<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: show counter global filter category flow aspect dos in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/77096#M42525</link>
    <description>&lt;P&gt;ok, that makes things a little more tricky &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you make sure every single interface has a unique zone (the single session should go through 6 different zones)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have you checked the transmit (TX) stage of the firwall ? if you run a wireshark capture on the server, can you see the packet arriving ?&lt;/P&gt;</description>
    <pubDate>Wed, 27 Apr 2016 08:03:33 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2016-04-27T08:03:33Z</dc:date>
    <item>
      <title>show counter global filter category flow aspect dos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/76968#M42482</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below is &amp;nbsp;output of &amp;nbsp;'show counter global filter category flow aspect dos'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What does it mean by value and rate . Does it mean '&lt;SPAN&gt;143291' packets dropped ?&amp;nbsp;&lt;/SPAN&gt; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE width="579"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="253"&gt;name&lt;/TD&gt;
&lt;TD width="70"&gt;value&lt;/TD&gt;
&lt;TD width="64"&gt;rate&lt;/TD&gt;
&lt;TD width="64"&gt;severity&lt;/TD&gt;
&lt;TD width="64"&gt;category&lt;/TD&gt;
&lt;TD width="64"&gt;aspect&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_red_tcp&lt;/TD&gt;
&lt;TD&gt;1143291&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;TD&gt;drop&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_pf_ipfrag&lt;/TD&gt;
&lt;TD&gt;57444&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;TD&gt;drop&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_pf_icmplpkt&lt;/TD&gt;
&lt;TD&gt;1100&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;TD&gt;drop&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_pf_tcpoverlappingmismatch&lt;/TD&gt;
&lt;TD&gt;20411&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;TD&gt;drop&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_zone_red_max&lt;/TD&gt;
&lt;TD&gt;446965&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;TD&gt;drop&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_zone_red_act&lt;/TD&gt;
&lt;TD&gt;696326&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;TD&gt;drop&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_rule_drop&lt;/TD&gt;
&lt;TD&gt;403117&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;TD&gt;drop&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_rule_drop_classified&lt;/TD&gt;
&lt;TD&gt;403117&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;TD&gt;drop&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_rule_allow_under_rate&lt;/TD&gt;
&lt;TD&gt;3402693&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;TD&gt;info&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_rule_allow&lt;/TD&gt;
&lt;TD&gt;35492603&lt;/TD&gt;
&lt;TD&gt;21&lt;/TD&gt;
&lt;TD&gt;info&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_rule_match&lt;/TD&gt;
&lt;TD&gt;39298413&lt;/TD&gt;
&lt;TD&gt;22&lt;/TD&gt;
&lt;TD&gt;info&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_rule_nomatch&lt;/TD&gt;
&lt;TD&gt;129318926&lt;/TD&gt;
&lt;TD&gt;32&lt;/TD&gt;
&lt;TD&gt;info&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_no_empty_entp&lt;/TD&gt;
&lt;TD&gt;517212&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;TD&gt;info&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_curr_sess_add_no_entp&lt;/TD&gt;
&lt;TD&gt;114095&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;TD&gt;info&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_curr_sess_del_no_entp&lt;/TD&gt;
&lt;TD&gt;124207&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;TD&gt;info&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_cl_curr_sess_add_incr&lt;/TD&gt;
&lt;TD&gt;72234191&lt;/TD&gt;
&lt;TD&gt;27&lt;/TD&gt;
&lt;TD&gt;info&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;flow_dos_cl_curr_sess_del_decr&lt;/TD&gt;
&lt;TD&gt;72222602&lt;/TD&gt;
&lt;TD&gt;28&lt;/TD&gt;
&lt;TD&gt;info&lt;/TD&gt;
&lt;TD&gt;flow&lt;/TD&gt;
&lt;TD&gt;dos&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 06:59:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/76968#M42482</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2016-04-25T06:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: show counter global filter category flow aspect dos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/76970#M42484</link>
      <description>&lt;P&gt;"value" is the total number of packets that hit this counter since the last time the counters were reset (in many cases, the lifetime of this device)&lt;/P&gt;
&lt;P&gt;the "rate" is the amount of packets being dropped in a relative window of time&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the best way to determine/control the actual rate is by adding the 'delta' function to your show command and then running the command a few times with a few seconds or minutes in between. that way the delta will only show the actual increase in the counter&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&amp;gt; show counter global filter category flow aspect dos &lt;STRONG&gt;delta yes&lt;/STRONG&gt;

Global counters:
&lt;STRONG&gt;Elapsed time since last sampling: 2.110 seconds&lt;/STRONG&gt;

--------------------------------------------------------------------------------
Total counters shown: 0
--------------------------------------------------------------------------------

&lt;/PRE&gt;</description>
      <pubDate>Mon, 25 Apr 2016 07:09:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/76970#M42484</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-04-25T07:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: show counter global filter category flow aspect dos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/76974#M42487</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks reaper .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Traffic shows incomplete to a server from a host . but the other host can reachable&lt;/P&gt;
&lt;P&gt;So i was thinking it may due to the dos policy (zone protection or dos rule ). So how can i verify which policy casuing the 'incomplete'&lt;/P&gt;
&lt;P&gt;But there is no log under threats&lt;/P&gt;
&lt;P&gt;Thanks again&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 08:48:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/76974#M42487</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2016-04-25T08:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: show counter global filter category flow aspect dos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/76977#M42488</link>
      <description>&lt;P&gt;an incomplete is nearly never due to a policy (a policy would be a drop or reset). An incomplete is usually because a syn packet was sent out and an ack was never returned. this can be due to several network related issues: the host is unreachable, NAT was not applied, there is an asymmetric path, there is another firewall blocking the connection ....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you are unsure what is causing the issue, you can set up packetcaptures to help determine what is going on&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 09:27:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/76977#M42488</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-04-25T09:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: show counter global filter category flow aspect dos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/76980#M42489</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;If i change the client ip address it works .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 10:31:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/76980#M42489</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2016-04-25T10:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: show counter global filter category flow aspect dos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/76981#M42490</link>
      <description>&lt;P&gt;there could be an IP conflict, subnetting issue, an access list on the server or possibly NAT not being applied to the whole subnet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;setting up a packetcapture for send, receive and drop stage may help&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;check out this getting started guide:&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Packet-Capture/ta-p/72069" target="_blank"&gt;Getting Started: Packet Capture&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 10:50:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/76981#M42490</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-04-25T10:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: show counter global filter category flow aspect dos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/77025#M42501</link>
      <description>&lt;P&gt;Hi reaper&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have attached the rx &amp;nbsp;capture file &amp;nbsp;, and &amp;nbsp; topology&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;filter &amp;nbsp;: source &amp;nbsp;10.10.10.10 &amp;nbsp;destination 172.100.10 .254&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rx.PNG" style="width: 600px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3733iC6E21674A01A83D6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rx.PNG" alt="rx.PNG" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pa topology.png" style="width: 600px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3734i9D3D9417F5407DA4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pa topology.png" alt="pa topology.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help to understand&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 23:29:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/77025#M42501</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2016-04-25T23:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: show counter global filter category flow aspect dos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/77034#M42506</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so the pcap doesn't look good, there's only outgoing SYN packets and no reply&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you indicate there are 3 PA firewalls ? i'd start by setting up pcaps on all 3 with these filters:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1 10.10.10.10&amp;nbsp; - 172.100.10.254 d-port 80&lt;/P&gt;
&lt;P&gt;2 172.100.10.254 - 10.10.10.10 s-port 80&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(unless there is NAT, then you'd need to adjust the IP's)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and if possible, also on the ASA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;that will allow you to track the whole path the packets need to traverse so you can pinpoint where the link&lt;/P&gt;
&lt;P&gt;-if you see the syn packet on all firewalls, you know it was delivered to the DMZ switch and something went wrong there&lt;/P&gt;
&lt;P&gt;-if you see it on the first 2 PA's but not on the 3rd PA, you'll know it's on the ASA&lt;/P&gt;
&lt;P&gt;-if you don't see it on the second PA you'll know it's going wrong on the core&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;since you're only seeing SYN packets, i'd also focus on the TX pcaps first, to make sure they're leaving the firewall&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2016 07:43:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/77034#M42506</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-04-26T07:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: show counter global filter category flow aspect dos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/77085#M42519</link>
      <description>&lt;P&gt;Actually &amp;nbsp;there is only one physical firewall ,those three are in differnet zone&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2016 21:26:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/77085#M42519</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2016-04-26T21:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: show counter global filter category flow aspect dos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/77096#M42525</link>
      <description>&lt;P&gt;ok, that makes things a little more tricky &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you make sure every single interface has a unique zone (the single session should go through 6 different zones)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have you checked the transmit (TX) stage of the firwall ? if you run a wireshark capture on the server, can you see the packet arriving ?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2016 08:03:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/77096#M42525</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-04-27T08:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: show counter global filter category flow aspect dos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/77182#M42535</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Here is the tx , it seems &amp;nbsp;packets are leaving firewall ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tx.png" style="width: 600px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3785iCF3986C88E4CF816/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="tx.png" alt="tx.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per the &amp;nbsp;below diagram &amp;nbsp;rx of both interface will be &amp;nbsp;recordeed in rx stage &amp;nbsp;and tx in the tx stage,&lt;/P&gt;
&lt;P&gt;At firewall stage what all will be recorded &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pa trust untrust.png" style="width: 600px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3786i4C67DCE18487EA41/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pa trust untrust.png" alt="pa trust untrust.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 04:37:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/77182#M42535</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2016-04-28T04:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: show counter global filter category flow aspect dos</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/77184#M42537</link>
      <description>&lt;P&gt;if you see packets in the transmit stage, that means they are leaving the firewall on the egress interface&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the tricky part in your case is that the packets go in and out of the firewall 3 times, but i only see 2 transmits (look for source port 52087) and then a retransmit, so according to your initial diagram, that would mean the ASA &amp;nbsp;could be blocking your connection&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the first transmit is from distri to core, the second entry is from core to asa, the third one should be asa to dmz&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you now compare the transmit to the receive, you can see if the receive also only has 2 entries, which means the packet from asa was not received, or if it has 3 entries, which means the 3rd leg of the PA firewall received and dropped the packet&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 06:40:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-global-filter-category-flow-aspect-dos/m-p/77184#M42537</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-04-28T06:40:57Z</dc:date>
    </item>
  </channel>
</rss>

