<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: syn without window-scale option in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/syn-without-window-scale-option/m-p/240180#M68816</link>
    <description>&lt;P&gt;Add&amp;nbsp;filter.&lt;/P&gt;&lt;P&gt;Assuming that website IP is 1.1.1.1&lt;/P&gt;&lt;P&gt;Monitor &amp;gt; Packet Capture&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enable filter.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="filter.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17570iF0D2EFCE0B1E40A6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="filter.JPG" alt="filter.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Go to cli and run command.&lt;/P&gt;&lt;P&gt;&amp;gt; show counter global filter delta yes packet-filter yes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try to visit website and run command again.&lt;/P&gt;&lt;P&gt;&amp;gt; show counter global filter delta yes packet-filter yes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you see any where severity is drop?&lt;/P&gt;</description>
    <pubDate>Fri, 16 Nov 2018 19:18:26 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2018-11-16T19:18:26Z</dc:date>
    <item>
      <title>syn without window-scale option</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syn-without-window-scale-option/m-p/239972#M68742</link>
      <description>&lt;P&gt;Hi community,&amp;nbsp;&lt;/P&gt;&lt;P&gt;i am trying to access a website from LAN side of palo alto, even though correct policy is configured, tcp handshake was not complete. after packet capture i am able to find below points&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&amp;nbsp;client sending syn packet&lt;/LI&gt;&lt;LI&gt;but i am not able to get syn-ack packet from server,&lt;/LI&gt;&lt;LI&gt;able to see&amp;nbsp;one ack packets from server&lt;/LI&gt;&lt;LI&gt;server is using 3-way handshake only&lt;/LI&gt;&lt;LI&gt;server is sending syn-ack, but tcp window-scaling option is not available.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;i have seen firewall will drop packet if window scaling information is not available in syn packet. can anybody tell whether i am hitting on same issue, if yes, how to solve it in palo alto&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 14:20:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syn-without-window-scale-option/m-p/239972#M68742</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2018-11-15T14:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: syn without window-scale option</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syn-without-window-scale-option/m-p/240022#M68752</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Was the pcap performed from the PAN or from the client? I honestly suspect a routing issue since you are not getting any ack's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 17:42:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syn-without-window-scale-option/m-p/240022#M68752</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-11-15T17:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: syn without window-scale option</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syn-without-window-scale-option/m-p/240092#M68772</link>
      <description>&lt;P&gt;Hi klier,&lt;/P&gt;&lt;P&gt;No routing issue is involved, i am able to acces other sites, only this particular site is is not accessible. when i bypass firewall, i was getting syn-ack packet in my PC. when i access through firewall, firewall is dropping that particular packet.&lt;/P&gt;&lt;P&gt;for other sites, bypassing firewall or accessing through doesn't make any difference.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 05:58:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syn-without-window-scale-option/m-p/240092#M68772</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2018-11-16T05:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: syn without window-scale option</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syn-without-window-scale-option/m-p/240180#M68816</link>
      <description>&lt;P&gt;Add&amp;nbsp;filter.&lt;/P&gt;&lt;P&gt;Assuming that website IP is 1.1.1.1&lt;/P&gt;&lt;P&gt;Monitor &amp;gt; Packet Capture&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enable filter.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="filter.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17570iF0D2EFCE0B1E40A6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="filter.JPG" alt="filter.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Go to cli and run command.&lt;/P&gt;&lt;P&gt;&amp;gt; show counter global filter delta yes packet-filter yes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try to visit website and run command again.&lt;/P&gt;&lt;P&gt;&amp;gt; show counter global filter delta yes packet-filter yes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you see any where severity is drop?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 19:18:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syn-without-window-scale-option/m-p/240180#M68816</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-11-16T19:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: syn without window-scale option</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syn-without-window-scale-option/m-p/240221#M68851</link>
      <description>&lt;P&gt;Hi Radio,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your input.&lt;/P&gt;&lt;P&gt;the counter was increasing in my case because of out-of-window packets. after putting '&lt;SPAN&gt;set deviceconfig setting tcp asymmetric-path bypass' command, the website is accessible. it solved my issue. but it does look like an workaround only as the command is designed for assymetric routing. as of my understanding, in my case,&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;definitly the issue is not assymetric but because of firewall doesnt have window information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if i put this command, will i get any security risk as replay attack?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Nov 2018 07:15:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syn-without-window-scale-option/m-p/240221#M68851</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2018-11-17T07:15:42Z</dc:date>
    </item>
  </channel>
</rss>

