<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why traffic log shows that traffic match allow policy but the result was reset by default deny policy? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/why-traffic-log-shows-that-traffic-match-allow-policy-but-the/m-p/388605#M90522</link>
    <description>&lt;P&gt;Does anyone have following experience and could give me some idea to fix this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot ~&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found sometimes the traffic log shows that traffic match allow policy but the result was reset by default deny policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a policy for allow some users to access TCP 58975.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="圖片1.png" style="width: 698px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30121i1C632F437199BD38/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="圖片1.png" alt="圖片1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I checked traffic log and I found traffic be reset by interzone-default during 2/11 08:07:16 to 2/12 08:02:31&lt;/P&gt;&lt;P&gt;I already checked threat log and there is no log about drop or reset for this traffic.&lt;/P&gt;&lt;P&gt;And I checked configuration log and there is no change record.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="圖片2.png" style="width: 698px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30122i5171F623009A6E27/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="圖片2.png" alt="圖片2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="圖片3.png" style="width: 698px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30123iE6607C18E115AD36/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="圖片3.png" alt="圖片3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a clue, this PA-3020 update apps-content everyday at 8:00.&lt;/P&gt;&lt;P&gt;Traffic begin reset at&amp;nbsp;2/11 08:07:16 that just update to&amp;nbsp;8374-6528.&lt;/P&gt;&lt;P&gt;And after 24 hours traffic be allow at&amp;nbsp;2/12 08:02:31 that also just update to 8375-6541.&lt;/P&gt;&lt;P&gt;But I'm not sure is it can cause this problem because I think the policy allow any application so it should be allow if traffic match L3 to L4 rule. And I'm not sure that always happen after apps-content update in&amp;nbsp;the first few times.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have open a case but support says they need capture packets or they doesn't have&amp;nbsp;enough data to analysis this issue.&lt;/P&gt;&lt;P&gt;That is problem because I can not reproduce this&amp;nbsp;situation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA-3020&lt;/P&gt;&lt;P&gt;PAN-OS :&amp;nbsp;&lt;SPAN&gt;8.1.16&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Mar 2021 15:25:10 GMT</pubDate>
    <dc:creator>neilwu</dc:creator>
    <dc:date>2021-03-02T15:25:10Z</dc:date>
    <item>
      <title>Why traffic log shows that traffic match allow policy but the result was reset by default deny policy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-traffic-log-shows-that-traffic-match-allow-policy-but-the/m-p/388605#M90522</link>
      <description>&lt;P&gt;Does anyone have following experience and could give me some idea to fix this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot ~&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found sometimes the traffic log shows that traffic match allow policy but the result was reset by default deny policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a policy for allow some users to access TCP 58975.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="圖片1.png" style="width: 698px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30121i1C632F437199BD38/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="圖片1.png" alt="圖片1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I checked traffic log and I found traffic be reset by interzone-default during 2/11 08:07:16 to 2/12 08:02:31&lt;/P&gt;&lt;P&gt;I already checked threat log and there is no log about drop or reset for this traffic.&lt;/P&gt;&lt;P&gt;And I checked configuration log and there is no change record.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="圖片2.png" style="width: 698px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30122i5171F623009A6E27/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="圖片2.png" alt="圖片2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="圖片3.png" style="width: 698px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30123iE6607C18E115AD36/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="圖片3.png" alt="圖片3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a clue, this PA-3020 update apps-content everyday at 8:00.&lt;/P&gt;&lt;P&gt;Traffic begin reset at&amp;nbsp;2/11 08:07:16 that just update to&amp;nbsp;8374-6528.&lt;/P&gt;&lt;P&gt;And after 24 hours traffic be allow at&amp;nbsp;2/12 08:02:31 that also just update to 8375-6541.&lt;/P&gt;&lt;P&gt;But I'm not sure is it can cause this problem because I think the policy allow any application so it should be allow if traffic match L3 to L4 rule. And I'm not sure that always happen after apps-content update in&amp;nbsp;the first few times.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have open a case but support says they need capture packets or they doesn't have&amp;nbsp;enough data to analysis this issue.&lt;/P&gt;&lt;P&gt;That is problem because I can not reproduce this&amp;nbsp;situation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA-3020&lt;/P&gt;&lt;P&gt;PAN-OS :&amp;nbsp;&lt;SPAN&gt;8.1.16&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 15:25:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-traffic-log-shows-that-traffic-match-allow-policy-but-the/m-p/388605#M90522</guid>
      <dc:creator>neilwu</dc:creator>
      <dc:date>2021-03-02T15:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why traffic log shows that traffic match allow policy but the result was reset by default deny policy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-traffic-log-shows-that-traffic-match-allow-policy-but-the/m-p/389127#M90599</link>
      <description>&lt;P&gt;This is interesting..&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see what you mean in your rules, dropped for about 24 hours.. then allowed again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Questions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Is this constant?&amp;nbsp; or was this a one time event?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Have you seen this before?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- It looks like you are just using Services and not apps? have you tried creating a custom app for this and allowing that application? Not sure that would matter.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 16:30:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-traffic-log-shows-that-traffic-match-allow-policy-but-the/m-p/389127#M90599</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2021-03-04T16:30:53Z</dc:date>
    </item>
  </channel>
</rss>

