<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PRe: Session End reason &amp;amp; Application Status in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-amp-application-status/m-p/356728#M87680</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/126926"&gt;@Diyar.m&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ping (ICMP) will survive asymmetric routing, but TCP won't.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Oct 2020 11:10:41 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2020-10-16T11:10:41Z</dc:date>
    <item>
      <title>Session End reason &amp; Application Status</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-amp-application-status/m-p/226199#M65126</link>
      <description>&lt;P&gt;I would like to know about Palo Alto firewall Session End reason, why we are getting those reasons &amp;amp; how we can resolve the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;tcp-rst-from-client—&amp;gt; it mean the client sent a TCP reset to the server.&lt;/P&gt;&lt;P&gt;tcp-rst-from-server—&amp;gt; it mean the server sent a TCP reset to the client.&lt;/P&gt;&lt;P&gt;Aged-Out -&amp;gt; Session Time out&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I am looking for the solution how we can resolve that issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Simillarly I would like to know about Application status:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What exactly mean by "Incomplete", "Unknow" &amp;amp; so on... How we can resolve these issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 06:11:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-amp-application-status/m-p/226199#M65126</guid>
      <dc:creator>ndeshmukh</dc:creator>
      <dc:date>2018-08-07T06:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: Session End reason &amp; Application Status</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-amp-application-status/m-p/226217#M65127</link>
      <description>&lt;P&gt;For session end reason you&amp;nbsp;don't have to do anything on PA (unless it's actually denied by PA). And reset (either by server or client) is a normal ending of TCP session. Session time out is also a normal occurence for non TCP sessions. So no action is needed there, these are just helpful info PA provides.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Incomplete means TCP 3 way handhsake didn't finish. It can be either routing issue or just destination server not listening on that port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unknown-tcp (or -udp) means there is some traffic passing through FW but PA can't recognise the application. These are the cases you should investigate; what is at source IP, which service is listening at destination IP, maybe do a packet capture for this traffic...&lt;/P&gt;&lt;P&gt;Idea is to identify the traffic as you don't want any unknown traffic in your network. Once you identify it and find the reason you can either block it or tell PA how to identify it (by Application Override or with custom application signature).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 07:27:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-amp-application-status/m-p/226217#M65127</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-08-07T07:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: Session End reason &amp; Application Status</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-amp-application-status/m-p/226376#M65168</link>
      <description>&lt;P&gt;Incomplete could also mean that the tcp handshake did finish and then the server resets the connection right after that handshake&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 21:52:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-amp-application-status/m-p/226376#M65168</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-07T21:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: Session End reason &amp; Application Status</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-amp-application-status/m-p/355024#M87506</link>
      <description>&lt;P&gt;If I have a ping between client and server, that means I have routing. Is there anything else I have to look at it?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 04:39:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-amp-application-status/m-p/355024#M87506</guid>
      <dc:creator>Diyar.m</dc:creator>
      <dc:date>2020-10-08T04:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: Session End reason &amp; Application Status</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-amp-application-status/m-p/355425#M87538</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/126926"&gt;@Diyar.m&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ping uses ICMP. Normally &lt;STRONG&gt;tcp-rst-from-server &lt;/STRONG&gt;or &lt;STRONG&gt;tcp-rst-from-client &lt;/STRONG&gt;is related TCP sessions traveling via firewall. Its just showing what was the reason for end of session. As already stated by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt; It is not palo alto who is doing anything to the session unless it block anything explicitly. Such TCP RST flags are indication of the TCP session end from any side (client/server).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/65800"&gt;@ndeshmukh&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Incomplete&lt;/STRONG&gt; in the Application Field - It means either TCP 3 way handshake between client and server is not completed &lt;STRONG&gt;or &lt;/STRONG&gt;the handshake did completed but there was no data to consider or recognize it as a application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;e.g. For Client TCP Sync, there is not ACK from the server end, it shows incomplete. If you do normal telnet on TCP port and you get the black screen, it means handshake was completed. Such normal telnet sessions also Palo alto will recognize it as&amp;nbsp;&lt;STRONG&gt;incomplete&amp;nbsp;&lt;/STRONG&gt;as just handshake got completed but there was no application data after it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Insufficient&lt;/STRONG&gt; - it means there is not enough data packets to identify it as a application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More details on such application status can be found at &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2020 13:28:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-amp-application-status/m-p/355425#M87538</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-10-09T13:28:44Z</dc:date>
    </item>
    <item>
      <title>PRe: Session End reason &amp; Application Status</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-amp-application-status/m-p/356728#M87680</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/126926"&gt;@Diyar.m&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ping (ICMP) will survive asymmetric routing, but TCP won't.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2020 11:10:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-amp-application-status/m-p/356728#M87680</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2020-10-16T11:10:41Z</dc:date>
    </item>
  </channel>
</rss>

