<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Application Incomplete For One Site But OK at Another in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153701#M50714</link>
    <description>&lt;P&gt;So that solved it. The reason is was more difficult to troubleshoot is that our logging is at the end of a conversation so there was no evidence that traffic I was sending to the remote site was passing through this one PAN before the tunneling PAN. Once I modified PBR on an adjacent router to avoid the 1st PAN then the conversation was able to maintain integrity to the SSL server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lessons for me to remember: Log end of session means you have no visibility on one way traffic through your FW. (Tho perhaps I could have&amp;nbsp;seen it in a packet capture)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"show route" on a Cisco router does not inform you that PBR may be happening and over-riding what you see in your route table.&lt;/P&gt;</description>
    <pubDate>Sat, 22 Apr 2017 00:26:29 GMT</pubDate>
    <dc:creator>palomed</dc:creator>
    <dc:date>2017-04-22T00:26:29Z</dc:date>
    <item>
      <title>Application Incomplete For One Site But OK at Another</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153078#M50561</link>
      <description>&lt;P&gt;I have an IPSec tunnel with source address NATting to a partner. 443 web traffic from site A triggers the IKE and the IPSEC-SA session. In PAN monitoring the application is correctly identified as SSL and in my browser I pull up the site from the partner without an issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;443 web traffic from site B triggers IKE and IPSEC-SA so that tunnel is ostensibly up. BUT the clients get a message that the site can't be reached in their browser "took too long to respond". And in monitoring on the PAN the Application status is "incomplete". However the record shows the src address was properly NATted and&amp;nbsp;allowed just like site A. Site B and site A have different&amp;nbsp;address blocks but get NATted and are permitted with the same policy.&lt;BR /&gt;&lt;BR /&gt;Can anyone recommend the right tools (pcap) for me to see exactly where the conversation from site B is failing? Any other thoughts appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2017 22:31:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153078#M50561</guid>
      <dc:creator>palomed</dc:creator>
      <dc:date>2017-04-18T22:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: Application Incomplete For One Site But OK at Another</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153098#M50567</link>
      <description>&lt;P&gt;So you have 2 sites- SiteA and SiteB and partner seems to be third - SiteC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Application is identified as SSL only after TCP 3way handshake is done and SSL negotiation starts.&lt;/P&gt;&lt;P&gt;So most likely SiteB sends SYN but no SYN ACK is returned to continue conversation to SiteC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It can be either security policy not permitting traffic at SiteC from SiteB or return route is missing in SiteC towards SiteB local subnet (in case there is route based VPN solution at SiteC like Palo).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 03:48:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153098#M50567</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-04-19T03:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: Application Incomplete For One Site But OK at Another</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153116#M50571</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;has already mentioned "incomplete" in application tab 99% means no 3-way handshake for TCP communication.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can do PCAP following the guide below:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Using-Packet-Filtering-through-the-WebGUI/ta-p/56363" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Using-Packet-Filtering-through-the-WebGUI/ta-p/56363&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you know if your server knows how to get to the site B when responding to the&amp;nbsp;SYN request? Do you know if &amp;nbsp;SYN packets from site B actually hitting the server?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 05:53:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153116#M50571</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-19T05:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: Application Incomplete For One Site But OK at Another</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153121#M50573</link>
      <description>&lt;P&gt;Monitor &amp;gt; Traffic&lt;/P&gt;&lt;P&gt;Add&amp;nbsp;Egress interface, Packets sent and Packets received columns.&lt;/P&gt;&lt;P&gt;If you see packets sent 1, packets received 0 and egress interface is correct tunnel interface towards SiteC (partner) then issue is at other side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="packets.PNG" style="width: 330px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8856iD7D8EF8C5CFDF95F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="packets.PNG" alt="packets.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 06:03:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153121#M50573</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-04-19T06:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: Application Incomplete For One Site But OK at Another</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153297#M50629</link>
      <description>&lt;P&gt;I added those colums. But everything is the same except for the number of bytes and packets are far smaller for the failed conversations than the successful. e.g. in my first successful conversation it's 5k while user from other site 540 bytes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ingress and egress (tunnel.x) are the same. We NAT to the same source address to the server at the far end would hear traffic coming from the same&amp;nbsp;source. A difference is that the failed conversations only end with a tcp-rst-from-server where as my good conversations have many tcp-rst-from-server.&lt;BR /&gt;&lt;BR /&gt;I ran a packet capture and it looks to me like the bad and the good both have a SYN, SYN ACK, ACK. But in my case the next packet is a SYN for TLS Hello and then a whole TLS exchange occurs. Based on that I made sure the user had TLS enabled, tried new browser, tried a new operating system (win 10, win 7, explorer, chrome, ff) - they all have the same result. Application incomplete and TLS Hello is never sent to the server. I've looked through syslogs for rejected traffic. Still no go.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another general difference&amp;nbsp;when I look at wireshark is that the pcap from the failed situation is mostly all gray with some black/red where as my good is light blue for the most part.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ScrnGrab1277 170419 17.53.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8870i61ABD67E908ECAD9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ScrnGrab1277 170419 17.53.jpg" alt="ScrnGrab1277 170419 17.53.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Bad&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ScrnGrab1279 170419 17.54.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8871i9218F429411D59D7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ScrnGrab1279 170419 17.54.jpg" alt="ScrnGrab1279 170419 17.54.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 00:57:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153297#M50629</guid>
      <dc:creator>palomed</dc:creator>
      <dc:date>2017-04-20T00:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Application Incomplete For One Site But OK at Another</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153326#M50633</link>
      <description>&lt;P&gt;That is weird.&lt;/P&gt;&lt;P&gt;3way handshake happens and client does not initiate SSL session.&lt;/P&gt;&lt;P&gt;This packet capture is taken on firewall right?&lt;/P&gt;&lt;P&gt;Can you install Wireshark and take packet capture on problematic workstation.&lt;/P&gt;&lt;P&gt;Do you see same result?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 07:19:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153326#M50633</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-04-20T07:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: Application Incomplete For One Site But OK at Another</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153328#M50635</link>
      <description>&lt;P&gt;Sorry I was imaging this connection differently. &amp;nbsp;So both clients at the site A and B using the same tunnel in order to get to teh&amp;nbsp;https website. If 3 way handshake ok them better to run pcap&amp;nbsp;from the client&amp;nbsp;side as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;has suggested and compare if need be between the one you took from the palo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 08:42:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153328#M50635</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-20T08:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: Application Incomplete For One Site But OK at Another</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153441#M50657</link>
      <description>&lt;P&gt;I think I have the issue resolved. It looks like before it hits the tunnel firewall some egress traffic goes through another firewall. But that portion does not return though that firewall. So the three way handshake succeeds as the synack makes it back to the client but TLS fails for the integrity of the conversation as a whole. Waiting for approvals of some PBR changes to verify my theory.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 22:01:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153441#M50657</guid>
      <dc:creator>palomed</dc:creator>
      <dc:date>2017-04-20T22:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Application Incomplete For One Site But OK at Another</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153473#M50662</link>
      <description>&lt;P&gt;Are you applying PBF based on TCP application in other firewall?&lt;/P&gt;&lt;P&gt;That is bad idea as application can shift during single session (incomplete &amp;gt; web-browsing &amp;gt; sharepoint-base &amp;gt; sharepoint-admin etc).&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 12:12:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153473#M50662</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-04-21T12:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: Application Incomplete For One Site But OK at Another</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153701#M50714</link>
      <description>&lt;P&gt;So that solved it. The reason is was more difficult to troubleshoot is that our logging is at the end of a conversation so there was no evidence that traffic I was sending to the remote site was passing through this one PAN before the tunneling PAN. Once I modified PBR on an adjacent router to avoid the 1st PAN then the conversation was able to maintain integrity to the SSL server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lessons for me to remember: Log end of session means you have no visibility on one way traffic through your FW. (Tho perhaps I could have&amp;nbsp;seen it in a packet capture)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"show route" on a Cisco router does not inform you that PBR may be happening and over-riding what you see in your route table.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Apr 2017 00:26:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-incomplete-for-one-site-but-ok-at-another/m-p/153701#M50714</guid>
      <dc:creator>palomed</dc:creator>
      <dc:date>2017-04-22T00:26:29Z</dc:date>
    </item>
  </channel>
</rss>

