<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Passive firewall initiating syslog connection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-initiating-syslog-connection/m-p/211376#M61669</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/88204"&gt;@amey_13&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What interface are you trying to make the syslog connection to? Unless it's the management interface this isn't going to work.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 23 Apr 2018 17:50:12 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-04-23T17:50:12Z</dc:date>
    <item>
      <title>Passive firewall initiating syslog connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-initiating-syslog-connection/m-p/211272#M61648</link>
      <description>&lt;P&gt;We've syslog configured on devices with tcp protocol on port 515. Our passive device syslog connection is breaking every 300 seconds. Can you help in understand why passive palo alto not sending keep-alive?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 01:44:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-initiating-syslog-connection/m-p/211272#M61648</guid>
      <dc:creator>amey_13</dc:creator>
      <dc:date>2018-04-23T01:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: Passive firewall initiating syslog connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-initiating-syslog-connection/m-p/211376#M61669</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/88204"&gt;@amey_13&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What interface are you trying to make the syslog connection to? Unless it's the management interface this isn't going to work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 17:50:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-initiating-syslog-connection/m-p/211376#M61669</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-23T17:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Passive firewall initiating syslog connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-initiating-syslog-connection/m-p/211429#M61684</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;, It is management interface only. We are getting logs in Monitor &amp;gt; system saying syslog connection broken and in next second syslog connection is established, this logs are with High severity.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 05:07:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-initiating-syslog-connection/m-p/211429#M61684</guid>
      <dc:creator>amey_13</dc:creator>
      <dc:date>2018-04-24T05:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: Passive firewall initiating syslog connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-initiating-syslog-connection/m-p/211520#M61704</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/88204"&gt;@amey_13&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Assuming that the Active and Passive firewall are not directly plugged into the same switch for management access, have you verified that it isn't actually losing connection to the syslog server? It may be that it actually is losing this connection for a second, hence why the logs are generating.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 13:25:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-initiating-syslog-connection/m-p/211520#M61704</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-24T13:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: Passive firewall initiating syslog connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-initiating-syslog-connection/m-p/211856#M61767</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The firewalls (active/passive) makes a tcp connection with syslog server virtual ip configured on load balancer. On load balancer we have tcp idle timeout set to 300 seconds. The load balancer is sending reset packet to passive device after 300 seconds which breaks the connection. &lt;STRONG&gt;My query is why the passive device not sending any keep-alive to keep the tcp connection active???&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Also if it sends keep-alive what is it default time, is it more then 300 seconds.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thanks.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 12:40:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-initiating-syslog-connection/m-p/211856#M61767</guid>
      <dc:creator>amey_13</dc:creator>
      <dc:date>2018-04-26T12:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Passive firewall initiating syslog connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-initiating-syslog-connection/m-p/211858#M61768</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/88204"&gt;@amey_13&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;To the best of my knowledge the firewall doesn't send a keep-alive, and will allow the connection to the syslog server to close if enough logs are not generated during this time frame; unlike the ESM server that actually sends a keep-alive message that you configure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 13:00:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-initiating-syslog-connection/m-p/211858#M61768</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-26T13:00:28Z</dc:date>
    </item>
  </channel>
</rss>

