<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP Session Stuck and only manual clear of the session id solve the iss in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-session-stuck-and-only-manual-clear-of-the-session-id-solve/m-p/341035#M85572</link>
    <description>&lt;P&gt;my guess would actually be that firewall1 is the problem, as it has terminated the session, any followup ACK packets will be discarded by it&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jul 2020 12:37:17 GMT</pubDate>
    <dc:creator>Thyrion</dc:creator>
    <dc:date>2020-07-28T12:37:17Z</dc:date>
    <item>
      <title>TCP Session Stuck and only manual clear of the session id solve the issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-session-stuck-and-only-manual-clear-of-the-session-id-solve/m-p/341025#M85569</link>
      <description>&lt;P&gt;Dear Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are facing a strange behavior with a tcp flow that is meant to mount a volume on a linux server, from time to time, the session get stuck in the firewall causing an error while trying to mount the device, the topology is as follow:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Linux Server &amp;lt;-&amp;gt; Firewall 1 &amp;lt;-&amp;gt; Firewall 2 &amp;lt;-&amp;gt; Script Server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the Script server execute a backup script that mount the volume in the linux Server and start uploading the files, when no session is created in the firewall the script work perfectly but when the issue happen we see at the Firewall two a session stuck and the volume doesn't mount&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is the tcp info:&lt;/P&gt;&lt;P&gt;(active)&amp;gt; show session all filter source 10.X.X.X destination 10.Y.Y.Y&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;ID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application&amp;nbsp;&amp;nbsp;&amp;nbsp; State&amp;nbsp;&amp;nbsp; Type Flag&amp;nbsp; Src[Sport]/Zone/Proto (translated IP[Port])&lt;/P&gt;&lt;P&gt;Vsys&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dst[Dport]/Zone (translated IP[Port])&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;3146098&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; undecided&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACTIVE&amp;nbsp; FLOW&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.X.X.X[782]/APP/6&amp;nbsp; (10.X.X.X[782])&lt;/P&gt;&lt;P&gt;vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.Y.Y.Y[2049]/RULEX&amp;nbsp; (10.Y.Y.Y[2049])&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(active)&amp;gt; show session id 3146098&lt;/P&gt;&lt;P&gt;Session 3146098&lt;/P&gt;&lt;P&gt;c2s flow:&lt;BR /&gt;source: 10.X.X.X [APP]&lt;BR /&gt;dst: 10.Y.Y.Y&lt;BR /&gt;proto: 6&lt;BR /&gt;sport: 782 dport: 2049&lt;BR /&gt;state: ACTIVE type: FLOW&lt;BR /&gt;src user: unknown&lt;BR /&gt;dst user: unknown&lt;/P&gt;&lt;P&gt;s2c flow:&lt;BR /&gt;source: 10.Y.Y.Y [RULEX]&lt;BR /&gt;dst: 10.X.X.X&lt;BR /&gt;proto: 6&lt;BR /&gt;sport: 2049 dport: 782&lt;BR /&gt;state: ACTIVE type: FLOW&lt;BR /&gt;src user: unknown&lt;BR /&gt;dst user: unknown&lt;/P&gt;&lt;P&gt;Slot : 1&lt;BR /&gt;DP : 0&lt;BR /&gt;index(local): : 3146098&lt;BR /&gt;start time : Wed Jun 24 21:03:01 2020&lt;BR /&gt;timeout : 120 sec&lt;BR /&gt;time to live : 108 sec&lt;BR /&gt;total byte count(c2s) : 5613888&lt;BR /&gt;total byte count(s2c) : 528&lt;BR /&gt;layer7 packet count(c2s) : 71974&lt;BR /&gt;layer7 packet count(s2c) : 8&lt;BR /&gt;vsys : vsys1&lt;BR /&gt;shared gateway : sg2&lt;BR /&gt;application : undecided&lt;BR /&gt;rule : RULEX&lt;BR /&gt;service timeout override(index) : False&lt;BR /&gt;application db : 0&lt;BR /&gt;app.id : c2s node (0, 0) s2s node (0, 0)&lt;BR /&gt;session to be logged at end : True&lt;BR /&gt;session in session ager : True&lt;BR /&gt;session updated by HA peer : False&lt;BR /&gt;layer7 processing : enabled&lt;BR /&gt;URL filtering enabled : False&lt;BR /&gt;session via syn-cookies : False&lt;BR /&gt;session terminated on host : False&lt;BR /&gt;session traverses tunnel : False&lt;BR /&gt;captive portal session : False&lt;BR /&gt;ingress interface : aeX.XXX&lt;BR /&gt;egress interface : aeY&lt;BR /&gt;session QoS rule : N/A (class 4)&lt;BR /&gt;end-reason : unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and only a clear of this session id will solve the issue, both firewalls are on version 8.1.12. no session is seen on Firewall 1 when the issue happen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 11:04:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-session-stuck-and-only-manual-clear-of-the-session-id-solve/m-p/341025#M85569</guid>
      <dc:creator>habib-souag</dc:creator>
      <dc:date>2020-07-28T11:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Session Stuck and only manual clear of the session id solve the iss</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-session-stuck-and-only-manual-clear-of-the-session-id-solve/m-p/341035#M85572</link>
      <description>&lt;P&gt;my guess would actually be that firewall1 is the problem, as it has terminated the session, any followup ACK packets will be discarded by it&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 12:37:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-session-stuck-and-only-manual-clear-of-the-session-id-solve/m-p/341035#M85572</guid>
      <dc:creator>Thyrion</dc:creator>
      <dc:date>2020-07-28T12:37:17Z</dc:date>
    </item>
  </channel>
</rss>

