<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic App id “Non-syn-tcp” in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-non-syn-tcp/m-p/234103#M67106</link>
    <description>I see a lot of non- syn-tcp from from few specific zone. I am sure that there is no asymmetric routing. If that has to be the case how to determine exact causing factor.&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
    <pubDate>Fri, 05 Oct 2018 13:27:46 GMT</pubDate>
    <dc:creator>Sanssj</dc:creator>
    <dc:date>2018-10-05T13:27:46Z</dc:date>
    <item>
      <title>App id “Non-syn-tcp”</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-non-syn-tcp/m-p/234103#M67106</link>
      <description>I see a lot of non- syn-tcp from from few specific zone. I am sure that there is no asymmetric routing. If that has to be the case how to determine exact causing factor.&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
      <pubDate>Fri, 05 Oct 2018 13:27:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-non-syn-tcp/m-p/234103#M67106</guid>
      <dc:creator>Sanssj</dc:creator>
      <dc:date>2018-10-05T13:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: App id “Non-syn-tcp”</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-non-syn-tcp/m-p/234117#M67113</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Look at the source/destination. Hopefully that will give you insight. I know my external interface gets then when people are probing for weak spots, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 13:52:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-non-syn-tcp/m-p/234117#M67113</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-10-05T13:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: App id “Non-syn-tcp”</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-non-syn-tcp/m-p/238284#M68253</link>
      <description>&lt;P&gt;That would definitely help if its basically&amp;nbsp; comming from an untrusted/external internet facing interafce but the problem here is its comming from trusted direct connect link.&amp;nbsp; In addition this traffic is being dropped due to non -syn tcp so had to&amp;nbsp;&lt;SPAN&gt;allow non-syn tcp for this specific zone. which is a serious security concern.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;At the end we are still puzzled why is there non-syn -tcp traffic in the first place?&lt;BR /&gt;Any thoughts are welcome&lt;BR /&gt;&lt;BR /&gt;thanks&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 02:44:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-non-syn-tcp/m-p/238284#M68253</guid>
      <dc:creator>Sanssj</dc:creator>
      <dc:date>2018-11-02T02:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: App id “Non-syn-tcp”</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-non-syn-tcp/m-p/238314#M68262</link>
      <description>&lt;P&gt;It can only be asymmetric routing or someone deliberately probing your network.&lt;/P&gt;&lt;P&gt;If you had to allow this in order to get your deisred connections to work then it's definitelly some asymetry in your network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To debug: find a TCP connection (&lt;SPAN&gt;source and destination&lt;/SPAN&gt; IP addresses, source and destination port). Let's say 1.1.1.1:43500 -&amp;gt; 2.2.2.2:443 (https).&lt;/P&gt;&lt;P&gt;Check the logs for SYN packet: source 1.1.1.1, dst 2.2.2.2, dst port 443. Now check ingress and egress interface for this.&lt;/P&gt;&lt;P&gt;Then check the logs for SYN-ACK packet; src.port 443, dst.port 43500, dst 1.1.1.1. &lt;SPAN&gt;Now check ingress and egress interface for this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That should give you a clear picture of packet flow and prove the&amp;nbsp;&lt;SPAN&gt;asymmetric routing.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 09:37:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-non-syn-tcp/m-p/238314#M68262</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-11-02T09:37:47Z</dc:date>
    </item>
  </channel>
</rss>

