<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I'm having a problem with Canon printers communicating with an external IP (Canon site). in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-having-a-problem-with-canon-printers-communicating-with-an/m-p/1042#M811</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I saw the session status is showing as =" INCOMPLETE". Incomplete means that either the three way TCP handshake did NOT complete or the three way TCP handshake did complete but there was no data after the handshake to identify the application. In other words that traffic you are seeing is not really an application.&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;So to explain a little clearer, if a client sends a server a &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;syn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; and the Palo Alto device creates a session for that &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;syn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;, but the server never sends a SYN ACK in response back to the client, then that session would be seen as incomplete.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is an urgent requirement, please open a ticket with PAN support and let me know the ticket number.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Dec 2013 01:45:07 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2013-12-04T01:45:07Z</dc:date>
    <item>
      <title>I'm having a problem with Canon printers communicating with an external IP (Canon site).</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-having-a-problem-with-canon-printers-communicating-with-an/m-p/1041#M810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm having a problem with Canon printers communicating with an external IP (Canon site).&amp;nbsp; They are trying to communicate to a particular IP on port 443 (simple, right?) but they aren't contacting the destination.&amp;nbsp; I checked my Palo monitor and didn't see anything wrong but I thought I'd create fresh rules just for these printers.&amp;nbsp; So, I've setup rules to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;NOT decrypt packets from the printer subnet&lt;/LI&gt;&lt;LI&gt;Allow all from &lt;UL&gt;&lt;LI&gt;From Zone:&amp;nbsp; Trust&lt;/LI&gt;&lt;LI&gt;To Zone:&amp;nbsp; Untrust&lt;/LI&gt;&lt;LI&gt;Source Address:&amp;nbsp; Printer Subnet&lt;/LI&gt;&lt;LI&gt;Destination Address:&amp;nbsp; ANY&lt;/LI&gt;&lt;LI&gt;Service:&amp;nbsp; Custom service - TCP / Destination port 443 / Source port &amp;gt; 0&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I've set the rule to log at session start and end.&amp;nbsp; I see the attempted communication alongside the correct rule and an allow.&amp;nbsp; But, the application appears as "incomplete".&amp;nbsp; The printers cannot contact the remote IP.&amp;nbsp; I've connected up one of these printers to a DSL line that doesn't traverse the Palo and it works.&amp;nbsp; If I try to browse to the IP from a web browser via the Palo, it works and I see the application appear correctly in the Palo monitor... See below (bottom one is me browsing via web and top one is from printer subnet):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" height="47" src="https://live.paloaltonetworks.com/legacyfs/online/10126_pastedImage_7.png" style="width: 1040.71px; height: 47px;" width="1041" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas on this?&amp;nbsp; I've tried manipulating security rules, decryption rules, services, etc with no success.&amp;nbsp; I really want to blame it on the Canon printers, but as they work over DSL, I can't &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Dec 2013 17:01:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-having-a-problem-with-canon-printers-communicating-with-an/m-p/1041#M810</guid>
      <dc:creator>itdeptcinven</dc:creator>
      <dc:date>2013-12-03T17:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: I'm having a problem with Canon printers communicating with an external IP (Canon site).</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-having-a-problem-with-canon-printers-communicating-with-an/m-p/1042#M811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I saw the session status is showing as =" INCOMPLETE". Incomplete means that either the three way TCP handshake did NOT complete or the three way TCP handshake did complete but there was no data after the handshake to identify the application. In other words that traffic you are seeing is not really an application.&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;So to explain a little clearer, if a client sends a server a &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;syn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; and the Palo Alto device creates a session for that &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;syn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;, but the server never sends a SYN ACK in response back to the client, then that session would be seen as incomplete.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is an urgent requirement, please open a ticket with PAN support and let me know the ticket number.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Dec 2013 01:45:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-having-a-problem-with-canon-printers-communicating-with-an/m-p/1042#M811</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-12-04T01:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: I'm having a problem with Canon printers communicating with an external IP (Canon site).</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-having-a-problem-with-canon-printers-communicating-with-an/m-p/1043#M812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hulk, thanks for your response.&amp;nbsp; It's not urgent as this has been going on for a while.&amp;nbsp; However, if I can't find a solution, in the next couple of days, I'll log it.&amp;nbsp; Besides, I won't earn the badges if I log it :smileygrin:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you've said is what I thought, but when the device is connected to a dsl line it works as Canon expect it to.&amp;nbsp; And as the picture above shows, when I browse to to IP from a browser, the Palo picks it up correctly.&amp;nbsp; Everything points to a problem with the printer until it's connected to the dsl line.&amp;nbsp; I'm at a total loss.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Dec 2013 09:44:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-having-a-problem-with-canon-printers-communicating-with-an/m-p/1043#M812</guid>
      <dc:creator>itdeptcinven</dc:creator>
      <dc:date>2013-12-04T09:44:11Z</dc:date>
    </item>
  </channel>
</rss>

