<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strange packet drop in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/strange-packet-drop/m-p/193847#M58074</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;In the logs there is the one that says 'Incomplete' for the application. This happens for several reasons, but in my experience, it is 95% of the time a routing issue between the hosts. Could be asymmetric routing or something else.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jan 2018 15:11:19 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-01-04T15:11:19Z</dc:date>
    <item>
      <title>Strange packet drop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-packet-drop/m-p/193804#M58067</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a PA820 in active/passive mode who has a strange behaviour. I have created a rule that permits that traffic but the device drops it. I see "allow"in the logs, but with a capture I can clearly see the SYN in the dropped section and not "syn/ack" and "ack".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have also tried to put an "any/any" rules, it matches but the behaviour is the same,&lt;/P&gt;&lt;P&gt;I have put "any" in the Application and Services fields and also disabled any antivirus check.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;Attached the two images.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_log_forum.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13126i66D67AB1594C6F0F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_log_forum.png" alt="PA_log_forum.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_rule_forum.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13127i3C4257BB483E75E0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_rule_forum.png" alt="PA_rule_forum.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2018 10:46:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-packet-drop/m-p/193804#M58067</guid>
      <dc:creator>Shye80</dc:creator>
      <dc:date>2018-01-04T10:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: Strange packet drop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-packet-drop/m-p/193847#M58074</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;In the logs there is the one that says 'Incomplete' for the application. This happens for several reasons, but in my experience, it is 95% of the time a routing issue between the hosts. Could be asymmetric routing or something else.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2018 15:11:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-packet-drop/m-p/193847#M58074</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-04T15:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Strange packet drop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-packet-drop/m-p/193864#M58077</link>
      <description>&lt;P&gt;'incomplete' in the application means the initial syn packet was allowed to pass through the firewall, but a returning ack was never seen.&lt;/P&gt;
&lt;P&gt;This could be a routing issue as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt; mentions, NAT not being applied properly or the remote host simply not responding to your connection (due to it being down our out of resources,...)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;best way to troubleshoot is to verify if NAT is applied in the egress stage packetcapture and traceroute to verify your packets are following an appropriate route&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2018 15:52:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-packet-drop/m-p/193864#M58077</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-01-04T15:52:11Z</dc:date>
    </item>
  </channel>
</rss>

