<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTP connections jumping rule in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/85893#M43393</link>
    <description>&lt;P&gt;Can you take a screensot of the 2 FTP rules so we can see them please. &amp;nbsp;Thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jun 2016 13:45:13 GMT</pubDate>
    <dc:creator>rmonvon</dc:creator>
    <dc:date>2016-06-14T13:45:13Z</dc:date>
    <item>
      <title>FTP connections jumping rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/85773#M43387</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have 2 rules. the first one filtering by application FTP&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and the second one with the same source/destination like the rule above and using any/any permit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We run ftp connections. all these FTP connections should match in the first rule filtering by FTP, but we see matches in the any/any rule too.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this rule should be match all the ftp connections (filter by FTP app, services any):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura1.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4409i10C8B3CB0CDE6CF8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Captura1.JPG" alt="Captura1.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;but we see connections in this rule too (any/any)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capturasegunda.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4410iA6739F86AB867E47/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capturasegunda.JPG" alt="Capturasegunda.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why all the connections FTP not using the same rule (first one)???&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 11:53:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/85773#M43387</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2016-06-14T11:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: FTP connections jumping rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/85807#M43388</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you run the PCAP on the PA? Use filters to specify a particular host /IP and post the result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 12:35:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/85807#M43388</guid>
      <dc:creator>Transporter</dc:creator>
      <dc:date>2016-06-14T12:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: FTP connections jumping rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/85854#M43390</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If during session application changes then unless you log at session start you see in log only last application identified.&lt;/P&gt;
&lt;P&gt;For troubleshooting period can you open both of those policies and on the last tab (Actions) check both boxes "log at session start" and "log at session end"&lt;/P&gt;
&lt;P&gt;Do you see only FTP in application field or Palo identifies it something else in the mean time?&lt;/P&gt;
&lt;P&gt;After application shift rules are evaluated again and top rule should match again so strange issu but worth to try.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 13:22:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/85854#M43390</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-06-14T13:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: FTP connections jumping rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/85873#M43391</link>
      <description>&lt;P&gt;The app is FTP, but i dont know why the second rule is matching if all the connections should go through first rule...&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 13:34:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/85873#M43391</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2016-06-14T13:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: FTP connections jumping rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/85893#M43393</link>
      <description>&lt;P&gt;Can you take a screensot of the 2 FTP rules so we can see them please. &amp;nbsp;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 13:45:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/85893#M43393</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2016-06-14T13:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: FTP connections jumping rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/85894#M43394</link>
      <description>&lt;P&gt;Any chance you're running into an issue with the FTP rule not catching FTPs?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 13:49:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/85894#M43394</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-06-14T13:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: FTP connections jumping rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/85897#M43396</link>
      <description>&lt;P&gt;I attach both rules. Connections shoyuld only go through first rule, but we see FTP tries in the last one. Why?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="REGLAS FTP.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4412iEBC432C13C2B0E99/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="REGLAS FTP.jpg" alt="REGLAS FTP.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 13:56:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/85897#M43396</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2016-06-14T13:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: FTP connections jumping rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/86158#M43410</link>
      <description>&lt;P&gt;From the rule screenshot, FTP should match 1st rule and not the 2nd rule as you pointed out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you happen to add/modify the FTP rules during the time period in question? &amp;nbsp;If so, it may be that the FTP session matched 1 rule and a rule change occurred afterward which would not take effect on the existing FTP session.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you're still seeing this behavior where FTP is matching rule2, I recommend opening a Support cast to have it diagnose. &amp;nbsp;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 18:19:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/86158#M43410</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2016-06-14T18:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: FTP connections jumping rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/86798#M43424</link>
      <description>&lt;P&gt;I checked the NAT rule for this FTP server and its weird this NAT rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4414iC15D7CA9083691FE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NAT.jpg" alt="NAT.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;It should be a static NAT??? currently its configured with dynamic ip and port... maybe this can caused problems?? The connections take different source ip nat to go to internet.....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe this could cause the problem?? i think for this FTP use we should use a static ftp ...&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 11:11:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/86798#M43424</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2016-06-15T11:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: FTP connections jumping rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/86799#M43425</link>
      <description>&lt;P&gt;Is 195.5 address object?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 11:27:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/86799#M43425</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-06-15T11:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: FTP connections jumping rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/86888#M43427</link>
      <description>&lt;P&gt;No, its the IP iwth no object created. I think NAT is not well created.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 12:45:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/86888#M43427</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2016-06-15T12:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: FTP connections jumping rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/86906#M43428</link>
      <description>&lt;P&gt;Hiya,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly could you provide screenshots of the FTP sessions that hitting a correct policy and "any" "any" policy.&lt;/P&gt;
&lt;P&gt;Example below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="example.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4415i009C88CE876C8F76/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="example.png" alt="example.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 13:07:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/86906#M43428</guid>
      <dc:creator>Transporter</dc:creator>
      <dc:date>2016-06-15T13:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: FTP connections jumping rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/86980#M43430</link>
      <description>&lt;P&gt;Can you also send screenshot of the session from session table.&lt;/P&gt;
&lt;P&gt;Monitor &amp;gt; Session table&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Click on the + sign to expand the view.&lt;/P&gt;
&lt;P&gt;Session table view includes NAT policy used but traffic log screenshot does not.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 14:20:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-connections-jumping-rule/m-p/86980#M43430</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-06-15T14:20:23Z</dc:date>
    </item>
  </channel>
</rss>

