<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: aged out vs unknown in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-vs-unknown/m-p/173522#M54603</link>
    <description>&lt;P&gt;According to the admin guide:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/monitoring/syslog-field-descriptions" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/monitoring/syslog-field-descriptions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;unknown&lt;/STRONG&gt;—This value applies in the following situations:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;-Session terminations that the preceding reasons do not cover (for example, a&amp;nbsp;clear session allcommand).&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;-For logs generated in a PAN-OS release that does not support the session end reason field (releases older than PAN-OS 6.1), the value will be&amp;nbsp;unknownafter an upgrade to the current PAN-OS release or after the logs are loaded onto the firewall.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;-In Panorama, logs received from firewalls for which the PAN-OS version does not support session end reasons will have a value of&amp;nbsp;unknown&amp;nbsp;.&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Aug 2017 02:05:41 GMT</pubDate>
    <dc:creator>emr_1</dc:creator>
    <dc:date>2017-08-29T02:05:41Z</dc:date>
    <item>
      <title>aged out vs unknown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-vs-unknown/m-p/173471#M54595</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;From some pc session end reason for dns traffic shows 'aged out'&lt;BR /&gt;and for some shows 'unknown'&lt;BR /&gt;what could be the reason&lt;BR /&gt;internet traffic from the pc which shows aged out are really slow&lt;BR /&gt;any help&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2017 18:31:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-vs-unknown/m-p/173471#M54595</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-08-28T18:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: aged out vs unknown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-vs-unknown/m-p/173479#M54596</link>
      <description>&lt;P&gt;DNS uses UDP, so session end reason will be "aged-out", which is correct.&lt;/P&gt;&lt;P&gt;Do you have any other users, which are hitting the same policy and experiencing the same issue?&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;'unknown' &amp;nbsp;in the application tab could be due to several reasons: not enough&amp;nbsp;info for the app-id engine to identify the application (3-way handshake is not completed, routing issue etc).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2017 19:24:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-vs-unknown/m-p/173479#M54596</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-28T19:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: aged out vs unknown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-vs-unknown/m-p/173520#M54601</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;From other pc's dns traffic shows unknown.This is what I confused&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 01:45:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-vs-unknown/m-p/173520#M54601</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-08-29T01:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: aged out vs unknown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-vs-unknown/m-p/173522#M54603</link>
      <description>&lt;P&gt;According to the admin guide:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/monitoring/syslog-field-descriptions" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/monitoring/syslog-field-descriptions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;unknown&lt;/STRONG&gt;—This value applies in the following situations:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;-Session terminations that the preceding reasons do not cover (for example, a&amp;nbsp;clear session allcommand).&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;-For logs generated in a PAN-OS release that does not support the session end reason field (releases older than PAN-OS 6.1), the value will be&amp;nbsp;unknownafter an upgrade to the current PAN-OS release or after the logs are loaded onto the firewall.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;-In Panorama, logs received from firewalls for which the PAN-OS version does not support session end reasons will have a value of&amp;nbsp;unknown&amp;nbsp;.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 02:05:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-vs-unknown/m-p/173522#M54603</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2017-08-29T02:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: aged out vs unknown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-vs-unknown/m-p/173523#M54604</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for the reply .&lt;/P&gt;&lt;P&gt;My concern is why for some dns traffic ,it is unknown ' and for some it is aged out&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 02:12:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-vs-unknown/m-p/173523#M54604</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-08-29T02:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: aged out vs unknown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-vs-unknown/m-p/173561#M54606</link>
      <description>&lt;P&gt;Unknown-tcp means the firewall captured the three-way TCP handshake, but the application was not identified. This may be due to the use of a custom application for which the firewall does not have signatures.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Seesion end reason is (n/a or unknown): PAN-OS provides a&amp;nbsp;&lt;/SPAN&gt;session end reason&lt;SPAN&gt;&amp;nbsp;field for traffic logs. This field only applies to logs of &lt;STRONG&gt;subtype&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;end&lt;/STRONG&gt;&lt;SPAN&gt;. For all other subtypes, the value is&amp;nbsp;&lt;/SPAN&gt;not applicable (N/A)(example: logs of subtype: start it will show n/a)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess you have enabled both&amp;nbsp;&lt;SPAN&gt;Log at Session Start,&amp;nbsp;Log at Session end on the associated security rule thats why it's showing both unknwon and and aged out on the session end reason, DNS uses UDP protocols so its obivisouly aged-out always.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i dont think this caused internt slowness on the PC.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 07:44:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-vs-unknown/m-p/173561#M54606</guid>
      <dc:creator>KotreshaMC</dc:creator>
      <dc:date>2017-08-29T07:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: aged out vs unknown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aged-out-vs-unknown/m-p/173666#M54635</link>
      <description>&lt;P&gt;Can you please post DNS request traffic logs from the affected PC:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aged-out.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10958i9C07C41F9FBB2DAF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="aged-out.PNG" alt="aged-out.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure to select &amp;nbsp;Bytes Sent/Received columns&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 14:52:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aged-out-vs-unknown/m-p/173666#M54635</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-29T14:52:10Z</dc:date>
    </item>
  </channel>
</rss>

