<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Do not see deny in traffic logs for traffic to internal server accessible via Public IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/do-not-see-deny-in-traffic-logs-for-traffic-to-internal-server/m-p/254349#M72185</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have server reachable via Public IP say on port 13001 and 13002&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have Security rule&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source any&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zone outside&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Destination 173.82.x.x IP&amp;nbsp; of server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zone inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;port 13001&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here i have not included the port 13002.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have correct NAT policy for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i see traffic logs i see&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source any&amp;nbsp;&lt;/P&gt;&lt;P&gt;destination server public ip address&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;port 13002&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;action allow&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;source zone is outside&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;destination zone is outside.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;need to know why i do not see deny for traffic on port 13002 from source zone outside to destination zone inside?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Mar 2019 03:34:27 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2019-03-20T03:34:27Z</dc:date>
    <item>
      <title>Do not see deny in traffic logs for traffic to internal server accessible via Public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-not-see-deny-in-traffic-logs-for-traffic-to-internal-server/m-p/254349#M72185</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have server reachable via Public IP say on port 13001 and 13002&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have Security rule&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source any&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zone outside&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Destination 173.82.x.x IP&amp;nbsp; of server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zone inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;port 13001&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here i have not included the port 13002.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have correct NAT policy for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i see traffic logs i see&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source any&amp;nbsp;&lt;/P&gt;&lt;P&gt;destination server public ip address&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;port 13002&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;action allow&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;source zone is outside&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;destination zone is outside.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;need to know why i do not see deny for traffic on port 13002 from source zone outside to destination zone inside?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 03:34:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-not-see-deny-in-traffic-logs-for-traffic-to-internal-server/m-p/254349#M72185</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-20T03:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: Do not see deny in traffic logs for traffic to internal server accessible via Public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-not-see-deny-in-traffic-logs-for-traffic-to-internal-server/m-p/254405#M72202</link>
      <description>&lt;P&gt;Hmmm.... this is a bit confusing...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;to answer your question....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;because you don't have an explicit "deny" policy for this traffic, so the palo will just drop the packets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or maybe i have not understood your question.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 16:58:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-not-see-deny-in-traffic-logs-for-traffic-to-internal-server/m-p/254405#M72202</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-03-20T16:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Do not see deny in traffic logs for traffic to internal server accessible via Public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-not-see-deny-in-traffic-logs-for-traffic-to-internal-server/m-p/254734#M72291</link>
      <description>&lt;P&gt;You must select logging for your deny rule that this traffic traverses.&amp;nbsp; The interzone-default deny rule (greyed out at the bottom of you list) does not have logging turned on by default.&amp;nbsp; You can override this or create your own deny rule to catch these.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 19:30:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-not-see-deny-in-traffic-logs-for-traffic-to-internal-server/m-p/254734#M72291</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-03-22T19:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: Do not see deny in traffic logs for traffic to internal server accessible via Public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-not-see-deny-in-traffic-logs-for-traffic-to-internal-server/m-p/254743#M72295</link>
      <description>&lt;P&gt;logging is enabled.&lt;/P&gt;&lt;P&gt;I can see deny from other rules problem is only with this rule&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 20:16:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-not-see-deny-in-traffic-logs-for-traffic-to-internal-server/m-p/254743#M72295</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-22T20:16:15Z</dc:date>
    </item>
  </channel>
</rss>

