<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTP Data - Handshake is not estabilished in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-data-handshake-is-not-estabilished/m-p/12682#M9300</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We may need to enable TCP flow-basic in order to identify the failure condition. But, would it be possible to set the repeat time &amp;gt;30 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;sec&lt;/SPAN&gt; and let us know the result. Just to ensure that previous session has been closed and the same source port is not reused.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default timeout value in a PAN firewall will be as mentioned below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Session timeout&lt;/P&gt;&lt;P&gt;&amp;nbsp; TCP default timeout:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; TCP session timeout before SYN-ACK received:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; TCP session timeout before 3-way handshaking:&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; TCP session timeout after FIN/RST:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp; UDP default timeout:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; ICMP default timeout:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;other&lt;/SPAN&gt; IP default timeout:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Captive Portal session timeout:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Session timeout in discard state:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP: 90 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;, UDP: 60 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;, other IP protocols: 60 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Oct 2014 13:00:59 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-10-28T13:00:59Z</dc:date>
    <item>
      <title>FTP Data - Handshake is not estabilished</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-data-handshake-is-not-estabilished/m-p/12679#M9297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;we are struggling with this problem.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;There is a FTP Client and an FTP Server. Both on different sites. Between them is a VPN Tunnel build with PA 3020 and PA 5020.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;FTP is working - but sometimes not!!!!!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;We found the reason for this: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;This is what I can see at client's site&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;Controlchannel (21) is UP&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;Client asks "STOR myfile.txt"&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;Datachannel Handshake starts, the last packet is WRONG!! Wrong Source AND destination Port:&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;SYN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packet&amp;nbsp; 218 Essen&amp;gt;Erfurt&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port 20 -&amp;gt; Port 6406&lt;SPAN style="color: #82c168;"&gt;8&lt;/SPAN&gt; &lt;BR /&gt;ACK&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packet&amp;nbsp; 219 Erfurt&amp;gt;Erfurt&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port 6406&lt;SPAN style="color: #82c168;"&gt;8&lt;/SPAN&gt; -&amp;gt; 20 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt; SYN ACK&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packet&amp;nbsp; 220 &lt;SPAN style="color: red;"&gt;Essen&amp;gt;Erfurt&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Port -&amp;gt; 2&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;1&lt;/STRONG&gt;&lt;/SPAN&gt; -&amp;gt; 6406&lt;STRONG style="color: red;"&gt;7&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;Is it possible Palo Alto is little bit confused? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;We are goint to trace on the server now ..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;Roman&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;&lt;IMG alt="Ashampoo_Snap_2014.10.24_14h03m16s_003_.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16639_Ashampoo_Snap_2014.10.24_14h03m16s_003_.png" style="height: 204px; width: 620px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 09:20:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-data-handshake-is-not-estabilished/m-p/12679#M9297</guid>
      <dc:creator>rkra</dc:creator>
      <dc:date>2014-10-28T09:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Data - Handshake is not estabilished</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-data-handshake-is-not-estabilished/m-p/12680#M9298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rkra,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In active mode FTP the client connects from a random unprivileged port (N &amp;gt; 1023) to the FTP server's command port, port 21. Then, the client starts listening to port N+1 and sends the FTP command PORT N+1 to the FTP server. The server will then connect back to the client's specified data port from its local data port, which is port 20. But the entire&amp;nbsp; TCP 3 way handshake will complete in port 21, hence 20 will not &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;ve&lt;/SPAN&gt; a right port during initial connection establishment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Active-FTP.jpg" class="image-0 jive-image" height="281" src="https://live.paloaltonetworks.com/legacyfs/online/16630_Active-FTP.jpg" style="height: 281.264108352145px; width: 350px;" width="350" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;From the server-side firewall's standpoint, to support active mode FTP the following communication channels need to be opened or ALG to be enabled to perform this automatically &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;Application Layer Gateway):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;FTP server's port 21 from anywhere (Client initiates connection)&lt;/P&gt;&lt;P&gt;FTP server's port 21 to ports &amp;gt; 1023 (Server responds to client's control port)&lt;/P&gt;&lt;P&gt;FTP server's port 20 to ports &amp;gt; 1023 (Server initiates data connection to client's data port)&lt;/P&gt;&lt;P&gt;FTP server's port 20 from ports &amp;gt; 1023 (Client sends ACKs to server's data port)&lt;/P&gt;&lt;P&gt;When drawn out, the connection appears as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;In step 1, the client's command port contacts the server's command port and sends the command PORT 1027. The server then sends an ACK back to the client's command port in step 2. In step 3 the server initiates a connection on its local data port to the data port the client specified earlier. Finally, the client sends an ACK back as shown in step 4.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The main problem with active mode FTP actually falls on the client side. The FTP client doesn't make the actual connection to the data port of the server--it simply tells the server what port it is listening on and the server connects back to the specified port on the client. From the client side firewall this appears to be an outside system initiating a connection to an internal client--something that is usually blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may attach PCAP on all 4 places to troubleshoot it properly. Client, PA_320, PA-5020, Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 12:25:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-data-handshake-is-not-estabilished/m-p/12680#M9298</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-10-28T12:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Data - Handshake is not estabilished</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-data-handshake-is-not-estabilished/m-p/12681#M9299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hulk,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to repeat, it works ... but not every time. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wrote a short batch to test the server, it is a small loop, this one repeats every 5 seconds.&lt;/P&gt;&lt;P&gt;The same problem is when configuring it passive OR active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the loop repeats every 60 second, it works long time well ..&lt;/P&gt;&lt;P&gt;If the loop repeats every &amp;lt;5 second, the problem appears very soon ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@echo off&lt;/P&gt;&lt;P&gt;:start&lt;/P&gt;&lt;P&gt;echo GO!&lt;/P&gt;&lt;P&gt;ftp -d -s:ftpcommands.txt&amp;gt;&amp;gt;.\ftp.log&lt;/P&gt;&lt;P&gt;timeout /T 5 /NOBREAK&lt;/P&gt;&lt;P&gt;goto start&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and now the ftp commands file:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;open 10.2.16.88&lt;/P&gt;&lt;P&gt;zgttest&lt;/P&gt;&lt;P&gt;password&lt;/P&gt;&lt;P&gt;put testfile.txt&lt;/P&gt;&lt;P&gt;bye&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 12:37:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-data-handshake-is-not-estabilished/m-p/12681#M9299</guid>
      <dc:creator>rkra</dc:creator>
      <dc:date>2014-10-28T12:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Data - Handshake is not estabilished</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-data-handshake-is-not-estabilished/m-p/12682#M9300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We may need to enable TCP flow-basic in order to identify the failure condition. But, would it be possible to set the repeat time &amp;gt;30 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;sec&lt;/SPAN&gt; and let us know the result. Just to ensure that previous session has been closed and the same source port is not reused.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default timeout value in a PAN firewall will be as mentioned below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Session timeout&lt;/P&gt;&lt;P&gt;&amp;nbsp; TCP default timeout:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3600 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; TCP session timeout before SYN-ACK received:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; TCP session timeout before 3-way handshaking:&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; TCP session timeout after FIN/RST:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp; UDP default timeout:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; ICMP default timeout:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;other&lt;/SPAN&gt; IP default timeout:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Captive Portal session timeout:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Session timeout in discard state:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP: 90 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;, UDP: 60 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;, other IP protocols: 60 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;secs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 13:00:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-data-handshake-is-not-estabilished/m-p/12682#M9300</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-10-28T13:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Data - Handshake is not estabilished</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-data-handshake-is-not-estabilished/m-p/12683#M9301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Roman,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on problem complexity, solution needs lots of live troubleshooting and live captures. Which may not be possible on forum. Still we will try to help as much as possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Follow bellow steps for failure attempt.&lt;/P&gt;&lt;P&gt;1. show counter globlal filter packet-filter yes delta yes.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;2. Lets say source is 1.1.1.1 and destination 2.2.2.2. Then put those values in filter and turn on filter and capture.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;3. Once connection is fail repeat step 1. and provide us output.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;4. Also provide us captures.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;5. Disable capture first and than filter.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Hardik Shah&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 13:36:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-data-handshake-is-not-estabilished/m-p/12683#M9301</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-28T13:36:18Z</dc:date>
    </item>
  </channel>
</rss>

