<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lot of non-syn-tcp in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/lot-of-non-syn-tcp/m-p/366649#M88735</link>
    <description>&lt;P&gt;Hello there!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think you explained the only 2 examples that I could think of.&lt;/P&gt;
&lt;P&gt;But I also do not think any keep-alive after the 3600 sec would keep a flow open, when the session itself is closed, the application/connection would drop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So are you saying that things are working fine, and you see a bunch of keep alives, or are you saying that the connection is dropped at the 1.5 hour mark, because there is no more session for the FW to inspect?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 01 Dec 2020 22:43:37 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2020-12-01T22:43:37Z</dc:date>
    <item>
      <title>Lot of non-syn-tcp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lot-of-non-syn-tcp/m-p/366586#M88727</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;we have a lot (I mean a LOT :-)) of non-syn-tcp traffic on our PA5220 cluster. The PA is in an enterprise company.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are we sure that the non-syn-tcp means that there is an asymmetric flow? Let me give you an example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Host A sends a SYN to Host B passing through PA&lt;/P&gt;&lt;P&gt;2) PA recognize it properly and establish a sessione in its session table&lt;/P&gt;&lt;P&gt;3) Host B receive that SYN and start the standard comunication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Host A has its timeout idle session at 3 hours;&lt;/P&gt;&lt;P&gt;Host B has its timeout idle session at 3 hours;&lt;/P&gt;&lt;P&gt;Palo Alto has ita timeoute idle TCP session at 1 hour.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After 1.5 hour the host A send a TCP Keep-Alive but on the PA the the session doesn't exist anymore... the timeout was expired.&lt;/P&gt;&lt;P&gt;So, that flow will be recognized as non-syn-tcp. But it is not an Asymmetric Flow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, do you know if there is some other situation where the non-syn-tcp not mean Asymmetric Routing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bye!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 17:23:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lot-of-non-syn-tcp/m-p/366586#M88727</guid>
      <dc:creator>paboy1</dc:creator>
      <dc:date>2020-12-01T17:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: Lot of non-syn-tcp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lot-of-non-syn-tcp/m-p/366649#M88735</link>
      <description>&lt;P&gt;Hello there!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think you explained the only 2 examples that I could think of.&lt;/P&gt;
&lt;P&gt;But I also do not think any keep-alive after the 3600 sec would keep a flow open, when the session itself is closed, the application/connection would drop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So are you saying that things are working fine, and you see a bunch of keep alives, or are you saying that the connection is dropped at the 1.5 hour mark, because there is no more session for the FW to inspect?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 22:43:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lot-of-non-syn-tcp/m-p/366649#M88735</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-12-01T22:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: Lot of non-syn-tcp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lot-of-non-syn-tcp/m-p/366667#M88739</link>
      <description>&lt;P&gt;Well non-syn-tcp means the firewall is receiving 'first' packets (ones that don't belong to an existing flow) that are not SYN, so there has not been a proper TCP handshake&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this does not mean traffic is asymmetrical, asymmetric routing is just one of the more common causes that the firewall is receiving ACK packets where no session exists&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your further example this is highlighted: session is torn down before either side is actually done talking, causing the firewall to receive an ACK packet for a non-existent session&lt;/P&gt;&lt;P&gt;This can be solved by editing the application and increasing the lifetime and idle timers to correspond with the expected time between keepalives&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 23:51:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lot-of-non-syn-tcp/m-p/366667#M88739</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-12-01T23:51:07Z</dc:date>
    </item>
  </channel>
</rss>

