<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blacklisting Workstations? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/blacklisting-workstations/m-p/307736#M79913</link>
    <description>&lt;P&gt;Thanks. Next time this happens I will do the packet capture.&lt;/P&gt;&lt;P&gt;I tried to replicate the issue on my laptop, but I haven't been able to. I haven't heard any reports of this happening to anyone else since I posted this either.&lt;/P&gt;&lt;P&gt;It's possible that the issue was something else, not PA. I'll just have to wait for the next report I guess.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jan 2020 20:39:42 GMT</pubDate>
    <dc:creator>Luke_R</dc:creator>
    <dc:date>2020-01-23T20:39:42Z</dc:date>
    <item>
      <title>Blacklisting Workstations?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blacklisting-workstations/m-p/307614#M79895</link>
      <description>&lt;P&gt;Sorry if this is a dumb question, I'm still a bit new to PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've recently had a case where a few workstations cannot access anything beyond the local network. A trace shows that they can reach their default GW, but not the next hop, which is the PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a workaround, I found that changing their IP address resolved the issue. I then found that if another workstation got the old IP through DHCP, they wouldn't work either. For now I've excluded the IP's from the range.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm wondering if something on the PA could have seen a threat coming from these IP's, and blacklisted them. Is there any troubleshooting you would recommend in a case like this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's what I've seen so far:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The traffic log shows a lot of entries with an action of 'allow', but a session end reason of 'tcp-rst-from-server'&lt;/LI&gt;&lt;LI&gt;Nothing in the threat log&lt;/LI&gt;&lt;LI&gt;No correlated events&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2020 21:23:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blacklisting-workstations/m-p/307614#M79895</guid>
      <dc:creator>Luke_R</dc:creator>
      <dc:date>2020-01-22T21:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting Workstations?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blacklisting-workstations/m-p/307663#M79900</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131072"&gt;@Luke_R&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;tcp-rst-from-server :&amp;nbsp;The server sent a TCP reset to the client.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You're seeing traffic logs so your traffic is reaching the FW...&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I'd check first if the traffic reaching the firewall is actually egressing out correctly ... if not then check for indicators in the global counters:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2020 10:14:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blacklisting-workstations/m-p/307663#M79900</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-01-23T10:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting Workstations?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blacklisting-workstations/m-p/307723#M79910</link>
      <description>&lt;P&gt;'tcp-rst-from-server'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this from one server or a whole bunch of them?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2020 17:05:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blacklisting-workstations/m-p/307723#M79910</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2020-01-23T17:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting Workstations?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blacklisting-workstations/m-p/307735#M79912</link>
      <description>&lt;P&gt;There were a few different ones. Not a lot though, but I'm not sure what's normal for this user.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2020 20:38:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blacklisting-workstations/m-p/307735#M79912</guid>
      <dc:creator>Luke_R</dc:creator>
      <dc:date>2020-01-23T20:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting Workstations?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blacklisting-workstations/m-p/307736#M79913</link>
      <description>&lt;P&gt;Thanks. Next time this happens I will do the packet capture.&lt;/P&gt;&lt;P&gt;I tried to replicate the issue on my laptop, but I haven't been able to. I haven't heard any reports of this happening to anyone else since I posted this either.&lt;/P&gt;&lt;P&gt;It's possible that the issue was something else, not PA. I'll just have to wait for the next report I guess.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2020 20:39:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blacklisting-workstations/m-p/307736#M79913</guid>
      <dc:creator>Luke_R</dc:creator>
      <dc:date>2020-01-23T20:39:42Z</dc:date>
    </item>
  </channel>
</rss>

