<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unexpected behaviour in security policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341107#M85592</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I took the packet capture and found the SYN packet is going towards the server but didn't get any ACK from the server side.&lt;/P&gt;&lt;P&gt;then TCP retransmission packet has been captured.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jul 2020 19:07:21 GMT</pubDate>
    <dc:creator>Jafar_Hussain</dc:creator>
    <dc:date>2020-07-28T19:07:21Z</dc:date>
    <item>
      <title>Unexpected behaviour in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/340917#M85538</link>
      <description>&lt;P&gt;I have one server belongs from the DMZ zone.&lt;BR /&gt;Example:-&lt;BR /&gt;server ip- 2.2.2.2&lt;BR /&gt;source ip for VPN user - 1.1.1.1&lt;BR /&gt;VPN zone&lt;BR /&gt;DMZ zone&lt;/P&gt;&lt;P&gt;There is 2 scenerio:-&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;policy(1) -&lt;/STRONG&gt;&lt;/U&gt; I have created a policy like:-&lt;BR /&gt;sourcezone- VPNzone&lt;BR /&gt;source ip - 1.1.1.1&lt;BR /&gt;destination zone - DMZ zone&lt;BR /&gt;destination IP - Create an address object for 2.2.2.2.&lt;BR /&gt;Application - ANY&lt;BR /&gt;services - ANY&lt;BR /&gt;Action - Allow&lt;BR /&gt;no security profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Policy(2):-&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;sourcezone- VPNzone&lt;BR /&gt;source ip - 1.1.1.1&lt;BR /&gt;destination zone - DMZ zone&lt;BR /&gt;destination IP - &lt;EM&gt;&lt;STRONG&gt;2.2.2.2&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;Application - ANY&lt;BR /&gt;services - ANY&lt;BR /&gt;Action - Allow&lt;BR /&gt;no security profile.&lt;/P&gt;&lt;P&gt;I can access 2.2.2.2 by policy(1) but when i apply policy(2) it is not accessible why this strange behaviour i am not able to find out.&lt;/P&gt;&lt;P&gt;once i applied policy -2 the traffic has been dropped.&lt;/P&gt;&lt;P&gt;PAN-OS version - 9.0.9-h1&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 18:18:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/340917#M85538</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-07-27T18:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected behaviour in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/340958#M85550</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I would say make sure you have logging enabled on the policy and check the logs to see why the PAN is denying the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 21:29:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/340958#M85550</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-07-27T21:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected behaviour in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341021#M85567</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes , i have checked the same , once i applied policy-1 it will bypass all the policy and heat directly to deny any-any.&lt;/P&gt;&lt;P&gt;And i can see the traffic is dropped.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 10:00:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341021#M85567</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-07-28T10:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected behaviour in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341056#M85580</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;This is definitely interesting. I would suggest opening a support case and see what they can find.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 14:34:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341056#M85580</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-07-28T14:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected behaviour in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341088#M85588</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will say check the objects, addresses then look&amp;nbsp; for source and destination address.&lt;/P&gt;
&lt;P&gt;Make sure under IP netmask it is 1.1.1.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or 2.2.2.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 17:11:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341088#M85588</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-28T17:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected behaviour in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341094#M85590</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply, my concern is why the firewall deny traffic once i configure the security policy-1 and given the IP address in destination, however, once i created the object for the same IP address and allow in destination all are working fine.&lt;/P&gt;&lt;P&gt;This issue is occurring only for one IP address rest are working fine.&lt;/P&gt;&lt;P&gt;I am not able to find out the reason.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 17:44:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341094#M85590</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-07-28T17:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected behaviour in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341106#M85591</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can do the PCAP on the firewall then you will have more info why PA is denying the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 18:59:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341106#M85591</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-28T18:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected behaviour in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341107#M85592</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I took the packet capture and found the SYN packet is going towards the server but didn't get any ACK from the server side.&lt;/P&gt;&lt;P&gt;then TCP retransmission packet has been captured.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 19:07:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341107#M85592</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-07-28T19:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected behaviour in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341437#M85647</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just curious do you find solution for this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 14:35:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341437#M85647</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-30T14:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected behaviour in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341828#M85736</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not yet.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 11:42:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unexpected-behaviour-in-security-policy/m-p/341828#M85736</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-08-03T11:42:23Z</dc:date>
    </item>
  </channel>
</rss>

