<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA syslog app id - problems in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311356#M80578</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seeing 'session aged out' does not mean that firewall is actually dropping traffic. There are multiple reasons for that. It may be the case there are some changes at server end itself. Also if you are trying to access it on TCP port, have you tried to telnet syslog server from client on tcp port?&lt;/P&gt;&lt;P&gt;Are you able to do so?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
    <pubDate>Sat, 15 Feb 2020 13:50:05 GMT</pubDate>
    <dc:creator>SutareMayur</dc:creator>
    <dc:date>2020-02-15T13:50:05Z</dc:date>
    <item>
      <title>PA syslog app id - problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311200#M80550</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so 5220 - 9.0.5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a syslog client and syslog server.&lt;/P&gt;&lt;P&gt;the path goes through my PA.&lt;/P&gt;&lt;P&gt;I have a rule basically says any internal ip is allowed to the syslog server if the app it syslog&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;that doesn't work, the packets are too short for the PA to distinguish them .. sigh so add in unknown - udp .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;now they go through.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;next problem tcp syslog on port 514 - default for centos and rhel when using tcp&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pa don't think syslog goes on port 514.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;okay application override&amp;nbsp;&lt;/P&gt;&lt;P&gt;I say any internal ip going to syslog server on tcp 514 . make it syslog application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;doesn't work . my session are still marked as unkown ... again i am guessing causes it too small.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WTF do you do .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see packets on both side. client and server .. and the client is trying to send the pa is not letting through.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FFS &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; sigh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any suggestions. I am thinking of just setting any app as long as its port 514 hopefully that will fix it&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 07:11:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311200#M80550</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2020-02-14T07:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslog app id - problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311201#M80551</link>
      <description>&lt;P&gt;tried allowing any app id but to that ip and only port 514..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;no luck &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 07:16:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311201#M80551</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2020-02-14T07:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslog app id - problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311205#M80552</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you see in the traffic logs ? Is it actually using syslog default port?&lt;/P&gt;&lt;P&gt;Can you try to configure policy for app - syslog and port any?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 08:25:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311205#M80552</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-14T08:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslog app id - problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311278#M80564</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Have you tried setting CentOS to send syslog over 514/UDP?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 17:59:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311278#M80564</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-02-14T17:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslog app id - problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311341#M80577</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp; &amp;nbsp;Not sure why I have to change my setup to make he firewall work :).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the reason I am using TCP over 514 is that the reliabe transfer setup for syslog. I can guarantee messages being sent from one server to the central logging server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue seems to be that the PA doesn't allow traffic to flow from client to server and back. because it can't id (my guess why the packets aren't flowing).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;initially I have it as&amp;nbsp;&lt;/P&gt;&lt;P&gt;any int ip to syslog server allow applicaiton syslog on port 514 udp and tcp.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;UDP works fine. but when i tried my tcp connections. no go.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So did some investigating and found that PA application syslog doesn't recognise tcp/514 as syslog ..&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I thought this is simple ! I do an applicaiton override for any int ip to syslog on tcp 514 say its syslog application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;that didn't seem to work !&amp;nbsp; when i look at current session they still show up as undecide .. so it just gets stuck and ages out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what next !&amp;nbsp; &amp;nbsp;I have raised this with support ..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but why do I have to change my setup to make the firewall work properly&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Feb 2020 06:52:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311341#M80577</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2020-02-15T06:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslog app id - problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311356#M80578</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seeing 'session aged out' does not mean that firewall is actually dropping traffic. There are multiple reasons for that. It may be the case there are some changes at server end itself. Also if you are trying to access it on TCP port, have you tried to telnet syslog server from client on tcp port?&lt;/P&gt;&lt;P&gt;Are you able to do so?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Sat, 15 Feb 2020 13:50:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311356#M80578</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-15T13:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslog app id - problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311358#M80580</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Very true, but I had tcpdump on both side - client and server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;syn tick&lt;/P&gt;&lt;P&gt;syn ack tick&lt;/P&gt;&lt;P&gt;syn ack ack tick&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then I see the client trying to push and then flush the tcp connection they don't actually make it to the syslog server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Feb 2020 14:25:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311358#M80580</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2020-02-15T14:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslog app id - problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311604#M80628</link>
      <description>&lt;P&gt;So the word i got from support you can't use app override to a preconfigure app and override the port number...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sigh ... tried that and its still not working &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2020 22:43:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311604#M80628</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2020-02-17T22:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslog app id - problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311615#M80631</link>
      <description>&lt;P&gt;Okay worked out the issue !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;asym routing&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;client -&amp;gt; external address&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;client -&amp;gt; fw -&amp;gt; syslog server via internal address -&amp;gt; loopback (external address !).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;return packet was directly back to the client. the FW wasn't seeing all of the packets !'&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2020 02:21:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslog-app-id-problems/m-p/311615#M80631</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2020-02-18T02:21:13Z</dc:date>
    </item>
  </channel>
</rss>

