<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic QUIC deny vs drop in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/quic-deny-vs-drop/m-p/237586#M68072</link>
    <description>&lt;P&gt;Just curious.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The recommended QUIC rules set the action to 'deny', but the first rule is for service udp 80/443 any application. Is there a reason this is a 'deny' and not a 'drop'?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reference&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HOW TO BLOCK QUIC PROTOCOL&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClarCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClarCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What a difference a Deny makes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Community-Blog/What-a-difference-a-Deny-makes/ba-p/188811" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Community-Blog/What-a-difference-a-Deny-makes/ba-p/188811&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Oct 2018 14:25:10 GMT</pubDate>
    <dc:creator>mike406</dc:creator>
    <dc:date>2018-10-29T14:25:10Z</dc:date>
    <item>
      <title>QUIC deny vs drop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quic-deny-vs-drop/m-p/237586#M68072</link>
      <description>&lt;P&gt;Just curious.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The recommended QUIC rules set the action to 'deny', but the first rule is for service udp 80/443 any application. Is there a reason this is a 'deny' and not a 'drop'?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reference&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HOW TO BLOCK QUIC PROTOCOL&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClarCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClarCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What a difference a Deny makes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Community-Blog/What-a-difference-a-Deny-makes/ba-p/188811" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Community-Blog/What-a-difference-a-Deny-makes/ba-p/188811&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 14:25:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quic-deny-vs-drop/m-p/237586#M68072</guid>
      <dc:creator>mike406</dc:creator>
      <dc:date>2018-10-29T14:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: QUIC deny vs drop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quic-deny-vs-drop/m-p/237608#M68080</link>
      <description>&lt;P&gt;There isn't a default "Deny Action" on QUIC, as it is (as you note) a UDP-only protocol.&amp;nbsp; I believe that the default Deny is equivalent to a Drop, unless you check the checkbox on the "Send ICMP Unreachable" option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/policy/security-policy/security-policy-actions" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/policy/security-policy/security-policy-actions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;EM&gt;For a UDP session with a drop or reset action, if the ICMP Unreachable check box is selected, the firewall sends an ICMP message to the client.&lt;/EM&gt;"&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 15:12:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quic-deny-vs-drop/m-p/237608#M68080</guid>
      <dc:creator>JW6224</dc:creator>
      <dc:date>2018-10-29T15:12:46Z</dc:date>
    </item>
  </channel>
</rss>

