<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: All incoming TCP connections blocked for 5 minutes at random times. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336746#M84865</link>
    <description>&lt;P&gt;DNS does use UDP, but can also use TCP over port 53 as well.&amp;nbsp; Any way if you have site-to-site vpn or something similar, you may want some exclusions to Dos / Zone protections policies.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Jul 2020 19:54:50 GMT</pubDate>
    <dc:creator>fhewiufhwefhwe</dc:creator>
    <dc:date>2020-07-06T19:54:50Z</dc:date>
    <item>
      <title>All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336313#M84713</link>
      <description>&lt;P&gt;At random times all TCP connections from the Internet are blocked (all ports and all IPs) for incoming traffic only.&amp;nbsp; Websites, mail servers etc are not accessible from the Internet.&amp;nbsp; UDP and ICMP are not affected.&amp;nbsp; What could be causing this?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 14:46:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336313#M84713</guid>
      <dc:creator>sharam</dc:creator>
      <dc:date>2020-07-01T14:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336366#M84726</link>
      <description>&lt;P&gt;Sounds like a DoS profile that is setup incorrectly and is blocking the destination address (your public IP) or vulnerability protection profile with the same misconfiguration. The default block-ip timeout is 5 minutes, which lines up with what you are running into.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 18:29:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336366#M84726</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-01T18:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336374#M84728</link>
      <description>&lt;P&gt;There are no entries under Policy -&amp;gt; DoS Protection.&lt;/P&gt;&lt;P&gt;Is there another location I can look?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 20:20:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336374#M84728</guid>
      <dc:creator>sharam</dc:creator>
      <dc:date>2020-07-01T20:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336375#M84729</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/147381"&gt;@sharam&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;If you had any that's where they would be. What does your Vulnerability Protection profile look like for the security rulebase entries allowing this traffic inbound? That would be the next thing I would look at.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 20:27:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336375#M84729</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-01T20:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336681#M84844</link>
      <description>&lt;P&gt;What I am seeing in logs related to the outage is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sharam_0-1594047748081.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26593i973833DD82ABD672/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="sharam_0-1594047748081.png" alt="sharam_0-1594047748081.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But I am not able to see which rulebase this it related to.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 15:03:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336681#M84844</guid>
      <dc:creator>sharam</dc:creator>
      <dc:date>2020-07-06T15:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336697#M84850</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/147381"&gt;@sharam&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;What I am seeing in logs related to the outage is:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sharam_0-1594047748081.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26593i973833DD82ABD672/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="sharam_0-1594047748081.png" alt="sharam_0-1594047748081.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But I am not able to see which rulebase this it related to.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;You're showing the detailed log entry.&amp;nbsp; (You've clicked the magnifying glass next to an entry in the threat log)&amp;nbsp; To better help point out why this is happening we need to see the main entry.&amp;nbsp; It looks like this is happening because of a VP profile which is attached to a security policy rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="threat.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26595i1F8A2FC53EB6FC85/image-size/large?v=v2&amp;amp;px=999" role="button" title="threat.PNG" alt="threat.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 16:24:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336697#M84850</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2020-07-06T16:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336723#M84857</link>
      <description>&lt;P&gt;zone protection&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 18:32:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336723#M84857</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2020-07-06T18:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336731#M84859</link>
      <description>&lt;P&gt;Thank you for your response&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;.&amp;nbsp; This is the main entry of an event that just happened today:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sharam_0-1594061476300.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26601iE27DBA95B74E889D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="sharam_0-1594061476300.png" alt="sharam_0-1594061476300.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 18:52:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336731#M84859</guid>
      <dc:creator>sharam</dc:creator>
      <dc:date>2020-07-06T18:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336733#M84860</link>
      <description>&lt;P&gt;Can you please be more specific?&amp;nbsp; Zone Pro is the first place we looked and changed various config to no effect.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 19:07:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336733#M84860</guid>
      <dc:creator>sharam</dc:creator>
      <dc:date>2020-07-06T19:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336739#M84861</link>
      <description>&lt;P&gt;Did you look under Objects -&amp;gt; Security Profiles -&amp;gt; Dos Protection?&amp;nbsp; &amp;nbsp;Th default block duration is 5 minutes..&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 19:28:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336739#M84861</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2020-07-06T19:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336740#M84862</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93469"&gt;@fhewiufhwefhwe&lt;/a&gt;&amp;nbsp;there are no entries under&amp;nbsp;&lt;SPAN&gt;Objects -&amp;gt; Security Profiles -&amp;gt; Dos Protection, not even default.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 19:35:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336740#M84862</guid>
      <dc:creator>sharam</dc:creator>
      <dc:date>2020-07-06T19:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336742#M84863</link>
      <description>&lt;P&gt;Do you have source address exclusions under Reconnaissance Protection?&amp;nbsp; You may want to include highly trusted items on your allow list there, such as internal DNS forwarders if you have them.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 19:37:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336742#M84863</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2020-07-06T19:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336744#M84864</link>
      <description>&lt;P&gt;We don't have this problem with UDP which is what DNS uses.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 19:46:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336744#M84864</guid>
      <dc:creator>sharam</dc:creator>
      <dc:date>2020-07-06T19:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336746#M84865</link>
      <description>&lt;P&gt;DNS does use UDP, but can also use TCP over port 53 as well.&amp;nbsp; Any way if you have site-to-site vpn or something similar, you may want some exclusions to Dos / Zone protections policies.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 19:54:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336746#M84865</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2020-07-06T19:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336747#M84866</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93469"&gt;@fhewiufhwefhwe&lt;/a&gt;&amp;nbsp;but the problem we are facing is that when the TCP outage occurs our thousands of user who are scattered across the Internet world are not able to reach our websites or mail servers.&amp;nbsp; We don't want the firewall to block the whole Internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I should also point out if the subject is not clear that the problem is only with incoming TCP traffic.&amp;nbsp; Outgoing traffic is not affected.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 20:18:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336747#M84866</guid>
      <dc:creator>sharam</dc:creator>
      <dc:date>2020-07-06T20:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336750#M84867</link>
      <description>&lt;P&gt;Have you tried increasing the thresholds under SYN Flood Protection then?&amp;nbsp; How high is your firewall on resource utilization?&amp;nbsp; I'm wondering if you might be able to use SYN Cookies instead of Random Early Drop action?&amp;nbsp; &amp;nbsp;Note that I have not tried this myself.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm also thinking that you might want to setup SNMP monitoring the DoS counters on the firewall.&amp;nbsp; I recently tried to configure this, but have not had success yet.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 20:28:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336750#M84867</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2020-07-06T20:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336756#M84870</link>
      <description>&lt;P&gt;This article might help.&amp;nbsp; I've been meaning to read it myself and figure out how to setup snmp monitoring for DoS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClOKCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClOKCA0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 20:43:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336756#M84870</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2020-07-06T20:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336760#M84873</link>
      <description>&lt;P&gt;I have increased the threshold from 100 to 500 under Reconnaissance per your suggestion.&amp;nbsp; Will see if that makes a difference.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 20:53:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336760#M84873</guid>
      <dc:creator>sharam</dc:creator>
      <dc:date>2020-07-06T20:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336764#M84875</link>
      <description>&lt;P&gt;I did not mean the threshold under Reconnaissance Protection.&amp;nbsp; I mean the threshold under Flood Protection.&amp;nbsp; The defaults are 10,000 fro Alarm Rate and Activate, and 40,000 for maximum connections/sec.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 20:58:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336764#M84875</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2020-07-06T20:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: All incoming TCP connections blocked for 5 minutes at random times.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336766#M84876</link>
      <description>&lt;P&gt;Those are already pretty high.&amp;nbsp; Alarm and active reates are 59,000.&amp;nbsp; Maximum connections at 100,000.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 21:13:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/all-incoming-tcp-connections-blocked-for-5-minutes-at-random/m-p/336766#M84876</guid>
      <dc:creator>sharam</dc:creator>
      <dc:date>2020-07-06T21:13:17Z</dc:date>
    </item>
  </channel>
</rss>

