<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo alto website issue - Virtual wire in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/286105#M76538</link>
    <description>&lt;P&gt;Model PA-850 pan os 8.1.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ssl decryption not enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;venky&lt;/P&gt;</description>
    <pubDate>Sat, 31 Aug 2019 16:23:28 GMT</pubDate>
    <dc:creator>Venkatesan_radhakrishnan</dc:creator>
    <dc:date>2019-08-31T16:23:28Z</dc:date>
    <item>
      <title>Palo alto website issue - Virtual wire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/285844#M76490</link>
      <description>&lt;P&gt;HI Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer has deployed Palo alto firewall in virtual wire mode between Cisco Meraki Gateway and Cisco meraki coreswitch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are seeing a issue where the website is not loading in first attempt. For example if we are seeing visiting website XYZ.com for first time in network it shows an error "This Site can't be reached the connection was reset" and immediatelty with in a second. This error appears may be for 2 seconds in screen not much more that mentioned.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Initially I thought this could be his internal DNS issue in PC, So I tried changing DNS to 8.8.8.8 and tried browsing new sites no luck and then while seeing drop counter I have seen drops for "url request pkt " and "flow tcp non syn" then I set tcp non syn lookup to false and configured timeout for url request lookup to 60 seconds but the issue is still not resolved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This issue happens with all the users as per customer, While in capturing im seeing lot of TCP retransmission sent for PSH ACK from source to destination.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This issue looks strange also for your knowledged there is security profiles attached the policy i removed all for testing purpose which also not resolved the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;Your valuable comments will add more value to this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Venky&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 19:18:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/285844#M76490</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2019-08-29T19:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto website issue - Virtual wire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/285855#M76493</link>
      <description>&lt;P&gt;Thanks for the info you have.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this time, take small steps to troubleshoot.&lt;/P&gt;&lt;P&gt;Removing the security profiles are good, but not the source of the issue, based on responses you provided.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Turn off any DoS Policy and also remove your Zone Protection Profile from the zones, and test.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Something within Content Inspection appears to be causing the issue.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 20:07:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/285855#M76493</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-08-29T20:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto website issue - Virtual wire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/285856#M76494</link>
      <description>&lt;P&gt;Dos profile disabled and zone protection configured only for alert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 20:10:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/285856#M76494</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2019-08-29T20:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto website issue - Virtual wire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/285858#M76496</link>
      <description>&lt;P&gt;As I mentioned, please remove the Zone protection profile and test again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The alert functionality is for Port Scans and Host Sweeps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are seeing drops, then it is the ZPP that could be root cause.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remove ZPP, test, and then report back to us.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 20:13:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/285858#M76496</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-08-29T20:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto website issue - Virtual wire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/285859#M76497</link>
      <description>&lt;P&gt;Zone protection will not help here why because I’m not seeing any drops related to zone protection in global counter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if I have seen zone protection drop counter I would have disabled it and tried&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 20:16:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/285859#M76497</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2019-08-29T20:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto website issue - Virtual wire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/285860#M76498</link>
      <description>&lt;P&gt;Hello again&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your comment in your orginal post was&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have seen drops for "url request pkt " and &lt;STRONG&gt;"flow tcp non syn&lt;/STRONG&gt;" then I set tcp non syn lookup to fals.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Part of ZPP includes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Reject Non-SYN TCP:&lt;/STRONG&gt; Determines whether to reject the packet if the first packet for the TCP session setup is not a SYN packet:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;global—Use system-wide setting that is assigned through the CLI.&lt;/LI&gt;&lt;LI&gt;yes—Reject non-SYN TCP traffic.&lt;/LI&gt;&lt;LI&gt;no—Accept non-SYN TCP traffic.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This why I am requesting that you just test removing ZPP for 5 minutes to see if this helps.&lt;/P&gt;&lt;P&gt;As I mentioned, it just small logical troubleshooting steps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could also run a tech support FW and open an offical ticket with TAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We want to assist you as much as possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For me personally, I have seen and experienced this issue, both as a Pro Service consultant and instructor of 8 years on PANW hardware. This is why I am attempting to assist you to rule out or confirm ZPP.&amp;nbsp; I have other steps that could be done, but wanted to get the easy ones out of the way initially.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 20:23:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/285860#M76498</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-08-29T20:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto website issue - Virtual wire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/285861#M76499</link>
      <description>&lt;P&gt;Ok I’ll check your opinion&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 20:25:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/285861#M76499</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2019-08-29T20:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto website issue - Virtual wire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/285932#M76510</link>
      <description>&lt;P&gt;Which software version you are running?&lt;/P&gt;&lt;P&gt;Do you have ssl decryption enabled?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2019 05:44:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/285932#M76510</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-08-30T05:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto website issue - Virtual wire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/286105#M76538</link>
      <description>&lt;P&gt;Model PA-850 pan os 8.1.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ssl decryption not enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;venky&lt;/P&gt;</description>
      <pubDate>Sat, 31 Aug 2019 16:23:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/286105#M76538</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2019-08-31T16:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto website issue - Virtual wire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/286111#M76541</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zone protection is not applied to the zones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Venky&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2019 05:46:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-website-issue-virtual-wire/m-p/286111#M76541</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2019-09-01T05:46:31Z</dc:date>
    </item>
  </channel>
</rss>

