<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy not catching correct traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policy-not-catching-correct-traffic/m-p/239245#M68508</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/95713"&gt;@ChickenTenderer&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IP Protocol number of etherip (97) is not as same as TCP. I think that is the reason why it is not hitting the above rule when you defined TCP ports there. Traffic which is having destination port 20033 and with IP protocol number 6 or 17 will only hit this rule. Can you change it to applicationd deafult and see if it is working?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Pic.PNG" style="width: 384px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17495i3F6493AA11BA1D33/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Pic.PNG" alt="Pic.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Nov 2018 05:52:45 GMT</pubDate>
    <dc:creator>Rajesh12</dc:creator>
    <dc:date>2018-11-09T05:52:45Z</dc:date>
    <item>
      <title>Policy not catching correct traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-not-catching-correct-traffic/m-p/239175#M68500</link>
      <description>&lt;P&gt;Hi all, first time poster so go easy!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're running into an issue where a rule that is meant to catch ether-ip traffic on port 20033 is slipping through and being caught by a lower rule which allows any application and service. Rules as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rules.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17471i3A2535F0D300A80F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rules.png" alt="rules.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rulebig.png" style="width: 260px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17473i0717867F109F0CA1/image-dimensions/260x103/is-moderation-mode/true?v=v2" width="260" height="103" role="button" title="rulebig.png" alt="rulebig.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When running the "show session all filter rule X" command in cli, we can see that sessions are only established for the lower one, and not the higher one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cli.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17472i8BF9571481A98173/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="cli.png" alt="cli.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suppose I'm wondering if the rules have been configured incorrectly caused by me missing something, or if it's configured fine and this appears to be a bug.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 02:38:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-not-catching-correct-traffic/m-p/239175#M68500</guid>
      <dc:creator>ChickenTenderer</dc:creator>
      <dc:date>2018-11-09T02:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: Policy not catching correct traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-not-catching-correct-traffic/m-p/239245#M68508</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/95713"&gt;@ChickenTenderer&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IP Protocol number of etherip (97) is not as same as TCP. I think that is the reason why it is not hitting the above rule when you defined TCP ports there. Traffic which is having destination port 20033 and with IP protocol number 6 or 17 will only hit this rule. Can you change it to applicationd deafult and see if it is working?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Pic.PNG" style="width: 384px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17495i3F6493AA11BA1D33/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Pic.PNG" alt="Pic.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 05:52:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-not-catching-correct-traffic/m-p/239245#M68508</guid>
      <dc:creator>Rajesh12</dc:creator>
      <dc:date>2018-11-09T05:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Policy not catching correct traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-not-catching-correct-traffic/m-p/239434#M68564</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/100390"&gt;@Rajesh12&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply - your recommendation worked like a charm!&lt;/P&gt;&lt;P&gt;Looks like I'll have to be aware of that in the future.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Nov 2018 20:53:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-not-catching-correct-traffic/m-p/239434#M68564</guid>
      <dc:creator>ChickenTenderer</dc:creator>
      <dc:date>2018-11-11T20:53:42Z</dc:date>
    </item>
  </channel>
</rss>

