<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: why firewall drop server hello message in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/why-firewall-drop-server-hello-message/m-p/341771#M85727</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132490"&gt;@bit_byte&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are both firewalls have same model and same PAN OS?&lt;/P&gt;
&lt;P&gt;Check the security policy on Firewall&amp;nbsp; A and B and compare them?&lt;/P&gt;
&lt;P&gt;Make sure they are similar in security profiles.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Look for threat logs in Firewall A if any traffic is denied there?&lt;/P&gt;
&lt;P&gt;When you did packet capture do you see any drops on firewall A and B?&lt;/P&gt;
&lt;P&gt;Use this command test security policy on both Firewall A and B&lt;/P&gt;
&lt;P&gt;Also as Remo mentioned when you do the pcap check global counters on both Firewalls and look for drops?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 02 Aug 2020 16:17:11 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2020-08-02T16:17:11Z</dc:date>
    <item>
      <title>why firewall drop server hello message</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-firewall-drop-server-hello-message/m-p/341563#M85671</link>
      <description>&lt;P&gt;network flow&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lan Network --&amp;gt;Firewall A-----&amp;gt;switch --&amp;gt;-Firewall B ----&amp;gt;Internet--------&amp;gt;Database server&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are facing issue to connect database server from our lan network.&lt;/P&gt;&lt;P&gt;We took packet capture on Firewall A and firewall B .&lt;/P&gt;&lt;P&gt;When we initiate traffic from LAN network to database server:&lt;/P&gt;&lt;P&gt;Firewall B ; We are getting client Hello and server hello message on Firewall B&lt;/P&gt;&lt;P&gt;Firewall A: Only client hello message we got means server hello message drop by firewall A&amp;nbsp;&lt;/P&gt;&lt;P&gt;that why we could not able to connect with database server.&lt;/P&gt;&lt;P&gt;We are not using any decryption and proxy we have checked counter value also we did not get any drop.&lt;/P&gt;&lt;P&gt;traffic monitor logs session end reason: TCP-rst by client&lt;/P&gt;&lt;P&gt;@&amp;nbsp;&lt;SPAN class="UserName lia-user-name lia-user-rank-Cyber-Elite lia-component-message-view-widget-author-username"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039" target="_self"&gt;&lt;SPAN class="login-bold"&gt;MP18&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;@&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Cyber-Elite lia-component-message-view-widget-author-username"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592" target="_self"&gt;&lt;SPAN class="login-bold"&gt;Vsys_remo&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Cyber-Elite lia-component-message-view-widget-author-username"&gt;&lt;SPAN class="login-bold"&gt;@&amp;nbsp;Reaper&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 09:13:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-firewall-drop-server-hello-message/m-p/341563#M85671</guid>
      <dc:creator>bit_byte</dc:creator>
      <dc:date>2020-07-31T09:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: why firewall drop server hello message</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-firewall-drop-server-hello-message/m-p/341677#M85699</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132490"&gt;@bit_byte&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is the assumption correct, that both firewalls are paloalto firewalls?&lt;/P&gt;
&lt;P&gt;Anyway, when you say "&lt;SPAN&gt;Firewall A: Only client hello message we got means server hello message drop by firewall A", does this really mean the server hello is dropped by firewall A or isn't there any server hello on firewall A which would mean that the server hello is dropped by firewall B.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 20:49:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-firewall-drop-server-hello-message/m-p/341677#M85699</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-07-31T20:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: why firewall drop server hello message</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-firewall-drop-server-hello-message/m-p/341716#M85710</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, both firewalls are PA.&lt;/P&gt;&lt;P&gt;We have already bypass firewall A and we did the test from the switch then we can able to connect with the database server.&lt;/P&gt;&lt;P&gt;That means Lan pc did not get server hello that why TLS connection would not able to establish.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Aug 2020 08:09:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-firewall-drop-server-hello-message/m-p/341716#M85710</guid>
      <dc:creator>bit_byte</dc:creator>
      <dc:date>2020-08-01T08:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: why firewall drop server hello message</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-firewall-drop-server-hello-message/m-p/341718#M85712</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132490"&gt;@bit_byte&lt;/a&gt;&amp;nbsp;So when you did a packet capture, was the server hello in the drop stage of the capture? How does the session look like in the traffic log? Did you try a packet log debug via cli and checked the global counters when testing the connection?&lt;/P&gt;</description>
      <pubDate>Sat, 01 Aug 2020 08:25:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-firewall-drop-server-hello-message/m-p/341718#M85712</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-08-01T08:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: why firewall drop server hello message</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-firewall-drop-server-hello-message/m-p/341771#M85727</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132490"&gt;@bit_byte&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are both firewalls have same model and same PAN OS?&lt;/P&gt;
&lt;P&gt;Check the security policy on Firewall&amp;nbsp; A and B and compare them?&lt;/P&gt;
&lt;P&gt;Make sure they are similar in security profiles.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Look for threat logs in Firewall A if any traffic is denied there?&lt;/P&gt;
&lt;P&gt;When you did packet capture do you see any drops on firewall A and B?&lt;/P&gt;
&lt;P&gt;Use this command test security policy on both Firewall A and B&lt;/P&gt;
&lt;P&gt;Also as Remo mentioned when you do the pcap check global counters on both Firewalls and look for drops?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Aug 2020 16:17:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-firewall-drop-server-hello-message/m-p/341771#M85727</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-08-02T16:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: why firewall drop server hello message</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-firewall-drop-server-hello-message/m-p/429502#M94911</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132490"&gt;@bit_byte&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you solve this problem. We are facing similar issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our environment&lt;/P&gt;&lt;P&gt;client-&amp;gt;palo alto-&amp;gt;f5 reverseproxy-&amp;gt;webapp server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Observation&lt;/P&gt;&lt;P&gt;We could notice that the f5 is receiving client-hello and it is responding with server hello. A PCap at the PA shows that the server hello is recd. But a packet capture at the client shows no server-hello message.&amp;nbsp; There is no specific change we did in the environment and suddenly this issue has cropped up.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we bypassed firewall and routed the traffic directly from Client to f5, the web page loads properly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Kanthanathan&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 01:57:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-firewall-drop-server-hello-message/m-p/429502#M94911</guid>
      <dc:creator>Kanthanathan</dc:creator>
      <dc:date>2021-08-27T01:57:16Z</dc:date>
    </item>
  </channel>
</rss>

