<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cannot understand drop reason in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5352#M3939</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i will check and update by the way... protocol should be 6 for tcp, and add destination-port 80 for http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Mar 2014 07:17:31 GMT</pubDate>
    <dc:creator>minow</dc:creator>
    <dc:date>2014-03-12T07:17:31Z</dc:date>
    <item>
      <title>cannot understand drop reason</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5343#M3930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hey&lt;/P&gt;&lt;P&gt;i have a client that connects to a remote site using&amp;nbsp; GP, and that site have s2s vpn to my site,&lt;/P&gt;&lt;P&gt;we have problems connecting to a server in that site, we can i cannot see and drops in the traffic or threat logs,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have put filter on the ips and used tha show global couters shows this drops:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Global counters:&lt;/P&gt;&lt;P&gt;Elapsed time since last sampling: 5.880 seconds&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; value&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rate severity&amp;nbsp; category&amp;nbsp; aspect&amp;nbsp;&amp;nbsp;&amp;nbsp; description&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;flow_fwd_zonechange&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 drop&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; flow&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; forward&amp;nbsp;&amp;nbsp; Packets dropped: forwarded to different zone&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Total counters shown: 1&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i dont understand this drop error, but i have checked routes and have only one route to each direction and the s2s vpn is steady and up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pings between the client and server works fine&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please help&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2014 10:35:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5343#M3930</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2014-03-10T10:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: cannot understand drop reason</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5344#M3931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i can see the SYN from the client to the server and then i can see the SYN-ACK from the server to the client on the stages: receive, firewall and drop on my paloalto &lt;/P&gt;&lt;P&gt;on the drop it is the same packets of the SYN-ACK (comparing the firewall and the drop pcaps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2014 10:45:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5344#M3931</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2014-03-10T10:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: cannot understand drop reason</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5345#M3932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Minow,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please confirm whether outgoing SYN packet and incoming SYN-ACK packet is being received by the same physical interface and zone.It's looking like a assymetric routing situation. For testing perpose you can enable "assmetric-path-bypass= YES" "TCP non-syn reject=NO".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2014 16:24:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5345#M3932</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-03-10T16:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: cannot understand drop reason</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5346#M3933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes i will try&lt;/P&gt;&lt;P&gt;but how can i see on which interface every packet received from and sent to &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2014 08:55:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5346#M3933</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2014-03-11T08:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: cannot understand drop reason</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5347#M3934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the weird thing is that there is only one route to the client and one route to the server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2014 08:55:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5347#M3934</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2014-03-11T08:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: cannot understand drop reason</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5348#M3935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Minow,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Check what Hulk said, and double check your routes (including any PBF rules). It could be that the return packet is being routed to a different interface than the SYN packet came in on, which will give you the zonechange drop counter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig Stancill&amp;nbsp; |&amp;nbsp; Technical Support Engineer&lt;/P&gt;&lt;P&gt;Shift Time : 05:00 – 14:00 GMT&lt;/P&gt;&lt;P&gt;Support Contact: US: (866) 898-9087, Outside the US: +1-408-738-7799&lt;/P&gt;&lt;P&gt;Palo Alto Networks&amp;nbsp; |&amp;nbsp; 3300 Olcott Street&amp;nbsp; |&amp;nbsp; Santa Clara, CA 95054-3005, USA&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://support.paloaltonetworks.com/"&gt;https://support.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2014 11:13:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5348#M3935</guid>
      <dc:creator>cstancill</dc:creator>
      <dc:date>2014-03-11T11:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: cannot understand drop reason</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5349#M3936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi minow,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please try the command:&lt;/P&gt;&lt;P&gt;- test security-policy-match source xxx destination xxx protocol xxx show-all yes&lt;/P&gt;&lt;P&gt;- test security-policy-match source xxx destination xxx protocol xxx from xxx to xxx show-all yes (&lt;/P&gt;&lt;P&gt;protocol: for example 80 is the right number for http&lt;/P&gt;&lt;P&gt;from: source zone&lt;/P&gt;&lt;P&gt;to: destination zone&lt;/P&gt;&lt;P&gt;the result will show which rule is taken. I guess there is a mismatch between interface and zones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Klaus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2014 11:57:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5349#M3936</guid>
      <dc:creator>kdd</dc:creator>
      <dc:date>2014-03-11T11:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: cannot understand drop reason</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5350#M3937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/8513"&gt;kdd&lt;/A&gt; this is awesome! I just added these commands to our internal wiki&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2014 13:47:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5350#M3937</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2014-03-11T13:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: cannot understand drop reason</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5351#M3938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/12528"&gt;ericgearhart&lt;/A&gt; i like it too because it keeps a lot short&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2014 16:10:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5351#M3938</guid>
      <dc:creator>kdd</dc:creator>
      <dc:date>2014-03-11T16:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: cannot understand drop reason</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5352#M3939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i will check and update by the way... protocol should be 6 for tcp, and add destination-port 80 for http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Mar 2014 07:17:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5352#M3939</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2014-03-12T07:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: cannot understand drop reason</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5353#M3940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It PBR policy routing ACK to a different zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Mar 2014 07:59:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5353#M3940</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2014-03-20T07:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: cannot understand drop reason</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5354#M3941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/6493"&gt;minow&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is this doc where it explains taking packet level logs known as flow basic. This would give details results if there is a drop at what stage what is the reason and so on to understand.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2542"&gt;Packet Based Troubleshooting - Configuring Packet Captures and Debug Logs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Mar 2014 15:41:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-understand-drop-reason/m-p/5354#M3941</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2014-03-20T15:41:19Z</dc:date>
    </item>
  </channel>
</rss>

