<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disabled policy  rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/disabled-policy-rules/m-p/68610#M39995</link>
    <description>&lt;P&gt;disabled rules are not active in the system, this can be seen through the following command:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&amp;gt; show running security-policy&lt;/PRE&gt;
&lt;P&gt;If the disabled rule is at the bottom of the policy it could be that the incomplete session "hits" these for logging purposes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What happens is that the system accepts a syn packet and starts building up a session once the syn packet is allowed to pass throught&lt;/P&gt;
&lt;P&gt;If then the session is disrupted, the process of properly building the session and matching an appropriate App-ID and security policy fails and the session is discarded. The system then will still create a log entry and will need to have a 'rule' but since the session was disrupted before a security&amp;nbsp; policy was properly matched, it will not have a proper security policy to add to the log. it can either use a security policy that was matched for the initial handshake, or if it matched an implied rule, one of the last rules in the policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tom&lt;/P&gt;</description>
    <pubDate>Wed, 25 Nov 2015 08:56:08 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2015-11-25T08:56:08Z</dc:date>
    <item>
      <title>Disabled policy  rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabled-policy-rules/m-p/68545#M39956</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under monitoring , still disabled policy rules matching to some some session . &lt;BR /&gt;And the session status are most of them 'incomplete' .&lt;BR /&gt;Why ? &lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2015 15:29:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabled-policy-rules/m-p/68545#M39956</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2015-11-24T15:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: Disabled policy  rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabled-policy-rules/m-p/68589#M39981</link>
      <description>&lt;P&gt;This article gives the full definitions for incomplete status. &amp;nbsp;Basically, there is either not a full tcp handshake or not enough data to identify the flow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Not-Applicable-Incomplete-Insufficient-Data-in-the-Application/ta-p/65711" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Not-Applicable-Incomplete-Insufficient-Data-in-the-Application/ta-p/65711&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2015 23:32:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabled-policy-rules/m-p/68589#M39981</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-11-24T23:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: Disabled policy  rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabled-policy-rules/m-p/68607#M39993</link>
      <description>&lt;P&gt;Are you saying traffic is matching disabled rules?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 06:41:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabled-policy-rules/m-p/68607#M39993</guid>
      <dc:creator>gtomte</dc:creator>
      <dc:date>2015-11-25T06:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: Disabled policy  rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabled-policy-rules/m-p/68610#M39995</link>
      <description>&lt;P&gt;disabled rules are not active in the system, this can be seen through the following command:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&amp;gt; show running security-policy&lt;/PRE&gt;
&lt;P&gt;If the disabled rule is at the bottom of the policy it could be that the incomplete session "hits" these for logging purposes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What happens is that the system accepts a syn packet and starts building up a session once the syn packet is allowed to pass throught&lt;/P&gt;
&lt;P&gt;If then the session is disrupted, the process of properly building the session and matching an appropriate App-ID and security policy fails and the session is discarded. The system then will still create a log entry and will need to have a 'rule' but since the session was disrupted before a security&amp;nbsp; policy was properly matched, it will not have a proper security policy to add to the log. it can either use a security policy that was matched for the initial handshake, or if it matched an implied rule, one of the last rules in the policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tom&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 08:56:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabled-policy-rules/m-p/68610#M39995</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-11-25T08:56:08Z</dc:date>
    </item>
  </channel>
</rss>

