<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: reset-client vs. reset-server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/77223#M42550</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;Some other points to consider:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.digitalocean.com/community/tutorials/how-to-choose-an-effective-firewall-policy-to-secure-your-servers&amp;nbsp;" target="_blank"&gt;https://www.digitalocean.com/community/tutorials/how-to-choose-an-effective-firewall-policy-to-secure-your-servers&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt; 
The link is dead.</description>
    <pubDate>Thu, 28 Apr 2016 16:21:33 GMT</pubDate>
    <dc:creator>Sly_Cooper</dc:creator>
    <dc:date>2016-04-28T16:21:33Z</dc:date>
    <item>
      <title>reset-client vs. reset-server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/76766#M42420</link>
      <description>&lt;P&gt;How do you decide on the action for a particular threat? For drop, tcp will still retry. With recent what is the general practice, reset-both, reset-client or reset-server?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 19:06:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/76766#M42420</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2016-04-20T19:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: reset-client vs. reset-server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/76771#M42424</link>
      <description>&lt;P&gt;There's probably enough smart people on either fence to make a case for either deployment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The old addage of "don't" respond is countered today with. &amp;nbsp;"Well, if you don't get a response, you can probably assume there was a FW there." &amp;nbsp;Also there comes the issue with resource exhaustion and just sending so much garabge traffic to a FW that it's having to account for the TCP sessions and sending those replies to source of the session.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's really going to depend on your local security policy, your intent, and the "value" of what you're trying to protect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://isc.sans.edu/forums/diary/Silent+Drop+vs+Reject+Firewall+rules/966/" target="_blank"&gt;https://isc.sans.edu/forums/diary/Silent+Drop+vs+Reject+Firewall+rules/966/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 20:10:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/76771#M42424</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-04-20T20:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: reset-client vs. reset-server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/76772#M42425</link>
      <description>&lt;P&gt;Some other points to consider:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.digitalocean.com/community/tutorials/how-to-choose-an-effective-firewall-policy-to-secure-your-servers&amp;nbsp;" target="_blank"&gt;https://www.digitalocean.com/community/tutorials/how-to-choose-an-effective-firewall-policy-to-secure-your-servers&amp;nbsp;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 20:17:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/76772#M42425</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-04-20T20:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: reset-client vs. reset-server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/76795#M42429</link>
      <description>&lt;P&gt;in most cases i would probably only care for my internal resources, so for outbound connections i'd only reset the client's side and for inbound only the server's side. inside the organization a reset to both&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 12:15:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/76795#M42429</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-04-21T12:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: reset-client vs. reset-server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/77223#M42550</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;Some other points to consider:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.digitalocean.com/community/tutorials/how-to-choose-an-effective-firewall-policy-to-secure-your-servers&amp;nbsp;" target="_blank"&gt;https://www.digitalocean.com/community/tutorials/how-to-choose-an-effective-firewall-policy-to-secure-your-servers&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt; 
The link is dead.</description>
      <pubDate>Thu, 28 Apr 2016 16:21:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/77223#M42550</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2016-04-28T16:21:33Z</dc:date>
    </item>
    <item>
      <title>Re: reset-client vs. reset-server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/77287#M42561</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30703"&gt;@Sly_Cooper﻿&lt;/a&gt;&amp;nbsp;hahaha, wow, it was active when I posted it. &amp;nbsp;Sorry about that&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2016 12:48:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/77287#M42561</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-04-29T12:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: reset-client vs. reset-server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/77416#M42592</link>
      <description>&lt;P&gt;Does anyone know what happens with the other side of the connection when you use reset-client or reset-server action?&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2016 14:14:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/77416#M42592</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2016-05-03T14:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: reset-client vs. reset-server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/77419#M42594</link>
      <description>&lt;P&gt;The other side experiences a 'silent drop', meaning no notification is sent at all and the packets just dissapear.&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2016 14:17:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/77419#M42594</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-05-03T14:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: reset-client vs. reset-server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/77439#M42598</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;The other side experiences a 'silent drop', meaning no notification is sent at all and the packets just dissapear.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;So the remote side will "think" that the session is still ON and continue to send packets which will get dropped further?&lt;/P&gt;
&lt;P&gt;Will it be advisable to use drop or reset-server in case of public facing dmz system? Reset-server will clean up the session on my server instead of waiting it to get cleaned after idle-timeout. Thoughts?&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2016 17:08:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/77439#M42598</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2016-05-03T17:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: reset-client vs. reset-server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/77470#M42615</link>
      <description>&lt;P&gt;part of the consideration is also at which stage a session might get dropped:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-if you are going to block an application (say, facebook) a session already needs to have been started before we get to the point where we identify facebook and close the session&lt;/P&gt;
&lt;P&gt;-if you are going to block a port (allow port 80 block everything else) the session gets stopped at the initial SYN packet&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in the first scenario both parties have a socket dedicated to this connection, so receiving a reset allows either to free up the allocated resource faster. in the second scenario, only the client has an outbound socket, the server did not receive anything so&amp;nbsp;has no resources in play&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in the first scenario, you could decide if you want to let either side know and allow them to close the connection gracefully, in the second you only need to worry about the client (is it yours or not)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In case of a public facing DMZ you may want to mix things up a little and allow for legitimate clients that run into a block for some reason to receive a reset so their browser can pop up an error message while silently dropping ports that are not used to hamper port scans. a reset to the server can be useful if it is stretched for resources. (i'd also enable zone protection to ensure port scans are dealt with)&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2016 08:08:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reset-client-vs-reset-server/m-p/77470#M42615</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-05-04T08:08:04Z</dc:date>
    </item>
  </channel>
</rss>

