<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: message security over http in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149177#M49745</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10226"&gt;@dieter_b&lt;/a&gt;&amp;nbsp;if you don't have a profile associated with it the firewall should never issue a reset, since it should just be allowing the traffic. I would take a look at what the identified applications TCP Timeout, TCP Half Closed, and TCP Time Wait settings are. Just for giggles customize those to something completely unreasonably high and see if the issue persists. The firewall may not be seeing any type of response from the other server and terminating the session because it believes the session has gone stale.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Good idea, I will give this a try. I just hope our session limit is not reached, since we're talking about http &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Mar 2017 14:25:32 GMT</pubDate>
    <dc:creator>dieter_b</dc:creator>
    <dc:date>2017-03-23T14:25:32Z</dc:date>
    <item>
      <title>message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/148656#M49623</link>
      <description>&lt;P&gt;How does PA handle message security over http ?&lt;/P&gt;&lt;P&gt;Whereas https secures the communication, message security secures the content.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would expect PA does not touch http content. But we are having issues with an application that connects to a partners server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Application throws this error, I guess it's a pretty default .net error:&lt;/P&gt;&lt;P&gt;An error occurred while receiving the HTTP response to http://blabla/blablaConnectorHostService.svc. This could be due to the service endpoint binding not using the HTTP protocol. This could also be due to an HTTP request context being aborted by the server (possibly due to the service shutting down).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Partner says it has something to do with large transfers that get interrupted. I'm guessing it happens somewhere on the firewall.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2017 15:22:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/148656#M49623</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2017-03-21T15:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/148659#M49625</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good place to start is a traffic logs for this particular session (s), session-end reason and application identification. What can you see?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2017 17:20:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/148659#M49625</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-21T17:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/148664#M49628</link>
      <description>&lt;P&gt;Look at your threat logs and make sure the PA isn't resseting&amp;nbsp;something due to it identification&amp;nbsp;anything as a possible threat.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2017 17:11:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/148664#M49628</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-21T17:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/148665#M49629</link>
      <description>&lt;P&gt;good point&amp;nbsp;&lt;SPAN&gt;threat logs, totally forgot about them :0 busy day............&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2017 17:15:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/148665#M49629</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-21T17:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/148829#M49656</link>
      <description>&lt;P&gt;Right now the application seems to generate no logging at all...&lt;/P&gt;&lt;P&gt;I will get back when I have something useful &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 12:56:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/148829#M49656</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2017-03-22T12:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/148830#M49657</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10226"&gt;@dieter_b&lt;/a&gt;&amp;nbsp;make sure that you actually have logging enabled on your security policies that you suspect this should be hitting, sounds like you likely don't have it set to log at start or end.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 13:11:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/148830#M49657</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-22T13:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/148831#M49658</link>
      <description>&lt;P&gt;or traffic is not even hitting that policy!&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 13:12:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/148831#M49658</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-22T13:12:34Z</dc:date>
    </item>
    <item>
      <title>Re: message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149102#M49728</link>
      <description>&lt;P&gt;I have logging enabled for start and end. And I'm pretty sure the traffic should hit the rule. Logging is enabled for almost everything (except for some dns, ntp and "internal" traffic). So if there would be a deny somewhere or a threat blocked, I would see it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So here's the fun part:&lt;/P&gt;&lt;P&gt;If there's no user-to-ip mapping for the clients ip, nothing is logged.&lt;/P&gt;&lt;P&gt;If there is a user-to-ip mapping, I have log entries.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Session end reasons are tcp-rst-from-client and tcp-fin, so pretty normal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Known user or not should not even matter. The rule allows Any app/service for Any user from clients fixed ip. And for troubleshooting I don't even have a security profile attached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In a wireshark capture on the client I only get a dry RST from the server. But that could be the firewall sending a RST.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would the option "Disable Server Response Inspection" do any good ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 10:43:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149102#M49728</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2017-03-23T10:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149103#M49729</link>
      <description>&lt;P&gt;&lt;SPAN&gt;DSRI option may be useful under heavy server load conditions. &amp;nbsp;Post the security policy here same as PCAP snip. Firewall, as far as l&amp;nbsp;know, will not intercept the session (in your case as you can see tcp-rst-from-client and tcp-fin logs). If the firewall sends you RST you should see its IP address as a&amp;nbsp;source. Firewall only generates a logs based on how it seing the&amp;nbsp;session between client-server.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 11:48:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149103#M49729</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-23T11:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149111#M49731</link>
      <description>&lt;P&gt;That's all there is to the rule:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8345i22547D74DADB34CB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rule.png" alt="rule.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry I can't give PCAP, would reveal too much info.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You say firewall ip would be seen as source ip of RST. That's not the case so I assume RST is really coming from remote server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone confirm PA does not alter http content ? There's no such thing as http message security decryption ? Or an option that blocks encrypted http messages ?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 12:39:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149111#M49731</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2017-03-23T12:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149121#M49733</link>
      <description>&lt;P&gt;This is how l understand&amp;nbsp;3-way handshake :0 If you are not using user-id on trust zone please disable this&amp;nbsp;future under the&amp;nbsp;zone configuration:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ID.PNG" style="width: 699px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8348i22BAC2C783000534/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ID.PNG" alt="ID.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 12:50:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149121#M49733</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-23T12:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149131#M49736</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10226"&gt;@dieter_b&lt;/a&gt;&amp;nbsp;if you don't have a profile associated with it the firewall should never issue a reset, since it should just be allowing the traffic. I would take a look at what the identified applications TCP Timeout, TCP Half Closed, and TCP Time Wait settings are. Just for giggles customize those to something completely unreasonably high and see if the issue persists. The firewall may not be seeing any type of response from the other server and terminating the session because it believes the session has gone stale.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 13:00:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149131#M49736</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-23T13:00:16Z</dc:date>
    </item>
    <item>
      <title>Re: message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149176#M49744</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;This is how l understand&amp;nbsp;3-way handshake :0 If you are not using user-id on trust zone please disable this&amp;nbsp;future under the&amp;nbsp;zone configuration&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;We heavily use user-id for that zone. But for some traffic, that doesn't matter. User Any solves that problem for most cases.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 14:23:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149176#M49744</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2017-03-23T14:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149177#M49745</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10226"&gt;@dieter_b&lt;/a&gt;&amp;nbsp;if you don't have a profile associated with it the firewall should never issue a reset, since it should just be allowing the traffic. I would take a look at what the identified applications TCP Timeout, TCP Half Closed, and TCP Time Wait settings are. Just for giggles customize those to something completely unreasonably high and see if the issue persists. The firewall may not be seeing any type of response from the other server and terminating the session because it believes the session has gone stale.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Good idea, I will give this a try. I just hope our session limit is not reached, since we're talking about http &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 14:25:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149177#M49745</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2017-03-23T14:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149347#M49783</link>
      <description>&lt;P&gt;I have pretty much default general session timeouts&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sestimeouts.png" style="width: 402px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8386i07914C132FA7A732/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="sestimeouts.png" alt="sestimeouts.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Connections are dropped way faster than that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where can I find application specific timeouts ?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 11:20:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149347#M49783</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2017-03-24T11:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149348#M49784</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73374"&gt;@dieterb&lt;/a&gt; wrote:&lt;BR /&gt;&lt;BR /&gt;&lt;P&gt;Where can I find application specific timeouts ?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;nevermind, found it (Objects -&amp;gt; Applications)&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 11:22:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149348#M49784</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2017-03-24T11:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: message security over http</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149677#M49821</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73374"&gt;@dieterb&lt;/a&gt; wrote:&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;This is how l understand&amp;nbsp;3-way handshake :0 If you are not using user-id on trust zone please disable this&amp;nbsp;future under the&amp;nbsp;zone configuration&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;We heavily use user-id for that zone. But for some traffic, that doesn't matter. User Any solves that problem for most cases.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Ok, problem is indeed related to user-id: http traffic triggers an NTLM authentication request (if there's no user-ip-mapping) on the firewall. Application did not know how to handle that and resets session.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The trick was to put the client's fixed IP address in the exclude list for user identification for the zone. Not only in the user-id agent exclude list and/or PA user-id exclude list (what most of the time just worked because it was no http traffic).&lt;/P&gt;&lt;P&gt;Now the firewall doesn't ask for NTLM auth and traffic passes fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also found out that it's not possible to disable NTLM entirely, is that correct ? Maybe because of captive portal ?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 14:55:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/message-security-over-http/m-p/149677#M49821</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2017-03-27T14:55:25Z</dc:date>
    </item>
  </channel>
</rss>

