<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: what is the meaning of &amp;quot;tcp client reset via TCP responding rst&amp;quot; output in global counter in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-meaning-of-quot-tcp-client-reset-via-tcp-responding/m-p/393072#M90974</link>
    <description>&lt;P&gt;Howdy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would interpret this to mean that the Srv side of the VPN reset the connection,and&amp;nbsp; likewise, the client side reset its side of the TCP connection.&amp;nbsp; But I think you are getting perhaps a little too deep in analysis.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the current status of your VPN?&amp;nbsp; It is up or not?&lt;/P&gt;
&lt;P&gt;If it is not up, run a "clear vpn flow", followed by "test vpn ike-sa", then "test vpn ipsec-sa", and then look at your System Logs for the output on the responses to these commands.&amp;nbsp; One side needs to initiate the vpn, and the other side needs to respond.&amp;nbsp; What do you see in your logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Presuming that ipsec and ike are allowed by a security policy, you should get some response/details about what is going on.&lt;/P&gt;
&lt;P&gt;Can you get the remote (non PAN) to initiate the VPN and you again at logs on your PANW FW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I do not personally think it is necessary to look at global counters.&amp;nbsp; If packets are going to be dropped,you would see the session in the Session Browser or the Traffic Logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 23 Mar 2021 17:12:10 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2021-03-23T17:12:10Z</dc:date>
    <item>
      <title>what is the meaning of "tcp client reset via TCP responding rst" output in global counter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-meaning-of-quot-tcp-client-reset-via-tcp-responding/m-p/393009#M90966</link>
      <description>&lt;P&gt;We are not able to connect VPN hosted in vpn_dmz zone.&lt;/P&gt;&lt;P&gt;We have deployed third party vpn in vpn_dmz zone and configured inbound nat for same.&lt;/P&gt;&lt;P&gt;Its old setup , all of sudden we are unable to connect vpn intermittently.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;did pcap for vpn public ip , showing below counter after running "show counter global filter packet-filter yes delta yes severity drop" command&lt;/P&gt;&lt;P&gt;tcp client reset via TCP responding rst:&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 15:44:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-meaning-of-quot-tcp-client-reset-via-tcp-responding/m-p/393009#M90966</guid>
      <dc:creator>Deepak_K</dc:creator>
      <dc:date>2021-03-23T15:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: what is the meaning of "tcp client reset via TCP responding rst" output in global counter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-meaning-of-quot-tcp-client-reset-via-tcp-responding/m-p/393072#M90974</link>
      <description>&lt;P&gt;Howdy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would interpret this to mean that the Srv side of the VPN reset the connection,and&amp;nbsp; likewise, the client side reset its side of the TCP connection.&amp;nbsp; But I think you are getting perhaps a little too deep in analysis.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the current status of your VPN?&amp;nbsp; It is up or not?&lt;/P&gt;
&lt;P&gt;If it is not up, run a "clear vpn flow", followed by "test vpn ike-sa", then "test vpn ipsec-sa", and then look at your System Logs for the output on the responses to these commands.&amp;nbsp; One side needs to initiate the vpn, and the other side needs to respond.&amp;nbsp; What do you see in your logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Presuming that ipsec and ike are allowed by a security policy, you should get some response/details about what is going on.&lt;/P&gt;
&lt;P&gt;Can you get the remote (non PAN) to initiate the VPN and you again at logs on your PANW FW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I do not personally think it is necessary to look at global counters.&amp;nbsp; If packets are going to be dropped,you would see the session in the Session Browser or the Traffic Logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 17:12:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-meaning-of-quot-tcp-client-reset-via-tcp-responding/m-p/393072#M90974</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-03-23T17:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: what is the meaning of "tcp client reset via TCP responding rst" output in global counter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-meaning-of-quot-tcp-client-reset-via-tcp-responding/m-p/393090#M90979</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have deployed F5 vpn , we were unable&amp;nbsp; to connect sslvpn intermittently. This issue happened first time.&lt;/P&gt;&lt;P&gt;In traffic logs , session end reason for some logs were tcp-fin and for some it was tcp-rst-frm-client&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 18:12:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-meaning-of-quot-tcp-client-reset-via-tcp-responding/m-p/393090#M90979</guid>
      <dc:creator>Deepak_K</dc:creator>
      <dc:date>2021-03-23T18:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: what is the meaning of "tcp client reset via TCP responding rst" output in global counter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-meaning-of-quot-tcp-client-reset-via-tcp-responding/m-p/393091#M90980</link>
      <description>&lt;P&gt;Hi there&lt;/P&gt;
&lt;P&gt;Again, we are getting closer.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Instead of looking at traffic logs, let's see why your VPN is not being established.&lt;/P&gt;
&lt;P&gt;Could you copy/paste the logs from your System logs, with a "subtype eq vpn"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We would normally expect Phase1 (ike) and phase2 (IPsec) to be negotiated and those negotiations logs are found in System.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tcp-fin means that the session closed by a FIN packet.&amp;nbsp; Unless you can provide visual information, it may be hard to explain what/why/how this is not working as expected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 18:28:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-meaning-of-quot-tcp-client-reset-via-tcp-responding/m-p/393091#M90980</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-03-23T18:28:06Z</dc:date>
    </item>
  </channel>
</rss>

