<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Calculate the flag from logged value of Traffic Log PanOS 8.1 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/calculate-the-flag-from-logged-value-of-traffic-log-panos-8-1/m-p/256243#M72696</link>
    <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;The flags for 8.1 log is as follows&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x80000000—session has a packet capture (PCAP)&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x40000000—option is enabled to allow a client to use multiple paths to connect to a destination host&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x20000000—file is submitted to WildFire for a verdict&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x10000000—enterprise credential submission by end user detected&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x08000000— source for the flow is whitelisted and not subject to recon protection&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x02000000—IPv6 session&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x01000000—SSL session is decrypted (SSL Proxy)&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00800000—&lt;/FONT&gt;session&lt;FONT face="arial,helvetica,sans-serif"&gt; is denied via URL filtering&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00400000—session has a NAT translation performed&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00200000—user information for the session was captured through Captive Portal&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00100000—application traffic is on a non-standard destination port&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00080000 —X-Forwarded-For value from a proxy is in the source user field&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00040000—log corresponds to a transaction within &lt;/FONT&gt;a http&lt;FONT face="arial,helvetica,sans-serif"&gt; proxy session (Proxy Transaction)&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00020000—Client to Server flow is subject to policy based forwarding&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00010000—Server to Client flow is subject to policy based forwarding&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00008000—&lt;/FONT&gt;session&lt;FONT face="arial,helvetica,sans-serif"&gt; is a container page access (Container Page)&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00002000—session has a temporary &lt;/FONT&gt;match&lt;FONT face="arial,helvetica,sans-serif"&gt; on a rule for implicit application dependency handling. Available in PAN-OS 5.0.0 and above.&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00000800—symmetric return is used to forward traffic for this session&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00000400—decrypted traffic is being sent out clear text through a mirror port&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00000100—&lt;/FONT&gt;payload&lt;FONT face="arial,helvetica,sans-serif"&gt; of the outer tunnel is being inspected&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;So the flag value available &lt;/FONT&gt;in&lt;FONT face="arial,helvetica,sans-serif"&gt; the &lt;/FONT&gt;log,&lt;FONT face="arial,helvetica,sans-serif"&gt; in your case "&lt;FONT color="#FF0000"&gt;0x500019" &lt;FONT color="#000000"&gt;should be AND with all the predefined hex value. If the value return after ANDing is matched with the predefined flag, then that is the flag for your log.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;In your case, for "0x500019" &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;it matches with&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;0x00400000 :session has a NAT translation performed&lt;BR /&gt;0x00100000 :application traffic is on a non-standard destination port&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;i.e. 0x500019 AND 0x00400000= 0x00400000&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;0x500019 AND 0x00100000=0x00100000&lt;BR /&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;But the AND value results into zero for another predefined flag.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;e.g. 0x500019 AND 0x00000100=0x0&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;So for given log, flag is "session has a NAT translation performed" and "application traffic is on a non-standard destination port"&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Apr 2019 05:29:23 GMT</pubDate>
    <dc:creator>ram_gubhaju</dc:creator>
    <dc:date>2019-04-05T05:29:23Z</dc:date>
    <item>
      <title>Calculate the flag from logged value of Traffic Log PanOS 8.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/calculate-the-flag-from-logged-value-of-traffic-log-panos-8-1/m-p/256233#M72692</link>
      <description>&lt;P&gt;According to Documentation,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/traffic-log-fields.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/traffic-log-fields.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="p"&gt;The field Flags is a 32-bit field that provides details on session; this field can be decoded by AND-ing the values with the logged value.&lt;/DIV&gt;&lt;DIV class="p"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="p"&gt;In my Traffic Log:&lt;/DIV&gt;&lt;DIV class="p"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="p"&gt;&lt;FONT face="courier new,courier"&gt;&amp;lt;14&amp;gt;Apr 3 11:35:32 HQFW01 1,2019/04/03 11:35:31,XXXXXXXXXXXXX,TRAFFIC,end,2049,2019/04/03 11:35:31,XX.XX.XX.XX,XX.XX.XX.XX,XX.XX.XX.XX,XX.XX.XX.XX,Guest Internet Access,,,abcde,vsys1,Guest,Untrust,XXX,XXX,default,2019/04/03 11:35:31,31450,1,19786,3139,58657,3479,&lt;FONT color="#FF0000"&gt;0x500019&lt;/FONT&gt;,udp,allow,504,270,234,6,2019/04/03 11:30:31,0,any,0,4233345645,0x0,XX.XX.XX.XX-XX.XX.XX.XX,United States,0,3,3,aged-out,0,0,0,0,,FW01,from-policy,,,0,,0,,N/A,0,0,0,0&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV class="p"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I see the flag value 0x500019. I am not sure how this value is calculated.&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV class="p"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="p"&gt;Can someone please explain which flags generates this value and how can we calculate it?&lt;/DIV&gt;</description>
      <pubDate>Fri, 05 Apr 2019 01:31:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/calculate-the-flag-from-logged-value-of-traffic-log-panos-8-1/m-p/256233#M72692</guid>
      <dc:creator>gnikesh</dc:creator>
      <dc:date>2019-04-05T01:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Calculate the flag from logged value of Traffic Log PanOS 8.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/calculate-the-flag-from-logged-value-of-traffic-log-panos-8-1/m-p/256243#M72696</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;The flags for 8.1 log is as follows&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x80000000—session has a packet capture (PCAP)&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x40000000—option is enabled to allow a client to use multiple paths to connect to a destination host&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x20000000—file is submitted to WildFire for a verdict&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x10000000—enterprise credential submission by end user detected&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x08000000— source for the flow is whitelisted and not subject to recon protection&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x02000000—IPv6 session&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x01000000—SSL session is decrypted (SSL Proxy)&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00800000—&lt;/FONT&gt;session&lt;FONT face="arial,helvetica,sans-serif"&gt; is denied via URL filtering&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00400000—session has a NAT translation performed&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00200000—user information for the session was captured through Captive Portal&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00100000—application traffic is on a non-standard destination port&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00080000 —X-Forwarded-For value from a proxy is in the source user field&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00040000—log corresponds to a transaction within &lt;/FONT&gt;a http&lt;FONT face="arial,helvetica,sans-serif"&gt; proxy session (Proxy Transaction)&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00020000—Client to Server flow is subject to policy based forwarding&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00010000—Server to Client flow is subject to policy based forwarding&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00008000—&lt;/FONT&gt;session&lt;FONT face="arial,helvetica,sans-serif"&gt; is a container page access (Container Page)&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00002000—session has a temporary &lt;/FONT&gt;match&lt;FONT face="arial,helvetica,sans-serif"&gt; on a rule for implicit application dependency handling. Available in PAN-OS 5.0.0 and above.&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00000800—symmetric return is used to forward traffic for this session&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00000400—decrypted traffic is being sent out clear text through a mirror port&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;0x00000100—&lt;/FONT&gt;payload&lt;FONT face="arial,helvetica,sans-serif"&gt; of the outer tunnel is being inspected&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;So the flag value available &lt;/FONT&gt;in&lt;FONT face="arial,helvetica,sans-serif"&gt; the &lt;/FONT&gt;log,&lt;FONT face="arial,helvetica,sans-serif"&gt; in your case "&lt;FONT color="#FF0000"&gt;0x500019" &lt;FONT color="#000000"&gt;should be AND with all the predefined hex value. If the value return after ANDing is matched with the predefined flag, then that is the flag for your log.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;In your case, for "0x500019" &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;it matches with&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;0x00400000 :session has a NAT translation performed&lt;BR /&gt;0x00100000 :application traffic is on a non-standard destination port&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;i.e. 0x500019 AND 0x00400000= 0x00400000&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;0x500019 AND 0x00100000=0x00100000&lt;BR /&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;But the AND value results into zero for another predefined flag.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;e.g. 0x500019 AND 0x00000100=0x0&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;So for given log, flag is "session has a NAT translation performed" and "application traffic is on a non-standard destination port"&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 05:29:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/calculate-the-flag-from-logged-value-of-traffic-log-panos-8-1/m-p/256243#M72696</guid>
      <dc:creator>ram_gubhaju</dc:creator>
      <dc:date>2019-04-05T05:29:23Z</dc:date>
    </item>
  </channel>
</rss>

