receiving duplicate packets when the stream of data flows past 2(or more) of the spans/taps that we have in place.&amp;nbsp; Looking at the logs, the PA doesn't look like it creates duplicate log entries, but I have a feeling it may be taking those duplicate packets and adding the "Bytes" and "Packets" data ON TOP of the original session data in the traffic log.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2012 16:50:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-and-duplicate-packets/m-p/41388#M30421</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2012-11-15T16:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto and Duplicate Packets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-and-duplicate-packets/m-p/41389#M30422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think thats expected behaviour regarding volume counting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean thats what I would expect it to do if the PA box were in inline mode (lets say vwire).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCP session 1 sends packets (lets say 100 bytes each): 1, 2, 3, 4, 5, 6 = 600 bytes in total and 6 packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCP session 2 sends packets (duplicates): 1, 1, 2, 2, 3, 3 = also 600 bytes in total and 6 packets which has pass the unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise I think you would also end up with broken stats like regarding bandwidth utilization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets say someone tries to DDoS your setup and send the very same packet 1953125 of them per second (64 byte packets). This would fill up your 1Gbit/s link and I would expect the PA device to show just this that the bandwidth consumed is 1Gbit/s and not 512 bit/s.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Nov 2012 08:59:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-and-duplicate-packets/m-p/41389#M30422</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-11-16T08:59:42Z</dc:date>
    </item>
  </channel>
</rss>

