<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA is dropping SYN packet with ECN and CWR in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-is-dropping-syn-packet-with-ecn-and-cwr/m-p/278388#M75600</link>
    <description>I would expect these bits to either be stripped or ignored
The global counter would indicate the session behavior has changed so it is trying to piggyback off another session for which there is no predict session set up

I'd reach out to TAC to have this investigated</description>
    <pubDate>Tue, 23 Jul 2019 13:57:44 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2019-07-23T13:57:44Z</dc:date>
    <item>
      <title>PA is dropping SYN packet with ECN and CWR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-is-dropping-syn-packet-with-ecn-and-cwr/m-p/277922#M75525</link>
      <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently I have come across a scenario that palo alto was dropping TCP SYN packets which have ECN and CWR bits set. upon checking the global counter, i have seen that the drop reason was 'process owner message err, no predict'. anybody have seen this?. PA doesn't support SYN packets with ECN and CWR set ?..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once I disable this enhancement in windows using the command 'netsh int tcp set global ecncapability=disabled', the session is getting established and the thinks are working fine.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 12:13:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-is-dropping-syn-packet-with-ecn-and-cwr/m-p/277922#M75525</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-07-22T12:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: PA is dropping SYN packet with ECN and CWR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-is-dropping-syn-packet-with-ecn-and-cwr/m-p/278388#M75600</link>
      <description>I would expect these bits to either be stripped or ignored
The global counter would indicate the session behavior has changed so it is trying to piggyback off another session for which there is no predict session set up

I'd reach out to TAC to have this investigated</description>
      <pubDate>Tue, 23 Jul 2019 13:57:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-is-dropping-syn-packet-with-ecn-and-cwr/m-p/278388#M75600</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-07-23T13:57:44Z</dc:date>
    </item>
  </channel>
</rss>

