<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: incomplete in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41825#M30774</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="http://www.spapiestany.sk/"&gt;www.spapiestany.sk&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Sep 2012 20:13:28 GMT</pubDate>
    <dc:creator>oitspa</dc:creator>
    <dc:date>2012-09-27T20:13:28Z</dc:date>
    <item>
      <title>incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41820#M30769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I need urgent help. I dont know why but from one moment during the day is one website unreachable from our internal network(only this website). There was no change in configuration PA500, no changes in web server configuration. From outside of company is website reachable without problem. What I see in log is for this session application:incomplete.&lt;/P&gt;&lt;P&gt;I tried different computers, restart PA but no change, website still unreachable.&lt;/P&gt;&lt;P&gt;I dont know what I can do more. Please, help.&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 19:33:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41820#M30769</guid>
      <dc:creator>oitspa</dc:creator>
      <dc:date>2012-09-27T19:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41821#M30770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0px 0px 1em; color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #f8f8f8;"&gt;Incomplete means that either the three way tcp handshake did NOT complete or the three way tcp handshake did complete but there was no data after the handshake to identify the application. In other words that traffic you are seeing is not really an application.&lt;/P&gt;&lt;P style="margin: 0px 0px 1em; color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #f8f8f8;"&gt; So to explain a little clearer, if a client sends a server a syn and the paloalto device creates a session for that syn, but the server never sends a syn ack in response back to the client, then that session would be seen as incomplete.&lt;/P&gt;&lt;P style="margin: 0px 0px 1em; color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #f8f8f8;"&gt;Regards&lt;/P&gt;&lt;P style="margin: 0px 0px 1em; color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #f8f8f8;"&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 19:58:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41821#M30770</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-09-27T19:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41822#M30771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, it is clear but what can I do to solve it? We didnt change PA configuration and also web server configuration. Websites are from outside of company reachable?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 20:06:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41822#M30771</guid>
      <dc:creator>oitspa</dc:creator>
      <dc:date>2012-09-27T20:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41823#M30772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do packet captures on the firewall at the transmit, receive and drop stage.&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1653"&gt;https://live.paloaltonetworks.com/docs/DOC-1653&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You would be able to point out the root cause.&lt;/P&gt;&lt;P&gt;If the server is not responding most likely the receive/ transmit stage will send out SYN but not receive SYN-ACKs. &lt;/P&gt;&lt;P&gt;Let me know if that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 20:07:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41823#M30772</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-09-27T20:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41824#M30773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also check your threat logs if you are seeing any drops there. Which website is this ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 20:12:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41824#M30773</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-09-27T20:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41825#M30774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="http://www.spapiestany.sk/"&gt;www.spapiestany.sk&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 20:13:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41825#M30774</guid>
      <dc:creator>oitspa</dc:creator>
      <dc:date>2012-09-27T20:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41826#M30775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have tried accessing this behind my firewall. It is not blocked as virus or through URL filtering. In your case you might need to do a packet capture and see what is failing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 21:53:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41826#M30775</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-09-27T21:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41827#M30776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can also try and open up a security policy and specify the source IP of the test host pc.&lt;/P&gt;&lt;P&gt;Create an any any policy without any scan profiles as well. &lt;/P&gt;&lt;P&gt;Move the policy to the top.&lt;/P&gt;&lt;P&gt;If this works then review the existing policy to see if the application or scan profiles might be preventing the traffic from being identified. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this still does not work you might want to call into support or your local reseller for assistance. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 22:11:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41827#M30776</guid>
      <dc:creator>acamacho</dc:creator>
      <dc:date>2012-09-27T22:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41828#M30777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Parth,&lt;/P&gt;&lt;P&gt;I tried to collect more details by capturing and enclosing result files. I am not sure where is the problem...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2012 07:35:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41828#M30777</guid>
      <dc:creator>oitspa</dc:creator>
      <dc:date>2012-09-28T07:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41829#M30778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It appears that a RST-ACK is sent by the the client 62.112.193.167.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="pcap-1.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4250_pcap-1.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt; Can&amp;nbsp; you just once again confirm the issue&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;" From outside of company is website reachable without problem&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;Are you having issues accessing website from inside or outside? It appears that there is no translation in the pcaps.&lt;/P&gt;&lt;P&gt;Is your purpose trying to access the website from inside with a public ip-address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2012 08:30:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41829#M30778</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-09-28T08:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41830#M30779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;confirm - from outside of company is everything OK. You can try www.spapiestany.sk&lt;/P&gt;&lt;P&gt;We have issue to access the website only from internal network, behind the PA.&amp;nbsp; (company network - PA - public internet)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2012 08:38:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41830#M30779</guid>
      <dc:creator>oitspa</dc:creator>
      <dc:date>2012-09-28T08:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41831#M30780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to access the website from the internal zone (say trust zone having private ip-addressees) to a web server that is physical located inside but you want to access using the public ip-address, you need to configure a U-Turn NAT rule.&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1678"&gt;https://live.paloaltonetworks.com/docs/DOC-1678&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is an urgent issue and you are still unable to access the website from inside please contact support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2012 09:15:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41831#M30780</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-09-28T09:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41832#M30781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;it is probably misunderstanding, web server is not inside of our network (not physically located in internal network). Web server is outside of our company and also country.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2012 09:20:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41832#M30781</guid>
      <dc:creator>oitspa</dc:creator>
      <dc:date>2012-09-28T09:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41833#M30782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So your security rules should look like the following:- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SECURITY:-&lt;/P&gt;&lt;P&gt;Source zone: Trust&lt;/P&gt;&lt;P&gt;Destination Zone: Untrust&lt;/P&gt;&lt;P&gt;Source address: Any&lt;/P&gt;&lt;P&gt;Destination address: -website public ip-address&lt;/P&gt;&lt;P&gt;Action : Allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT :--&lt;/P&gt;&lt;P&gt;Source zone:-&amp;nbsp; Trust &lt;/P&gt;&lt;P&gt;Destination Zone :- Untrust&lt;/P&gt;&lt;P&gt;Source address Any &lt;/P&gt;&lt;P&gt;Destination address :- Website public ip-address &lt;/P&gt;&lt;P&gt;Source translation&amp;nbsp; :&amp;nbsp; type:- Dynamic ip and port ;&amp;nbsp; interface : Public facing interface &lt;/P&gt;&lt;P&gt;Destination translation: None&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2012 09:29:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41833#M30782</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-09-28T09:29:59Z</dc:date>
    </item>
    <item>
      <title>Re: incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41834#M30783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also I tested in the lab and as expected the the traffic just went fine and I was able to access the website from inside.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="pcap3.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4251_pcap3.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;The three way hand shake starts with the an internal ip-address 10.101.100.108.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However in your case a SYN is received from the server (i.e 62.112.193.167) which should not be the case. see below:- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="pcap-2.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4252_pcap-2.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try clearing all the sessions on the firewall pertaining to ip&amp;nbsp; 62.112.193.167&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the CLI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@Lab-59-PA-500&amp;gt; clear session all filter source 62.112.193.167&lt;/P&gt;&lt;P&gt;admin@Lab-59-PA-500&amp;gt; clear session all filter destination 62.112.193.167&lt;/P&gt;&lt;P&gt;admin@Lab-59-PA-500&amp;gt; clear session all filter source &amp;lt;test -pc ip-address&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test it now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2012 10:00:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41834#M30783</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-09-28T10:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41835#M30784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello Parth,&lt;/P&gt;&lt;P&gt;I tried to clear all sessions but final result is the same, website is not accessible from internal network.&lt;/P&gt;&lt;P&gt;I am enclosing last capture outputs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2012 11:19:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete/m-p/41835#M30784</guid>
      <dc:creator>oitspa</dc:creator>
      <dc:date>2012-09-28T11:19:12Z</dc:date>
    </item>
  </channel>
</rss>

