<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues with Asymetric Routing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-asymetric-routing/m-p/65379#M39048</link>
    <description>&lt;P&gt;To identify the asymmetric routing issue one of the possible way is to do a ping from a host and then check if the s2c byte are 0 or not if the s2c are 0 and ping is sucessful then reply is not comint through firewall&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Refer to following document for non syn packets&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Set-the-Palo-Alto-Networks-Firewall-to-Allow-non-Syn/ta-p/62868" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Set-the-Palo-Alto-Networks-Firewall-to-Allow-non-Syn/ta-p/62868&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Oct 2015 22:37:55 GMT</pubDate>
    <dc:creator>pankaku</dc:creator>
    <dc:date>2015-10-01T22:37:55Z</dc:date>
    <item>
      <title>Issues with Asymetric Routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-asymetric-routing/m-p/65363#M39039</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need your help to how to identify the asymetric routing in my PA-3020? and what are the best way to allow or bypass these traffic until solve the routing issue the third party device?.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Andres Padilla&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 16:12:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-asymetric-routing/m-p/65363#M39039</guid>
      <dc:creator>Apadilla</dc:creator>
      <dc:date>2015-10-01T16:12:34Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Asymetric Routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-asymetric-routing/m-p/65365#M39041</link>
      <description>&lt;P&gt;Depending on what assimetric routing the firewall is seeing, the most agressive/global is&amp;nbsp;&lt;/P&gt;&lt;P&gt;set session tcp-reject-non-syn no&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can also add a a Zone protection profile in this one select&amp;nbsp;"packet based attack protection", uncheck mismatched overlapping TCP segment, reject non-syn tcp: no, asymetric path: bypass. And attach it to the zone where the assimetric traffic is arriving.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Gerardo&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 16:57:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-asymetric-routing/m-p/65365#M39041</guid>
      <dc:creator>glastra1</dc:creator>
      <dc:date>2015-10-01T16:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Asymetric Routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-asymetric-routing/m-p/65367#M39042</link>
      <description>&lt;P&gt;I set up a protection zone the following way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And assinged to untrust zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/536i11DE65C0441644FD/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="issue asymetric routing.JPG" title="issue asymetric routing.JPG" border="0" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After performed this change I see the&lt;/P&gt;&lt;P&gt;the numer 51303508 not changed.&lt;/P&gt;&lt;P&gt;flow_tcp_non_syn_drop&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 51303508&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 drop&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; flow&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; session&amp;nbsp;&amp;nbsp; Packets dropped: non-SYN TCP without session match&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But this number always increase 51316034.&lt;/P&gt;&lt;P&gt;flow_tcp_non_syn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 51316034&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; flow&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; session&amp;nbsp;&amp;nbsp; Non-SYN TCP packets without session match&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 17:10:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-asymetric-routing/m-p/65367#M39042</guid>
      <dc:creator>Apadilla</dc:creator>
      <dc:date>2015-10-01T17:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Asymetric Routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-asymetric-routing/m-p/65379#M39048</link>
      <description>&lt;P&gt;To identify the asymmetric routing issue one of the possible way is to do a ping from a host and then check if the s2c byte are 0 or not if the s2c are 0 and ping is sucessful then reply is not comint through firewall&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Refer to following document for non syn packets&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Set-the-Palo-Alto-Networks-Firewall-to-Allow-non-Syn/ta-p/62868" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Set-the-Palo-Alto-Networks-Firewall-to-Allow-non-Syn/ta-p/62868&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 22:37:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-asymetric-routing/m-p/65379#M39048</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-10-01T22:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Asymetric Routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-asymetric-routing/m-p/65384#M39053</link>
      <description>&lt;P&gt;the numer 51303508 not changed.&lt;/P&gt;&lt;P&gt;flow_tcp_non_syn_drop&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 51303508&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 drop&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; flow&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; session&amp;nbsp;&amp;nbsp; Packets dropped: non-SYN TCP without session match&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But this number always increase 51316034.&lt;/P&gt;&lt;P&gt;flow_tcp_non_syn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 51316034&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; flow&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; session&amp;nbsp;&amp;nbsp; Non-SYN TCP packets without session match&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That means you are no longer dropping asymmetric TCP sessions, but there are still such sessions happening. Now you have to resolve your routing and when both counters stop increasing you know you don't have any asymmetric routing any longer. Then start dropping non-SYN sessions again.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 07:12:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-asymetric-routing/m-p/65384#M39053</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2015-10-02T07:12:33Z</dc:date>
    </item>
  </channel>
</rss>

