<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Session moves from ACTIVE to DISCARD in middle of download once zone protection enabled. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/session-moves-from-active-to-discard-in-middle-of-download-once/m-p/376421#M89301</link>
    <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;I am seeing the below behaviour in my PA-850 running on 9.1.4. Security policy is allowed for traffic.&lt;/P&gt;&lt;P&gt;Scenario-1, without zone protection in internet zone - Everything works fin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scenario -2,&lt;/P&gt;&lt;P&gt;Having zone protection with pretty much all options enabled for 'IP Drop' and TCP drop' and other options as well. Applied it on internet zone.&lt;/P&gt;&lt;P&gt;Everything works fine like browsing, streaming etc.. but once I start downloading a big file, after downloading some part, the session will move from Active to discard and the download will simply hung. There is no application shift(connection is over ssl and policy allows every app).&lt;/P&gt;&lt;P&gt;when checked for global counters, I can see the following counter increasing,&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;packets dropped because of failure in tcp reassembly&lt;/LI&gt;&lt;LI&gt;packets dropped due to the limitation on tcp out-of-order queue size&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Even though the drops are there, not sure why the session should move to discard state.&lt;/P&gt;&lt;P&gt;After the session hungs, I can see the counter "packet buffer pointer inconsistent" as well. Once I remove zone-protection, everything works fine ( i have tested iso download from releases.ubuntu.com).&lt;/P&gt;&lt;P&gt;What are the reasons the session moves from active to discard? I can't see any threat logs.&lt;/P&gt;&lt;P&gt;buffer protection is not enabled in global.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;----counter-----&lt;/P&gt;&lt;P&gt;show counter global filter packet-filter yes delta yes&lt;BR /&gt;&lt;BR /&gt;Global counters:&lt;BR /&gt;Elapsed time since last sampling: 3.72 seconds&lt;/P&gt;&lt;P&gt;name value rate severity category aspect description&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;pkt_outstanding 4026 1310 info packet pktproc Outstanding packet to be transmitted&lt;BR /&gt;pkt_alloc 5 1 info packet resource Packets allocated&lt;BR /&gt;pkt_inconsist 2101 683 info packet pktproc Packet buffer pointer inconsistent&lt;BR /&gt;session_freed 28 9 info session resource Sessions freed&lt;BR /&gt;flow_fwd_drop_noxmit 120 39 info flow forward Packet dropped at forwarding: noxmit&lt;BR /&gt;flow_qos_pkt_enque 2094 681 info flow qos Packet enqueued to QoS module&lt;BR /&gt;flow_dos_ag_buckets_upd 1 0 info flow dos Updated aggregate buckets for aging&lt;BR /&gt;flow_pppoe_encap_pkts 3868 1259 info flow pktproc Total packets encapsulated with PPPoE header&lt;BR /&gt;flow_host_pkt_xmt 5 1 info flow mgmt Packets transmitted to control plane&lt;BR /&gt;appid_unknown_fini_empty 11 3 info appid pktproc The number of unknown applications because of no data&lt;BR /&gt;nat_dynamic_port_release 5 1 info nat resource The total number of dynamic_ip_port NAT release called&lt;BR /&gt;dfa_sw 2132 694 info dfa pktproc The total number of dfa match using software&lt;BR /&gt;tcp_drop_packet 7 2 warn tcp pktproc packets dropped because of failure in tcp reassembly&lt;BR /&gt;tcp_pkt_queued 4294967233 1398101312 info tcp resource The number of out of order packets queued in tcp&lt;BR /&gt;tcp_case_2 24 7 info tcp pktproc tcp reassembly case 2&lt;BR /&gt;tcp_exceed_flow_seg_limit 7 2 warn tcp resource packets dropped due to the limitation on tcp out-of-order queue size&lt;BR /&gt;aho_sw_offload 2015 655 info aho pktproc The total number of software aho offload&lt;BR /&gt;ctd_pscan_sw 2132 694 info ctd pktproc The total usage of software for pscan&lt;BR /&gt;ctd_pkt_slowpath 2132 694 info ctd pktproc Packets processed by slowpath&lt;BR /&gt;log_traffic_cnt 28 9 info log system Number of traffic logs&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Dec 2020 15:01:43 GMT</pubDate>
    <dc:creator>Abdul_Razaq</dc:creator>
    <dc:date>2020-12-28T15:01:43Z</dc:date>
    <item>
      <title>Session moves from ACTIVE to DISCARD in middle of download once zone protection enabled.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-moves-from-active-to-discard-in-middle-of-download-once/m-p/376421#M89301</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;I am seeing the below behaviour in my PA-850 running on 9.1.4. Security policy is allowed for traffic.&lt;/P&gt;&lt;P&gt;Scenario-1, without zone protection in internet zone - Everything works fin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scenario -2,&lt;/P&gt;&lt;P&gt;Having zone protection with pretty much all options enabled for 'IP Drop' and TCP drop' and other options as well. Applied it on internet zone.&lt;/P&gt;&lt;P&gt;Everything works fine like browsing, streaming etc.. but once I start downloading a big file, after downloading some part, the session will move from Active to discard and the download will simply hung. There is no application shift(connection is over ssl and policy allows every app).&lt;/P&gt;&lt;P&gt;when checked for global counters, I can see the following counter increasing,&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;packets dropped because of failure in tcp reassembly&lt;/LI&gt;&lt;LI&gt;packets dropped due to the limitation on tcp out-of-order queue size&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Even though the drops are there, not sure why the session should move to discard state.&lt;/P&gt;&lt;P&gt;After the session hungs, I can see the counter "packet buffer pointer inconsistent" as well. Once I remove zone-protection, everything works fine ( i have tested iso download from releases.ubuntu.com).&lt;/P&gt;&lt;P&gt;What are the reasons the session moves from active to discard? I can't see any threat logs.&lt;/P&gt;&lt;P&gt;buffer protection is not enabled in global.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;----counter-----&lt;/P&gt;&lt;P&gt;show counter global filter packet-filter yes delta yes&lt;BR /&gt;&lt;BR /&gt;Global counters:&lt;BR /&gt;Elapsed time since last sampling: 3.72 seconds&lt;/P&gt;&lt;P&gt;name value rate severity category aspect description&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;pkt_outstanding 4026 1310 info packet pktproc Outstanding packet to be transmitted&lt;BR /&gt;pkt_alloc 5 1 info packet resource Packets allocated&lt;BR /&gt;pkt_inconsist 2101 683 info packet pktproc Packet buffer pointer inconsistent&lt;BR /&gt;session_freed 28 9 info session resource Sessions freed&lt;BR /&gt;flow_fwd_drop_noxmit 120 39 info flow forward Packet dropped at forwarding: noxmit&lt;BR /&gt;flow_qos_pkt_enque 2094 681 info flow qos Packet enqueued to QoS module&lt;BR /&gt;flow_dos_ag_buckets_upd 1 0 info flow dos Updated aggregate buckets for aging&lt;BR /&gt;flow_pppoe_encap_pkts 3868 1259 info flow pktproc Total packets encapsulated with PPPoE header&lt;BR /&gt;flow_host_pkt_xmt 5 1 info flow mgmt Packets transmitted to control plane&lt;BR /&gt;appid_unknown_fini_empty 11 3 info appid pktproc The number of unknown applications because of no data&lt;BR /&gt;nat_dynamic_port_release 5 1 info nat resource The total number of dynamic_ip_port NAT release called&lt;BR /&gt;dfa_sw 2132 694 info dfa pktproc The total number of dfa match using software&lt;BR /&gt;tcp_drop_packet 7 2 warn tcp pktproc packets dropped because of failure in tcp reassembly&lt;BR /&gt;tcp_pkt_queued 4294967233 1398101312 info tcp resource The number of out of order packets queued in tcp&lt;BR /&gt;tcp_case_2 24 7 info tcp pktproc tcp reassembly case 2&lt;BR /&gt;tcp_exceed_flow_seg_limit 7 2 warn tcp resource packets dropped due to the limitation on tcp out-of-order queue size&lt;BR /&gt;aho_sw_offload 2015 655 info aho pktproc The total number of software aho offload&lt;BR /&gt;ctd_pscan_sw 2132 694 info ctd pktproc The total usage of software for pscan&lt;BR /&gt;ctd_pkt_slowpath 2132 694 info ctd pktproc Packets processed by slowpath&lt;BR /&gt;log_traffic_cnt 28 9 info log system Number of traffic logs&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Dec 2020 15:01:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-moves-from-active-to-discard-in-middle-of-download-once/m-p/376421#M89301</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2020-12-28T15:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: Session moves from ACTIVE to DISCARD in middle of download once zone protection enabled.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-moves-from-active-to-discard-in-middle-of-download-once/m-p/376513#M89309</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101029"&gt;@Abdul_Razaq&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Sounds like PBP is being activated. I'm guessing that if you run&amp;nbsp;&lt;EM&gt;show running resource-monitor ingress-backlogs&amp;nbsp;&lt;/EM&gt;your ISO download will be taking max buffer. You could easily test this by just disabling PBP at the zone level and trying again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 04:16:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-moves-from-active-to-discard-in-middle-of-download-once/m-p/376513#M89309</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-12-29T04:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Session moves from ACTIVE to DISCARD in middle of download once zone protection enabled.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-moves-from-active-to-discard-in-middle-of-download-once/m-p/376529#M89312</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suspected the same before, but Packet buffer protection is not enabled at the global level. As well as I disabled the same in zone level. I cannot see any threat logs for the session as well.&amp;nbsp;&lt;EM&gt;show running resource-monitor ingress-backlogs &lt;/EM&gt;was mot showing any session consuming more buffer&lt;EM&gt;.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 05:46:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-moves-from-active-to-discard-in-middle-of-download-once/m-p/376529#M89312</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2020-12-29T05:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Session moves from ACTIVE to DISCARD in middle of download once zone protection enabled.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-moves-from-active-to-discard-in-middle-of-download-once/m-p/376545#M89314</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see the below output for 'show zone-protection'. Is any of these is capable of putting a session to discard from active instead of dropping packet?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--------------&lt;/P&gt;&lt;P&gt;IPv(4/6) Filter:&lt;BR /&gt;discard-ip-spoof: enabled: yes, packet dropped: 0&lt;BR /&gt;tcp-reject-non-syn: enabled: yes, (global), packet dropped: 413&lt;BR /&gt;tcp-timestamp: enabled: yes, packets modified: 0&lt;BR /&gt;discard-tcp-syn-with-data: enabled: yes, packet dropped: 0&lt;BR /&gt;discard-tcp-synack-with-data: enabled: yes, packet dropped: 0&lt;BR /&gt;strip-tcp-fast-open-and-data: enabled: yes, packet stripped: 21&lt;BR /&gt;IPv4 packet filter:&lt;BR /&gt;discard-icmp-ping-zero-id: enabled: yes, packet dropped: 0&lt;BR /&gt;discard-icmp-frag: enabled: yes, packet dropped: 0&lt;BR /&gt;discard-icmp-large-packet: enabled: yes, packet dropped: 0&lt;BR /&gt;discard-icmp-error: enabled: yes, packet dropped: 87&lt;BR /&gt;suppress-icmp-timeexceeded: enabled: yes, packet dropped: 0&lt;BR /&gt;suppress-icmp-needfrag: enabled: yes, packet dropped: 0&lt;BR /&gt;discard-malformed-option: enabled: yes, packet dropped: 0&lt;BR /&gt;discard-overlapping-tcp-segment-mismatch: enabled: yes, packet dropped: 4&lt;BR /&gt;strict-ip-check: enabled: yes, packet dropped: 0&lt;BR /&gt;discard-tcp-split-handshake: enabled: yes, packet dropped: 0&lt;BR /&gt;IPv6 packet filter:&lt;BR /&gt;routing-header-0: enabled: yes, packet dropped: 0&lt;BR /&gt;routing-header-1: enabled: yes, packet dropped: 0&lt;BR /&gt;routing-header-4-252: enabled: yes, packet dropped: 0&lt;BR /&gt;routing-header-255: enabled: yes, packet dropped: 0&lt;BR /&gt;redirect: enabled: yes&lt;BR /&gt;dest-unreach: enabled: yes&lt;BR /&gt;pkt-too-big: enabled: yes&lt;BR /&gt;time-exceeded: enabled: yes&lt;BR /&gt;param-problem: enabled: yes&lt;BR /&gt;----------------------&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 10:43:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-moves-from-active-to-discard-in-middle-of-download-once/m-p/376545#M89314</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2020-12-29T10:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: Session moves from ACTIVE to DISCARD in middle of download once zone protection enabled.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-moves-from-active-to-discard-in-middle-of-download-once/m-p/377630#M89367</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;/community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was able to identify the cause as '&lt;SPAN&gt;discard-overlapping-tcp-segment-mismatch', it was causing the session to be in a discard state.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 14:07:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-moves-from-active-to-discard-in-middle-of-download-once/m-p/377630#M89367</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2021-01-04T14:07:01Z</dc:date>
    </item>
  </channel>
</rss>

