<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packet flow for Hardware Offload in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-for-hardware-offload/m-p/234681#M67273</link>
    <description>&lt;P&gt;yes my understanding is also&amp;nbsp; this if app is identified and no more decryption thenit is offloaded.&lt;/P&gt;&lt;P&gt;lets see if someone confirm this?&lt;/P&gt;</description>
    <pubDate>Wed, 10 Oct 2018 05:29:12 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2018-10-10T05:29:12Z</dc:date>
    <item>
      <title>Packet flow for Hardware Offload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-for-hardware-offload/m-p/132273#M47049</link>
      <description>&lt;P&gt;Dear Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Was wondering regarding packet flow in terms of hardware offload. Is it like below or somethingelse?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ingress Stage &amp;gt; Session table/flow lookup&amp;gt; Offloaded&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ingress Stage &amp;gt; Session table/flow lookup &amp;gt; App-ID/Content-ID inspection is done or not &amp;gt; offloaded&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please suggest.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Reagrds,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fozail&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2016 14:49:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-for-hardware-offload/m-p/132273#M47049</guid>
      <dc:creator>fozail</dc:creator>
      <dc:date>2016-12-09T14:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: Packet flow for Hardware Offload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-for-hardware-offload/m-p/132281#M47053</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16044"&gt;@fozail&lt;/a&gt;&amp;nbsp;this link should provide you with all the session offload documentation you could possibly want.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Palo-Alto-Networks-Firewall-Session-Overview/ta-p/55633" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Palo-Alto-Networks-Firewall-Session-Overview/ta-p/55633&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2016 16:07:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-for-hardware-offload/m-p/132281#M47053</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-09T16:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: Packet flow for Hardware Offload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-for-hardware-offload/m-p/132308#M47056</link>
      <description>&lt;P&gt;Hi Fozail,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The flow is the second one you mentioned (at a high level), depending on the app it will fall to the first one i.e once the session is identified as SSL is then this gets offloaded if you're not decrypting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check this document, it goes into a lot of detail on the packet flow on the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Packet-Flow-Sequence-in-PAN-OS/ta-p/56081" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Packet-Flow-Sequence-in-PAN-OS/ta-p/56081&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2016 17:46:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-for-hardware-offload/m-p/132308#M47056</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-12-09T17:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Packet flow for Hardware Offload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-for-hardware-offload/m-p/132309#M47057</link>
      <description>&lt;P&gt;Hi Ben,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have chceked the&amp;nbsp;&lt;SPAN&gt;DOC-1628, but it does not talk about FPGA. After which stage FPGA comes into picture.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As far as I understood, once application gets identified like SSL and there is no further content ispection is needed, packet will go through Ingress Stage &amp;gt; Session Lookup &amp;gt; Matched Active session &amp;gt;&amp;nbsp;application got identified like SSL and there is no further content ispection is needed &amp;gt; handover the packet to FPGA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please correct me if I am wrong.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Fozail&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2016 18:04:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-for-hardware-offload/m-p/132309#M47057</guid>
      <dc:creator>fozail</dc:creator>
      <dc:date>2016-12-09T18:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: Packet flow for Hardware Offload</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-for-hardware-offload/m-p/234681#M67273</link>
      <description>&lt;P&gt;yes my understanding is also&amp;nbsp; this if app is identified and no more decryption thenit is offloaded.&lt;/P&gt;&lt;P&gt;lets see if someone confirm this?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 05:29:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-for-hardware-offload/m-p/234681#M67273</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-10T05:29:12Z</dc:date>
    </item>
  </channel>
</rss>

