<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Almost all traffic identified as unknown-tcp? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/almost-all-traffic-identified-as-unknown-tcp/m-p/235886#M67617</link>
    <description>&lt;P&gt;Checking to see if you ever heard back from TAC on this issue.&lt;/P&gt;</description>
    <pubDate>Wed, 17 Oct 2018 20:35:55 GMT</pubDate>
    <dc:creator>david.myers</dc:creator>
    <dc:date>2018-10-17T20:35:55Z</dc:date>
    <item>
      <title>Almost all traffic identified as unknown-tcp?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/almost-all-traffic-identified-as-unknown-tcp/m-p/217601#M62946</link>
      <description>&lt;P&gt;We are seeing some of our Palo's periodically logging (almost) all traffic as unknown-tcp.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As the traffic is being allowed through (and logged against) rules that do not allow it we assume this is a problem with the logs, rather than traffic being miscategorised.&amp;nbsp; However we do seem to be be experiencing some random issues that may, or mayt not be connected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rebooting the Palo seems to clear the problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just wondering if anyone else has see this (we are 8.1.1) before opening a support call.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 19:31:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/almost-all-traffic-identified-as-unknown-tcp/m-p/217601#M62946</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2018-06-12T19:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Almost all traffic identified as unknown-tcp?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/almost-all-traffic-identified-as-unknown-tcp/m-p/217612#M62947</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6173"&gt;@apackard&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I've been running 8.1.1 on some lab equipment and at home for a bit and haven't seen this issue at all; further I haven't heard of anyone else experiancing an issue like this running 8.1.*.&amp;nbsp;&lt;/P&gt;&lt;P&gt;That being said you probably want to open a ticket simply to at least provide PA with the logs so that they can see why you are experiancing this issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 20:16:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/almost-all-traffic-identified-as-unknown-tcp/m-p/217612#M62947</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-12T20:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: Almost all traffic identified as unknown-tcp?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/almost-all-traffic-identified-as-unknown-tcp/m-p/224560#M64463</link>
      <description>&lt;P&gt;Did that the problem get fixed?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our customer is facing with the same problem as you. (ver.&amp;nbsp;8.1.1 , pa-3020.)&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you said, rebooting the Palo seems to clear the problem.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 11:50:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/almost-all-traffic-identified-as-unknown-tcp/m-p/224560#M64463</guid>
      <dc:creator>m_izk</dc:creator>
      <dc:date>2018-08-02T11:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: Almost all traffic identified as unknown-tcp?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/almost-all-traffic-identified-as-unknown-tcp/m-p/224561#M64464</link>
      <description>&lt;P&gt;Fraid not - we're currently escalaing this with Palo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In a way it's good to know others are impacted by this as we're being told it's never been seen before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interestingly for us we see this much more in our US locations - we have same hardware, same OS version, same rules in EU and Asia locations and we're seeing 90% less unknown trafic types being logged.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 11:54:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/almost-all-traffic-identified-as-unknown-tcp/m-p/224561#M64464</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2018-08-02T11:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: Almost all traffic identified as unknown-tcp?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/almost-all-traffic-identified-as-unknown-tcp/m-p/235886#M67617</link>
      <description>&lt;P&gt;Checking to see if you ever heard back from TAC on this issue.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 20:35:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/almost-all-traffic-identified-as-unknown-tcp/m-p/235886#M67617</guid>
      <dc:creator>david.myers</dc:creator>
      <dc:date>2018-10-17T20:35:55Z</dc:date>
    </item>
  </channel>
</rss>

