<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTP session logged as 2 TCP sessions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49434#M36422</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I understand about PREDICT sessions, but we all agree those shouldn't be seen in traffic logs?&lt;/P&gt;&lt;P&gt;And I agree I shouldn't have to create a rule for traffic back, but in that case the session back in logs will be blocked?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And Session IDs for pair of such connections are different.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the screenshot of such sessions for easier understanding:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ftp.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16657_ftp.jpg" style="height: 465px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Another thing: for the security zone where the FTP server is we have a zone protection profile which doesn't reject Non-SYN TCP sessions and bybasses Asymmetric Paths.&lt;/P&gt;&lt;P&gt;But the mentioned FTP traffic isn't asymmetric so this zone protection profile shouldn't have any influence on these sessions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Oct 2014 07:31:02 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2014-10-29T07:31:02Z</dc:date>
    <item>
      <title>FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49423#M36411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem with the way PA handles FTP sessions. I have a general rule which allows privileged user groups to have full access to a certain network. So application and service in this rule is 'any'. One of the applications users will be using is FTP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I look at traffic logs i see 2 TCP session for each use of FTP application. Let's say client is at 1.1.1.1 and FTP server at 2.2.2.2.&lt;/P&gt;&lt;P&gt;Every time a client starts FTP session i see 2 TCP sessions in logs:&lt;/P&gt;&lt;P&gt;- TCP session from 1.1.1.1:yyyy to 2.2.2.2:21&lt;/P&gt;&lt;P&gt;- followed by TCP session from 2.2.2.2:xxxx to 1.1.1.1:20&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I know FTP application consists of 2 TCP session. But shouldn't PA as an application firewall match DATA session with CONTROL session and regard them as single use of FTP application?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;This will be a big issue when the traffic from the mentioned network towards user segment will be set to 'deny'. I don't think having to open port 20 towards user segment is the way to go on application firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards, &lt;/P&gt;&lt;P&gt;Simon &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 13:07:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49423#M36411</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-10-28T13:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49424#M36412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Simon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please confirm the session type in both directions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For an example: &lt;/P&gt;&lt;P&gt;vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 199.167.52.5&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;[&lt;/SPAN&gt;4501&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;]&lt;/SPAN&gt;/Untrust-ISP&amp;nbsp; (199.167.52.5&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;[&lt;/SPAN&gt;4501])&lt;/P&gt;&lt;P&gt;63320&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACTIVE --------------- &lt;STRONG&gt;FLOW--------------------&lt;/STRONG&gt;&amp;nbsp; ND&amp;nbsp;&amp;nbsp; 199.167.52.5&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;[&lt;/SPAN&gt;4030&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;]&lt;/SPAN&gt;/Untrust-ISP/6&amp;nbsp; (199.167.52.5&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;[&lt;/SPAN&gt;4030])&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; this is a flow session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope the &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;TCP session from 2.2.2.2&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;:&lt;/SPAN&gt;xxxx to 1.1.1.1:20 is not a flow session, it's a PRED &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;predict session). So, the firewall is expecting a connection from the server on that port. This is part of ALG &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;application layer gateway) functionality.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 13:24:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49424#M36412</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-10-28T13:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49425#M36413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Santonic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly provide us output for "show session all filter source &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;1.1.1.1 destination 2.2.2.2:21". Make sure you have just started the FTP application.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;As per issue, this output will generate two sessions. Then provide us output for "show session id &amp;lt;&amp;gt;" for both the sessions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;This will help us to determine root cause precisely.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Hardik Shah&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 13:32:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49425#M36413</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-28T13:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49426#M36414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanx for the tip, i'll try to catch such session live.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do predicted sessions go into traffic log as a seperate (TCP) session?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 13:35:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49426#M36414</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-10-28T13:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49427#M36415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="5601" data-username="santonic" href="https://live.paloaltonetworks.com/people/santonic" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;santonic&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my understanding, predict session will be not logged under traffic logs. It will be only appear in the session table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 13:40:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49427#M36415</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-10-28T13:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49428#M36416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12.8000001907349px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Hello Santonic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12.8000001907349px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;It looks like you are describing Active FTP where the client first initiates a connection on Command port 21 to server and the server responds to it. Then server will initiate a connection from its side to client for data connection using port 20.&lt;/P&gt;&lt;P style="font-size: 12.8000001907349px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" data-containerid="2028" data-containertype="14" data-objectid="6936" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-6936" style="font-weight: inherit; font-style: inherit; font-size: 12.8000001907349px; font-family: inherit; color: #006595;"&gt;https://live.paloaltonetworks.com/docs/DOC-6936&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12.8000001907349px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;But PAN uses its ALG(Application Layer Gateway) to inspect the layer 7 packets of the FTP connection ie from client to server's port 21 and its response from server. PAN then sees what ports the client and server's are negotiating, it will open a predict session of type PRED from server's side to Client's side on those specific ports. This is done dynamically so you DON'T have to open up those ports explicitly. When the firewall sees traffic coming from the server matching those ports, then it will convert this PRED session into ACTIVE session. This also means you DON'T have to create new security or NAT rules to allow traffic in the reverse direction. The other alternative is to use a Passive FTP where client only initiates connections in both the directions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12.8000001907349px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Moreover the second session doesn't appear to be correct in your example since the client will not serve anything on its port 20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12.8000001907349px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Regards,&lt;/P&gt;&lt;P style="font-size: 12.8000001907349px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Dileep&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 13:55:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49428#M36416</guid>
      <dc:creator>dreputi</dc:creator>
      <dc:date>2014-10-28T13:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49429#M36417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Santonic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Predict session do not appear in traffic log because there is no actual data exchange.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if there is any packet exchange than its seen as FTP log in traffic log rather than FTP-data. Kindly refer following document.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5349"&gt;Cannot Use 'ftp-data' as a Valid Application Selection for a Security Rule&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 13:59:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49429#M36417</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-28T13:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49430#M36418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/10366"&gt;dreputi&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yep, I copied it wrong. It should be like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Every time a client starts FTP session i see 2 TCP sessions in logs:&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;- TCP session from 1.1.1.1:yyyy to 2.2.2.2:21 application ftp&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;- followed by TCP session from 2.2.2.2:20 to 1.1.1.1:xxxx application ftp&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;I agree that I shouldn't be opening session for the DATA traffic in the other direction. But that means 2nd session will always be blocked when we implement the drop rule. Will FTP still work?&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A href="https://live.paloaltonetworks.com/u1/19490"&gt;hshah&lt;/A&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Yes, I agree that predicted sessions aren't logged and that there is no such application as ftp-data needed. &lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;But I do see a TCP session in other direction in traffic log, it's recognised as ftp application, there was some data transfered through it and it always appears after a ftp session from client to server. And that means I need to explicitly open everything from source port 20 in the other direction?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 14:54:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49430#M36418</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-10-28T14:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49431#M36419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it should work even if you have a drop rule. This is because the ALG is tracking the session based on its prediction. Like I mentioned earlier, ALG opens a predict session on for the second connection and when it receives that traffic, PAN will match the traffic to PRED session and convert it to ACTIVE session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if you have any questions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 15:00:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49431#M36419</guid>
      <dc:creator>dreputi</dc:creator>
      <dc:date>2014-10-28T15:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49432#M36420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="5601" data-username="santonic" href="https://live.paloaltonetworks.com/people/santonic" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;santonic&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ALG should take care about the predict session from the opposite direction and you need not to open port/policy in the other direction. The FW should be intelligent enough to match packets from the same session. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 15:03:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49432#M36420</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-10-28T15:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49433#M36421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Santonic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Return connection "&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; 2.2.2.2:20 to 1.1.1.1:xxxx application ftp" may be for future ftp-data. And that is expected behavior. Can you provide us show session id output for both the sessions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 17:25:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49433#M36421</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-28T17:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49434#M36422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I understand about PREDICT sessions, but we all agree those shouldn't be seen in traffic logs?&lt;/P&gt;&lt;P&gt;And I agree I shouldn't have to create a rule for traffic back, but in that case the session back in logs will be blocked?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And Session IDs for pair of such connections are different.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the screenshot of such sessions for easier understanding:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ftp.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16657_ftp.jpg" style="height: 465px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Another thing: for the security zone where the FTP server is we have a zone protection profile which doesn't reject Non-SYN TCP sessions and bybasses Asymmetric Paths.&lt;/P&gt;&lt;P&gt;But the mentioned FTP traffic isn't asymmetric so this zone protection profile shouldn't have any influence on these sessions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Oct 2014 07:31:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49434#M36422</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-10-29T07:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49435#M36423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Santonic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see FTP session on port 21 and 20 are in pair. Which means one is for control channel and other one is for data channel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, FTP server might be sending file through multiple sessions to get better throughput. Thats the reason there are multiple sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen server applications using multiple sessions to get faster throughput. May I know which FTP server are you using.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Oct 2014 13:41:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49435#M36423</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-29T13:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49436#M36424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@ santonic I had the same questions when i discovered what appeared to be IPs out on the internet doing FTP into our network but I believed should have been dropped. Under further investigation and a ticket to support I found out about the predict sessions.&amp;nbsp; RTP also works this way too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Oct 2014 14:32:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49436#M36424</guid>
      <dc:creator>lewis</dc:creator>
      <dc:date>2014-10-29T14:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49437#M36425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/19490"&gt;hshah&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanx for your info. Yep, to me it looks as well like the sessions are in pair. But session IDs are different. So I'm still worried the data sessions will be blocked.&lt;/P&gt;&lt;P&gt;I don't have info about FTP server, i'll check with the client where the issue appears. Do you know if PAN supports multiple DATA sessions back or only looks for 1?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/10171"&gt;lewis&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You saw data sessions (with source port 20) to internet and they were allowed despite the fact you didn't have such traffic allowed with rule?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2014 07:55:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49437#M36425</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-10-30T07:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49438#M36426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To clarify my scenario, I was seeing FTP traffic incoming (appeared to be initiated from an internet source which is an untrust zone for us) and being allowed to one of our NAT ips and logged under our outbound rule. This didn't make sense as all traffic incoming from the internet (untrust zone) to our NAT ip is set to deny and logged under a different rule. Under further investigation it was determined this FTP traffic was initiated from an internal device (trusted zone) which normal for us and is set to allow and the inbound untrust zone traffic in question was in fact the return traffic. As someone mentioned the traffic appears in pairs. If I were to do a screen shot of this type traffic it would look the same as yours above. I did not have to create a rule to allow the return FTP traffic back.&amp;nbsp; If untrust zone traffic were to initiate a FTP session to our NAT ip this traffic would be dropped under or deny rule. Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2014 11:32:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49438#M36426</guid>
      <dc:creator>lewis</dc:creator>
      <dc:date>2014-10-30T11:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49439#M36427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Santonic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FTP and FTP-data session ID doesnt have to be similar. The can be different. So based on session ID you can not determine if they are in pair.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If FTP application generates multiple session than they are allowed. Let me know if his helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2014 12:41:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49439#M36427</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-30T12:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49440#M36428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Santonic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The session IDs will be different. The control channel will be 'Parent Session' and the data channel will be 'child session'. But they work together ie the child session will be (predicted and converted to Active Flow) based on the parent session. Here is a sample output of child session:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; show session id 685 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Session 685&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt; Child Session ID&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;c2s flow: &lt;/P&gt;&lt;P&gt;source: 192.168.23.215 [trust-L3] &lt;/P&gt;&lt;P&gt;dst: 10.66.22.169 &lt;/P&gt;&lt;P&gt;proto: 6 &lt;/P&gt;&lt;P&gt;sport: 64047 dport: 24492 &lt;/P&gt;&lt;P&gt;state: ACTIVE type: FLOW &lt;/P&gt;&lt;P&gt;src user: unknown &lt;/P&gt;&lt;P&gt;dst user: unknown &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;s2c flow: &lt;/P&gt;&lt;P&gt;source: 10.66.22.169 [dmz-L3] &lt;/P&gt;&lt;P&gt;dst: 10.66.22.23 &lt;/P&gt;&lt;P&gt;proto: 6 &lt;/P&gt;&lt;P&gt;sport: 24492 dport: 2671 &lt;/P&gt;&lt;P&gt;state: ACTIVE type: FLOW &lt;/P&gt;&lt;P&gt;src user: unknown &lt;/P&gt;&lt;P&gt;dst user: unknown &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;start time : Sat Mar 29 06:51:52 2014 &lt;/P&gt;&lt;P&gt;timeout : 30 sec &lt;/P&gt;&lt;P&gt;time to live : 24 sec &lt;/P&gt;&lt;P&gt;total byte count(c2s) : 25293 &lt;/P&gt;&lt;P&gt;total byte count(s2c) : 69890&lt;/P&gt;&lt;P&gt;layer7 packet count(c2s) : 416 &lt;/P&gt;&lt;P&gt;layer7 packet count(s2c) : 461 &lt;/P&gt;&lt;P&gt;vsys : vsys1 &lt;/P&gt;&lt;P&gt;application : ftp-data &lt;/P&gt;&lt;P&gt;rule : trust-2-dmz &lt;/P&gt;&lt;P&gt;session to be logged at end : True &lt;/P&gt;&lt;P&gt;session in session ager : True &lt;/P&gt;&lt;P&gt;session synced from HA peer : False &lt;/P&gt;&lt;P&gt;address/port translation : source + destination &lt;/P&gt;&lt;P&gt;nat-rule : nat-trust-2-dmz(vsys1) &lt;/P&gt;&lt;P&gt;layer7 processing : completed &lt;/P&gt;&lt;P&gt;URL filtering enabled : False &lt;/P&gt;&lt;P&gt;session via prediction : True &lt;/P&gt;&lt;P&gt;use parent's policy : True &lt;/P&gt;&lt;P&gt;parent session : 683&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt; Parent session ID&lt;/P&gt;&lt;P&gt;refresh parent session : True &lt;/P&gt;&lt;P&gt;session via syn-cookies : False &lt;/P&gt;&lt;P&gt;session terminated on host : False &lt;/P&gt;&lt;P&gt;session traverses tunnel : False &lt;/P&gt;&lt;P&gt;captive portal session : False &lt;/P&gt;&lt;P&gt;ingress interface : ethernet1/4 &lt;/P&gt;&lt;P&gt;egress interface : ethernet1/5 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if that helps and if you have any questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dileep&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2014 13:44:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49440#M36428</guid>
      <dc:creator>dreputi</dc:creator>
      <dc:date>2014-10-30T13:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49441#M36429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. Dileep is correct. Just to add to it, in an FTP connection, there will be only one control connection, but may have multiple data-&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;connectiones&lt;/SPAN&gt; for each transaction. For an example, after successful login, if you apply&amp;nbsp; LS (directory listing&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;)&lt;/SPAN&gt;/PUT/GET, every time it will create different data connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2014 14:00:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49441#M36429</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-10-30T14:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: FTP session logged as 2 TCP sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49442#M36430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanx all for your replies, they've been really helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2014 14:17:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-session-logged-as-2-tcp-sessions/m-p/49442#M36430</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-10-30T14:17:26Z</dc:date>
    </item>
  </channel>
</rss>

