<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic sflow traffic denied from certain IPs even though rule allows it in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/sflow-traffic-denied-from-certain-ips-even-though-rule-allows-it/m-p/248592#M70711</link>
    <description>&lt;P&gt;I'm seeing an odd issue where I've got a rule allowing sflow traffic coming from a WAN zone into my server zone where my monitoring servers sit.&amp;nbsp; Most of the traffic passes as it should, but there are random subnets where the rule is being denied with it showing it is hitting the default deny policy.&amp;nbsp; The only filtering on the rule is for port 2055, coming from the WAN zone and into the server zone.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 02 Feb 2019 17:31:21 GMT</pubDate>
    <dc:creator>scott.jones</dc:creator>
    <dc:date>2019-02-02T17:31:21Z</dc:date>
    <item>
      <title>sflow traffic denied from certain IPs even though rule allows it</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sflow-traffic-denied-from-certain-ips-even-though-rule-allows-it/m-p/248592#M70711</link>
      <description>&lt;P&gt;I'm seeing an odd issue where I've got a rule allowing sflow traffic coming from a WAN zone into my server zone where my monitoring servers sit.&amp;nbsp; Most of the traffic passes as it should, but there are random subnets where the rule is being denied with it showing it is hitting the default deny policy.&amp;nbsp; The only filtering on the rule is for port 2055, coming from the WAN zone and into the server zone.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Feb 2019 17:31:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sflow-traffic-denied-from-certain-ips-even-though-rule-allows-it/m-p/248592#M70711</guid>
      <dc:creator>scott.jones</dc:creator>
      <dc:date>2019-02-02T17:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: sflow traffic denied from certain IPs even though rule allows it</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sflow-traffic-denied-from-certain-ips-even-though-rule-allows-it/m-p/248616#M70722</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Is the incoming sflow traffic on port 2055? The logs should show what is getting blocked, ie. source, destination, etc. Also I would change the policy to layer 7 by using the sflow application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Sun, 03 Feb 2019 00:52:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sflow-traffic-denied-from-certain-ips-even-though-rule-allows-it/m-p/248616#M70722</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-02-03T00:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: sflow traffic denied from certain IPs even though rule allows it</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sflow-traffic-denied-from-certain-ips-even-though-rule-allows-it/m-p/248630#M70729</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/103335"&gt;@scott.jones&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Utilizing the&amp;nbsp;&lt;EM&gt;'test security-policy-match'&lt;/EM&gt; command in the CLI with one of the denied flows should verify that the traffic&amp;nbsp;&lt;EM&gt;should&lt;/EM&gt; be matching your intended security entry.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Feb 2019 02:21:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sflow-traffic-denied-from-certain-ips-even-though-rule-allows-it/m-p/248630#M70729</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-02-03T02:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: sflow traffic denied from certain IPs even though rule allows it</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sflow-traffic-denied-from-certain-ips-even-though-rule-allows-it/m-p/248708#M70744</link>
      <description>&lt;P&gt;That ended up doing the trick.&amp;nbsp; Still not sure why some sites worked and others didn't, but when I switched to the app rule, it started passing traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks again for the help!&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 13:43:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sflow-traffic-denied-from-certain-ips-even-though-rule-allows-it/m-p/248708#M70744</guid>
      <dc:creator>scott.jones</dc:creator>
      <dc:date>2019-02-04T13:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: sflow traffic denied from certain IPs even though rule allows it</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sflow-traffic-denied-from-certain-ips-even-though-rule-allows-it/m-p/248709#M70745</link>
      <description>&lt;P&gt;This will come in handy for sure going forward.&amp;nbsp; ended up switching to the app rule for sflow and getting rid of the port-based config, and now it's allowing the traffic through.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the info!&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 13:44:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sflow-traffic-denied-from-certain-ips-even-though-rule-allows-it/m-p/248709#M70745</guid>
      <dc:creator>scott.jones</dc:creator>
      <dc:date>2019-02-04T13:44:51Z</dc:date>
    </item>
  </channel>
</rss>

