<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo Alto deny All policy reason non-syn-tcp in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-deny-all-policy-reason-non-syn-tcp/m-p/133396#M47209</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We realised our PA in version 7.0.6 is having any issue with the traffic. We see many traffic being dropped by DENY all rule (the last rule in the rule set). Looking in application we see "non-syn-tcp" in all the connections.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These denies connections always ocurrs each 30 minutes. For example: 4.01pm, 4.31pm, 5&lt;SPAN&gt;.01pm, 5.31pm.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logs.JPG" style="width: 396px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6953i8749BF167ECD2D88/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="logs.JPG" alt="logs.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have disabled tcp syn reject in global, but its configured in zones too. why is happening this???? its quite weird each 30 minutes we see these denies.&lt;/P&gt;</description>
    <pubDate>Sun, 18 Dec 2016 17:46:14 GMT</pubDate>
    <dc:creator>soporteseguridad</dc:creator>
    <dc:date>2016-12-18T17:46:14Z</dc:date>
    <item>
      <title>Palo Alto deny All policy reason non-syn-tcp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-deny-all-policy-reason-non-syn-tcp/m-p/133396#M47209</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We realised our PA in version 7.0.6 is having any issue with the traffic. We see many traffic being dropped by DENY all rule (the last rule in the rule set). Looking in application we see "non-syn-tcp" in all the connections.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These denies connections always ocurrs each 30 minutes. For example: 4.01pm, 4.31pm, 5&lt;SPAN&gt;.01pm, 5.31pm.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logs.JPG" style="width: 396px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6953i8749BF167ECD2D88/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="logs.JPG" alt="logs.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have disabled tcp syn reject in global, but its configured in zones too. why is happening this???? its quite weird each 30 minutes we see these denies.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Dec 2016 17:46:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-deny-all-policy-reason-non-syn-tcp/m-p/133396#M47209</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2016-12-18T17:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto deny All policy reason non-syn-tcp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-deny-all-policy-reason-non-syn-tcp/m-p/133406#M47212</link>
      <description>A non-syn-tcp drop occurs when a packet is received that is not a syn and also does not match an existing session (since a syn would start a new session)&lt;BR /&gt;&lt;BR /&gt;This is most commonly caused my asymmetric traffic where client-server packets follow a different route than the server-client packets&lt;BR /&gt;&lt;BR /&gt;So you will want to find the reason for these flows and try to fix them as this is not a firewall issue&lt;BR /&gt;There may be a need for U-turn NAT &lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Configure-U-Turn-NAT/ta-p/65081" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Configure-U-Turn-NAT/ta-p/65081&lt;/A&gt;</description>
      <pubDate>Sun, 18 Dec 2016 21:24:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-deny-all-policy-reason-non-syn-tcp/m-p/133406#M47212</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-12-18T21:24:33Z</dc:date>
    </item>
  </channel>
</rss>

