<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security Policies in Firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-in-firewall/m-p/396142#M91342</link>
    <description>&lt;P&gt;How to troubleshoot when we get sessions end reasons:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tcp-rst-Server&lt;/P&gt;&lt;P&gt;Tcp-rst- client&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tcp-fin&amp;nbsp;&lt;/P&gt;&lt;P&gt;n/a&lt;/P&gt;&lt;P&gt;Aged out&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know what all these but I don't know how to troubleshoot the issue and don't know where to start&amp;nbsp; troubleshoot&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone help on this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Apr 2021 21:59:57 GMT</pubDate>
    <dc:creator>Durga.Chitturi</dc:creator>
    <dc:date>2021-04-06T21:59:57Z</dc:date>
    <item>
      <title>Security Policies in Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-in-firewall/m-p/396142#M91342</link>
      <description>&lt;P&gt;How to troubleshoot when we get sessions end reasons:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tcp-rst-Server&lt;/P&gt;&lt;P&gt;Tcp-rst- client&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tcp-fin&amp;nbsp;&lt;/P&gt;&lt;P&gt;n/a&lt;/P&gt;&lt;P&gt;Aged out&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know what all these but I don't know how to troubleshoot the issue and don't know where to start&amp;nbsp; troubleshoot&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone help on this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 21:59:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-in-firewall/m-p/396142#M91342</guid>
      <dc:creator>Durga.Chitturi</dc:creator>
      <dc:date>2021-04-06T21:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policies in Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-in-firewall/m-p/396170#M91346</link>
      <description>&lt;P&gt;Well, for the TCP reset, you would start by going to the actual computer/server and do a packet capture or install Wireshark or similar software.&amp;nbsp; As you are aware, these messages do not come from the FW, but from those devices.&amp;nbsp; Start with the devices and look to see why they are sending those messages.&amp;nbsp; If Microsoft endpoints, then you may want to contact MS to support their OS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Fin does not need to be troubleshoot.&amp;nbsp; A tcp-fin means the sessions between client/server was closed properly.&lt;/P&gt;
&lt;P&gt;aged-out means that the FW held the session open for 3600 secs (if TCP) or 30 sec (if UDP) and either side (client/server) talked and so, to save resources, the session was closed.&amp;nbsp; Again, endpoint/server caused... not by the FW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;N/A means not available....&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 02:11:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-in-firewall/m-p/396170#M91346</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-04-07T02:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policies in Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-in-firewall/m-p/396380#M91367</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/177555"&gt;@Durga.Chitturi&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Just to expand on what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;&amp;nbsp;already stated, generally the only one that could point to an issue with your firewall is aged-out. If you're seeing aged-out traffic on something &lt;STRONG&gt;and it's not actually working as expected&lt;/STRONG&gt;, it could point towards a routing issue on your firewall.&lt;/P&gt;
&lt;P&gt;Just to be very clear here however, just because you are seeing aged-out responses doesn't automatically mean you have a routing issue on your firewall. aged-out is a common session end reason that doesn't mean you should be looking for a problem, it just means that if someone is reporting a problem and you are seeing aged-out in the logs that it&amp;nbsp;&lt;STRONG&gt;could&amp;nbsp;&lt;/STRONG&gt;point towards a potential routing issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 16:54:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-in-firewall/m-p/396380#M91367</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-04-07T16:54:25Z</dc:date>
    </item>
  </channel>
</rss>

