<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS packets in drop stage, but i can see the same packet in transmit stage and  DNS server response as well. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-packets-in-drop-stage-but-i-can-see-the-same-packet-in/m-p/407963#M92278</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="transmit_and responce.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33965i2F1312E21484101C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="transmit_and responce.PNG" alt="transmit_and responce.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drop.PNG" style="width: 971px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33966i8DEA594DF7AEDE6E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="drop.PNG" alt="drop.PNG" /&gt;&lt;/span&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Packet diag is set accounting for the NAT as well. As mentioned, I can see the dropped NATed packet.&lt;/P&gt;&lt;P&gt;Strange thing is i can see the same packet in transmit stage to ISP ( compared dns id and source port and destination mac to confirm it is going to ISP). The public DNS is responding to the query successfully and the client is resolving the fqdn.. Just not sure why the packet in the drop stage when it actually indicates the packet went through.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was able to see some counters like 'DNS packet drops while waiting' not sure if it is related ( as I have capture filter for fw_public ip to dns, it will include other clients requests as well)&lt;/P&gt;</description>
    <pubDate>Thu, 20 May 2021 07:47:06 GMT</pubDate>
    <dc:creator>Abdul_Razaq</dc:creator>
    <dc:date>2021-05-20T07:47:06Z</dc:date>
    <item>
      <title>DNS packets in drop stage, but i can see the same packet in transmit stage and  DNS server response as well.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-packets-in-drop-stage-but-i-can-see-the-same-packet-in/m-p/407940#M92273</link>
      <description>&lt;P&gt;Hi Community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am seeing a strange behavior with DNS traffic. I tried to resolve some FQDns which work fine (those are public fqdns). But when I do the packet capture, I can see the same packets in transmit and drop stage. By comparing the tcp port and dns transaction id, i can see those packets sent only once by end machine and the same in both transmit and drop stage. Even i can see the DNS server is responding with the IP address and from end machine, the fqdn is resolved. I am trying to figure out why the packet in drop stage as it causes confition. Also this is not happening always, this is very random.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I even tried floe capture, in flow capture I cannot see the drop, in fact there is a gap in flow capture at the time of transmitting and drop time(which means i cannot see this transmit and drop in the flow capture).&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 06:27:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-packets-in-drop-stage-but-i-can-see-the-same-packet-in/m-p/407940#M92273</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2021-05-20T06:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: DNS packets in drop stage, but i can see the same packet in transmit stage and  DNS server response as well.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-packets-in-drop-stage-but-i-can-see-the-same-packet-in/m-p/407947#M92274</link>
      <description>&lt;P&gt;packet-diag logging is not stateful (it does account for NAT), so for a flow basic you need to add filters that account for both flows, and also add a filter for 'stray' packets in case the packet is discarded because the firewall can't match it to a session&lt;/P&gt;&lt;P&gt;I usually filter like this:&lt;/P&gt;&lt;P&gt;1. privsrc-pubdest-destport&lt;/P&gt;&lt;P&gt;2. pubdest -pubsrc-srcport&lt;/P&gt;&lt;P&gt;3. pubdest-privsrc-srcport&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;did you check the global counters for drops ? (retry global counters with the above filters as well, in case a packet arrives 'out of window')&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 07:26:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-packets-in-drop-stage-but-i-can-see-the-same-packet-in/m-p/407947#M92274</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-05-20T07:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: DNS packets in drop stage, but i can see the same packet in transmit stage and  DNS server response as well.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-packets-in-drop-stage-but-i-can-see-the-same-packet-in/m-p/407963#M92278</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="transmit_and responce.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33965i2F1312E21484101C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="transmit_and responce.PNG" alt="transmit_and responce.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drop.PNG" style="width: 971px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33966i8DEA594DF7AEDE6E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="drop.PNG" alt="drop.PNG" /&gt;&lt;/span&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Packet diag is set accounting for the NAT as well. As mentioned, I can see the dropped NATed packet.&lt;/P&gt;&lt;P&gt;Strange thing is i can see the same packet in transmit stage to ISP ( compared dns id and source port and destination mac to confirm it is going to ISP). The public DNS is responding to the query successfully and the client is resolving the fqdn.. Just not sure why the packet in the drop stage when it actually indicates the packet went through.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was able to see some counters like 'DNS packet drops while waiting' not sure if it is related ( as I have capture filter for fw_public ip to dns, it will include other clients requests as well)&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 07:47:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-packets-in-drop-stage-but-i-can-see-the-same-packet-in/m-p/407963#M92278</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2021-05-20T07:47:06Z</dc:date>
    </item>
  </channel>
</rss>

