<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: palo alto interrupting  web server traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146414#M49185</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The server is 192.168.10.100:2048&lt;/P&gt;&lt;P&gt;and the client is &amp;nbsp;: 192.168.2.25&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the &amp;nbsp;capture -rx from the pa&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pa.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8017i5C60CC5BC65AED8A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pa.JPG" alt="pa.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sometimes can access the port 2048 .That is the syptom. &amp;nbsp;sometimes cannot &amp;nbsp;.&lt;/P&gt;&lt;P&gt;In my capture there &amp;nbsp;are tcp port numbers resued ,multiple retransmsiion and tcp previous segment not captured &amp;nbsp;.&lt;/P&gt;&lt;P&gt;These are indicating to any problems&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Mar 2017 15:30:40 GMT</pubDate>
    <dc:creator>sib2017</dc:creator>
    <dc:date>2017-03-07T15:30:40Z</dc:date>
    <item>
      <title>palo alto interrupting  web server traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146224#M49158</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have web server , in some computers website load properly and &amp;nbsp;some &amp;nbsp;not loading properly .&lt;/P&gt;&lt;P&gt;I suspect pa is interrupting &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2017 19:09:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146224#M49158</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2017-03-06T19:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: palo alto interrupting  web server traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146232#M49159</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11223"&gt;@sib2017&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is actually happening? How is your policy looks like (profiles) etc.&amp;nbsp;Traffic logs for the&amp;nbsp;affected users? What I&amp;nbsp;am usually doing&amp;nbsp;&lt;SPAN&gt;(not always possible in the production)&lt;/SPAN&gt;&amp;nbsp;is taking one of the affected users/PCs and creating a "clear" test policy without anything purely from source to the destination permit any any&amp;nbsp;(no profiles) and see what is happening. Same issue? Removing test policy and checking the client-server side only :0 as this is not PA issue.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 15:35:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146232#M49159</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-07T15:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: palo alto interrupting  web server traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146256#M49165</link>
      <description>&lt;P&gt;your issue is very vague. if you are talking about the same website on multiple computers, the first thing to check is to see if each computer is hitting the same rule for the same website in the traffic log. if so, you should also look at the reason for the session end, if it's a tcp-fin or timed out or a reset of some sort. also consider the threat log if you have a threat prevention policy in place. you also need to consider if all computers are using the same browser/version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;there are many places something like this could go wrong, but unless your rules are applied subjectively/unevenly, the firewall is probably the least likely source of the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2017 22:41:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146256#M49165</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-03-06T22:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: palo alto interrupting  web server traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146414#M49185</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The server is 192.168.10.100:2048&lt;/P&gt;&lt;P&gt;and the client is &amp;nbsp;: 192.168.2.25&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the &amp;nbsp;capture -rx from the pa&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pa.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8017i5C60CC5BC65AED8A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pa.JPG" alt="pa.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sometimes can access the port 2048 .That is the syptom. &amp;nbsp;sometimes cannot &amp;nbsp;.&lt;/P&gt;&lt;P&gt;In my capture there &amp;nbsp;are tcp port numbers resued ,multiple retransmsiion and tcp previous segment not captured &amp;nbsp;.&lt;/P&gt;&lt;P&gt;These are indicating to any problems&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 15:30:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146414#M49185</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2017-03-07T15:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: palo alto interrupting  web server traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146415#M49186</link>
      <description>&lt;P&gt;What can you see in the traffic logs when accessing this server? How the PA identifies this port TCP&amp;nbsp;&lt;SPAN&gt;2048 under which application? How is your security policy looks like?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 15:36:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146415#M49186</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-07T15:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: palo alto interrupting  web server traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146494#M49208</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per the screenshot there is &amp;nbsp;SYN-ACK and corresponding (5 and 6) and finally client sent an ACK (11 and 12)&amp;nbsp;&lt;/P&gt;&lt;P&gt;so the server listening on port 2048 , is'nt it ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 17:56:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146494#M49208</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2017-03-07T17:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: palo alto interrupting  web server traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146498#M49211</link>
      <description>&lt;P&gt;A couple things could help clear it up if you can repost the screenshot:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Remove or hide the SNR and Rate columns in Wireshark.&lt;/LI&gt;&lt;LI&gt;Reduce the sizes of the IP columns to expand the other columns that have "..." so we can see the full data.&lt;/LI&gt;&lt;LI&gt;I assume the "delta" column is delta time between displayed frames, but expanding that field could help (or change your time display format to "Seconds since previous displayed packet".&lt;/LI&gt;&lt;LI&gt;Grab a packet capture of a working client to compare the flow.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like we see two sets of three-way handshakes here, both on destination port 2048. Both handshakes are complete, and there seems to be an exchange of data (client sends PSH flags on frames 11-12, 13-14, and 15-16; the server sends a reply in frames 17-18).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the traffic is known to Wireshark, you can also decode it as the known traffic (if it's TLS for example, right-click on any frame and choose Decode As..., and specify port 2048 to be whatever the actual traffic is).&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 18:06:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146498#M49211</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-03-07T18:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: palo alto interrupting  web server traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146510#M49216</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28203" target="_self"&gt;&lt;SPAN class=""&gt;gwesson&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thank you for the &amp;nbsp;reply &amp;nbsp;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have adjusted the view as you said . And &amp;nbsp;i did decode as 'ssl'&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pa.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8022i742D6919EE438FDB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pa.JPG" alt="pa.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for the incenvenience&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 19:28:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146510#M49216</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2017-03-07T19:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: palo alto interrupting  web server traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146511#M49217</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, correct. The server is listening on TCP&amp;nbsp;&lt;SPAN&gt;2048 port (no doubt) but same time we can see SSL traffic to the same server. But what l am trying to understand is how is the PA seeing this traffic and how it is identifying? Under which application. This all info is under Monitoring tab on PA.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 21:07:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146511#M49217</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-07T21:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: palo alto interrupting  web server traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146518#M49219</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;&amp;nbsp;is bringing up a really good point. If the only information that your giving is a wireshark it doesn't actually tell us what the Palo Alto itself is seeing. Knowing what your security policy for the traffic looks like, how the Palo Alto is seeing the termination, all of that other good information.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 21:02:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146518#M49219</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-07T21:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: palo alto interrupting  web server traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146588#M49229</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Unfortunately &amp;nbsp;i Changed this port&amp;nbsp;from 2048 to 80 and all the logs were over written .&lt;/P&gt;&lt;P&gt;When i change the app to port 80 , its&amp;nbsp;seems working fine .There is some few old logs &amp;nbsp;(Rules are same )&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pa2.png" style="width: 406px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8032i3F0F2594BDA359A7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pa2.png" alt="pa2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And there are some records shows&amp;nbsp;session end reason is &lt;STRONG&gt;unknown&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thanks&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2017 07:21:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interrupting-web-server-traffic/m-p/146588#M49229</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2017-03-08T07:21:18Z</dc:date>
    </item>
  </channel>
</rss>

