<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Weirdest thing I have seen in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/weirdest-thing-i-have-seen/m-p/221831#M63833</link>
    <description>&lt;P&gt;Having a weird issue. I installed an 820. I have internet traffic being NAT'ed. My gateway is set to the Palo. My hops to the internet look like this&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Windows Box ---&amp;gt; Palo 820 --&amp;gt; Cisco Pix --&amp;gt; Internet Provider&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pretty basic.. I have a rule in place to allow all internal to 0.0.0.0/0 443, 80..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can get to anything google even your tube just fine. works fast no hesitation. If I go anywhere else ( MSN, Yahoo, CNN) I get nothing. Traffic drops.&amp;nbsp; I cant figure this out for the life of me.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got a pcap going to google and going to red.com (52.73.0.154)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can get to google but not red. I cant find a difference. Any ideas would be appreciated.&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jul 2018 19:59:58 GMT</pubDate>
    <dc:creator>scottoliver</dc:creator>
    <dc:date>2018-07-11T19:59:58Z</dc:date>
    <item>
      <title>Weirdest thing I have seen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weirdest-thing-i-have-seen/m-p/221831#M63833</link>
      <description>&lt;P&gt;Having a weird issue. I installed an 820. I have internet traffic being NAT'ed. My gateway is set to the Palo. My hops to the internet look like this&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Windows Box ---&amp;gt; Palo 820 --&amp;gt; Cisco Pix --&amp;gt; Internet Provider&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pretty basic.. I have a rule in place to allow all internal to 0.0.0.0/0 443, 80..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can get to anything google even your tube just fine. works fast no hesitation. If I go anywhere else ( MSN, Yahoo, CNN) I get nothing. Traffic drops.&amp;nbsp; I cant figure this out for the life of me.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got a pcap going to google and going to red.com (52.73.0.154)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can get to google but not red. I cant find a difference. Any ideas would be appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 19:59:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weirdest-thing-i-have-seen/m-p/221831#M63833</guid>
      <dc:creator>scottoliver</dc:creator>
      <dc:date>2018-07-11T19:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Weirdest thing I have seen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weirdest-thing-i-have-seen/m-p/221847#M63834</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73655"&gt;@scottoliver&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;First thing that comes to mind would be an MTU mismatch between the Palo and the Pix?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 21:05:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weirdest-thing-i-have-seen/m-p/221847#M63834</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-11T21:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: Weirdest thing I have seen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weirdest-thing-i-have-seen/m-p/221918#M63850</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73655"&gt;@scottoliver&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you're able to quantify a reliable source and destination IP address for a flow that isn't working, I would recommend taking a look at the global counters. This will show you what is being blocked, whether it be due to a policy deny or MTU issues like &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; states.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-check-global-counters-for-a-specific-source-and/ta-p/65794" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-check-global-counters-for-a-specific-source-and/ta-p/65794&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 13:54:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weirdest-thing-i-have-seen/m-p/221918#M63850</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-07-12T13:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: Weirdest thing I have seen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weirdest-thing-i-have-seen/m-p/221971#M63865</link>
      <description>&lt;P&gt;I did look at the counters and there were no drops. I cleared all sessions to the destination. I set up my filters to&amp;nbsp;52.73.0.154. I turned my filters on.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran this command to clear the counters data out. ( show counter global filter delta yes packet-filter yes severity drop ) . I turned the capture on and ran (show counter global filter delta yes packet-filter yes severity drop) again to make sure I had 0 counters...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I then iniated the connection to the above address.. I ran a local wireshark to watch the connection so I knew when it was finished. When the connection was finished I ran ( show counter global filter delta yes packet-filter yes severity drop ) again and it came back with 0 counters hit...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at the PCAPS packets do not appear to be getting dropped at all.. I can zip the pcaps and upload them to my server if anyone wants to take a look at them to see if they see something I do not.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 17:39:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weirdest-thing-i-have-seen/m-p/221971#M63865</guid>
      <dc:creator>scottoliver</dc:creator>
      <dc:date>2018-07-12T17:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Weirdest thing I have seen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weirdest-thing-i-have-seen/m-p/221972#M63866</link>
      <description>&lt;P&gt;Thinking it might be a TCP window sizing issue but not 100%&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 17:41:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weirdest-thing-i-have-seen/m-p/221972#M63866</guid>
      <dc:creator>scottoliver</dc:creator>
      <dc:date>2018-07-12T17:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: Weirdest thing I have seen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/weirdest-thing-i-have-seen/m-p/222009#M63876</link>
      <description>&lt;P&gt;Do you see the packet going to red.com hitting your PIX?&lt;/P&gt;&lt;P&gt;Is your DNS doing proper resolution for red.com?&lt;/P&gt;&lt;P&gt;Can you issue a show session all filter destination&amp;nbsp;&lt;SPAN&gt;52.73.0.154?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you see the session please open it in the session browser and see the progress of the connectin.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Collecting this information will be a good start.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 20:35:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/weirdest-thing-i-have-seen/m-p/222009#M63876</guid>
      <dc:creator>hfregoso</dc:creator>
      <dc:date>2018-07-12T20:35:25Z</dc:date>
    </item>
  </channel>
</rss>

