<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rules with schedules failing intermittantly in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203291#M59903</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yup I opened a case with TAC yesterday and am collecting information for them now. I do have a lot of issues that seem to fall outside of the norm&lt;/P&gt;</description>
    <pubDate>Fri, 02 Mar 2018 16:02:37 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2018-03-02T16:02:37Z</dc:date>
    <item>
      <title>Rules with schedules failing intermittantly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203154#M59879</link>
      <description>&lt;P&gt;I recently upgraded to OS 7.1.15 on my PA 5050, I have two rules with schedules on them and have had for over a year.&amp;nbsp; In the traffic logs it was showing the traffic going back and forth between denying and allowing the traffic.&amp;nbsp; When I removed the schedules they worked with no issues. Any ideas what could be going on?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Mar 2018 20:32:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203154#M59879</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-01T20:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: Rules with schedules failing intermittantly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203251#M59890</link>
      <description>&lt;P&gt;what does the policy look like and how is the schedule set? are you seeing both allow AND deny happening on the same rule?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the behavior for an &lt;EM&gt;allow&lt;/EM&gt; rule, with a schedule 9am-11am should be:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;connection at 8:50 is processed by a rule below the one with schedule, blocked/allowed by a different rule&lt;/LI&gt;
&lt;LI&gt;connection at 9:01 is allowed by rule&lt;/LI&gt;
&lt;LI&gt;(new) connection at 11:01 is processed by a rule below the schedule one, existing session that was allowed by policy is still active and will be left to live it's life (unless action is taken to terminate the session)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the behavior for a&lt;EM&gt; deny&lt;/EM&gt; rule, with a schedule 9am-11am should be:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;connection at 8:50 is processed by a rule below the one with schedule, blocked/allowed by a different rule&lt;/LI&gt;
&lt;LI&gt;connection at 9:01 is blocked by rule&lt;/LI&gt;
&lt;LI&gt;(new) connection at 11:01 is processed by a rule below the schedule one, here is a bit of a caveat: if appID is let to create a session before hitting the block rule (eg your block rule is built with applications rather than ports, a session first needs to be created before being able to block based on the app) an existing 'discard phase' session could still be blocking packets matching the tuples after the schedule ends (this is measured in seconds to a few minutes, usually)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;so if you could provide a little more detail, that would be helpful &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 10:30:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203251#M59890</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-02T10:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Rules with schedules failing intermittantly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203266#M59895</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Yes I am seeing both allow and deny on the same rule within seconds.&amp;nbsp; Its been working consistently for over a year until this week. I upgraded the PA to 7.1.15 from 7.1.13 a week ago. I also reset the regions around the same time. This was allowing our student access to certain server/application from a specific wireless IP range to a specific IP. the rules are built with applications not ports, we took off several things(put them back if it didn't fix it) before we found that removing the schedule fixed it&lt;/P&gt;&lt;P&gt;Here is the schedule information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="schedule.PNG" style="width: 549px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14092iCC8AEB54D08D97EC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="schedule.PNG" alt="schedule.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 13:39:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203266#M59895</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-02T13:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: Rules with schedules failing intermittantly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203269#M59896</link>
      <description>&lt;P&gt;hm... that's not supposed to happen...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the schedule should make the rules 'invisible' outside of the schedule so they get passed by when the 'decission making process' happens, not reverse the action ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have you reached out to support on this already? If not I'd do that asap &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 13:46:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203269#M59896</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-02T13:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Rules with schedules failing intermittantly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203270#M59897</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is a sample of the traffice and is bouncing betweening allowing and dropping the traffic with in minutes. It is being denied by the clean up rule and goes off and on through the rule designed to allow the traffic&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="traffic.PNG" style="width: 781px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14093i187E5388DDE20064/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="traffic.PNG" alt="traffic.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 13:47:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203270#M59897</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-02T13:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: Rules with schedules failing intermittantly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203272#M59898</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ok, that looks more normal than I first expected &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;would you mind adding the rest of the log in there to get a more complete view? (feel free to obfuscate sensitive data ofcourse)&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 13:49:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203272#M59898</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-02T13:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: Rules with schedules failing intermittantly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203274#M59899</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I feel like a politician redacting classified information this isn't pretty but here it is&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="traffic.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14094i99BBDCA89662E7B1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="traffic.PNG" alt="traffic.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 13:58:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203274#M59899</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-02T13:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: Rules with schedules failing intermittantly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203287#M59902</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;Ok, that does look pretty weird&lt;/P&gt;
&lt;P&gt;I fear you will need to have a little chat with support about this&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 14:55:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203287#M59902</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-02T14:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: Rules with schedules failing intermittantly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203291#M59903</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yup I opened a case with TAC yesterday and am collecting information for them now. I do have a lot of issues that seem to fall outside of the norm&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 16:02:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203291#M59903</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-02T16:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: Rules with schedules failing intermittantly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203292#M59904</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Forgot to say is it weird cause of the way I redacted it or how it is behaving LOL &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 16:03:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203292#M59904</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-02T16:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Rules with schedules failing intermittantly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203339#M59912</link>
      <description>&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt; haha! Because of the behavior, I won't comment on your 'paint' skillz &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;</description>
      <pubDate>Fri, 02 Mar 2018 18:57:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-with-schedules-failing-intermittantly/m-p/203339#M59912</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-02T18:57:56Z</dc:date>
    </item>
  </channel>
</rss>

