<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: drop-reset application list in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/drop-reset-application-list/m-p/50859#M37424</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for this answer.&lt;/P&gt;&lt;P&gt;This is a problem because Skype opens many TCP connections which then remain in the INIT state. As MS Windows allows only limited number of simultaneous connections, all other connection attempts are slowed and users are complaining.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please could you confirm that the deny action is a drop and not a drop-reset ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case we will need to find a workaround, and this will generate delay and additional cost for us.&lt;/P&gt;&lt;P&gt;As already said by many users, we would appreciate to have the opportunity to choose the action by ourselves !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 May 2012 15:16:11 GMT</pubDate>
    <dc:creator>Duplem</dc:creator>
    <dc:date>2012-05-25T15:16:11Z</dc:date>
    <item>
      <title>drop-reset application list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/drop-reset-application-list/m-p/50857#M37422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found this explanation about TCP REJECT today :&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #0000ff;"&gt;"The deny action used in a security policy will either ‘drop’ or ‘drop-reset’ based on the app being used in the policy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #0000ff;"&gt;For most browser-based apps, it is drop-reset - this prevents the browser from spinning while retrying.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #0000ff;"&gt;For&amp;nbsp; client-server apps that are based on http (or other protocols that we&amp;nbsp; have decoders for), we generally use drop-reset if the app is considered&amp;nbsp; harmless. We don't currently support icmp-host-unreachable for udp/icmp but it is on the cards."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where could I get information about drop-reset implementation on apps ? Could this information be added on applipedia ?&lt;/P&gt;&lt;P&gt;If this information is not available for customers, could you tell me which action is choosed for skype app ? You can contact me by email if necessary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Emmanuel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 14:40:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/drop-reset-application-list/m-p/50857#M37422</guid>
      <dc:creator>Duplem</dc:creator>
      <dc:date>2012-05-23T14:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: drop-reset application list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/drop-reset-application-list/m-p/50858#M37423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...Since skype is not a browser-based app, the deny action would be a drop action.&amp;nbsp; You can confirm by blocking skype and performing a packet capture of the traffic.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2012 15:01:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/drop-reset-application-list/m-p/50858#M37423</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-05-25T15:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: drop-reset application list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/drop-reset-application-list/m-p/50859#M37424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for this answer.&lt;/P&gt;&lt;P&gt;This is a problem because Skype opens many TCP connections which then remain in the INIT state. As MS Windows allows only limited number of simultaneous connections, all other connection attempts are slowed and users are complaining.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please could you confirm that the deny action is a drop and not a drop-reset ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case we will need to find a workaround, and this will generate delay and additional cost for us.&lt;/P&gt;&lt;P&gt;As already said by many users, we would appreciate to have the opportunity to choose the action by ourselves !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2012 15:16:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/drop-reset-application-list/m-p/50859#M37424</guid>
      <dc:creator>Duplem</dc:creator>
      <dc:date>2012-05-25T15:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: drop-reset application list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/drop-reset-application-list/m-p/50860#M37425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The users can't use skype since you're blocking skype anyway.&amp;nbsp; Even with drop-reset, skype will retry and open new connections again.&amp;nbsp; Can they signed out of skype then skype won't take up the computer's resource.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2012 15:21:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/drop-reset-application-list/m-p/50860#M37425</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-05-25T15:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: drop-reset application list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/drop-reset-application-list/m-p/50861#M37426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems you didn't understood the problem. Better say me that if I don't want skype on my network, skype should not be installed on computers... Easy to say, no&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition, you didn't answer all questions :&lt;/P&gt;&lt;P&gt;Where could I get information about drop-reset implementation on apps ? Could this information be added on applipedia ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Last but not least, we &lt;STRONG&gt;need&lt;/STRONG&gt; to be able to choose the type of deny action, but this is another topic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 13:49:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/drop-reset-application-list/m-p/50861#M37426</guid>
      <dc:creator>Duplem</dc:creator>
      <dc:date>2012-06-27T13:49:08Z</dc:date>
    </item>
  </channel>
</rss>

