<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ping log with 0 bytes sent in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ping-log-with-0-bytes-sent/m-p/413912#M93022</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is intersting suggestion, but in my humble opition (by default) ping will never take the fast path.&lt;/P&gt;&lt;P&gt;Looking at the logs it seems that any request creates new log entry, therefor create new session. Which means after FW receives the ping reply it will close the session and next request will create new session which will take again slow path.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was thinking if it could be related something with the fact that 5200 seriese and above have multiple Data Processors (DPs).&lt;/P&gt;&lt;P&gt;Another direction I was starting to think - "bytes sent", does this means that FW didn't forward this packet - it receive it, create session and log, but drops it before reaching the egress interface. But this means that we will see packet lost in the ping (I am not able to confirm this at the moment)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jun 2021 16:14:45 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2021-06-17T16:14:45Z</dc:date>
    <item>
      <title>Ping log with 0 bytes sent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-log-with-0-bytes-sent/m-p/413841#M93012</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I noticed some strange logs on one of our 5200 firewalls.&lt;/P&gt;&lt;P&gt;There is device behind the firewall that is running constant ping to google dns, traffic is allowed and working normally.&lt;/P&gt;&lt;P&gt;I noticed a some logs that &lt;U&gt;bytes sent &lt;/U&gt;is zero... I can explain bytes received with no reply, but I don't have any explanation why log entry will have bytes sent with zero:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AlexanderAstardzhiev_0-1623937334598.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34471iEA1E496C70CC8DF6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AlexanderAstardzhiev_0-1623937334598.png" alt="AlexanderAstardzhiev_0-1623937334598.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AlexanderAstardzhiev_1-1623937505092.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34472i7939BD31FD035DFA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AlexanderAstardzhiev_1-1623937505092.png" alt="AlexanderAstardzhiev_1-1623937505092.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have notice something similar?&lt;BR /&gt;Googling around I found another discussion in Reddit - &lt;A href="https://www.reddit.com/r/paloaltonetworks/comments/9pg27s/0_byte_sent_logs/" target="_blank"&gt;https://www.reddit.com/r/paloaltonetworks/comments/9pg27s/0_byte_sent_logs/&lt;/A&gt; But there they discuss TCP/UDP traffic, which I can guess can be related to predicted sessions, but I cannot explain it for ICMP traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 13:54:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-log-with-0-bytes-sent/m-p/413841#M93012</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-06-17T13:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: Ping log with 0 bytes sent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-log-with-0-bytes-sent/m-p/413846#M93013</link>
      <description>&lt;P&gt;Good Day&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I too, have similar packets with zero bytes, and others with some bytes in it.&amp;nbsp; It may have to do with how quickly the pings are going, if a session is being set up (slow path) vs fast path.&amp;nbsp; I think it OK to see these, and nothing wrong with your FW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any other questions can I assist with?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 14:12:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-log-with-0-bytes-sent/m-p/413846#M93013</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-06-17T14:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: Ping log with 0 bytes sent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ping-log-with-0-bytes-sent/m-p/413912#M93022</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is intersting suggestion, but in my humble opition (by default) ping will never take the fast path.&lt;/P&gt;&lt;P&gt;Looking at the logs it seems that any request creates new log entry, therefor create new session. Which means after FW receives the ping reply it will close the session and next request will create new session which will take again slow path.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was thinking if it could be related something with the fact that 5200 seriese and above have multiple Data Processors (DPs).&lt;/P&gt;&lt;P&gt;Another direction I was starting to think - "bytes sent", does this means that FW didn't forward this packet - it receive it, create session and log, but drops it before reaching the egress interface. But this means that we will see packet lost in the ping (I am not able to confirm this at the moment)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 16:14:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ping-log-with-0-bytes-sent/m-p/413912#M93022</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-06-17T16:14:45Z</dc:date>
    </item>
  </channel>
</rss>

