<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packet Flow Query - FW Inspection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-query-fw-inspection/m-p/414521#M93139</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163836"&gt;@RoutingWithJon&lt;/a&gt;&amp;nbsp;is talking about this one here:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pktflow_module_breakdown_2.jpg" style="width: 2880px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34534i88E8B128D931F9DF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pktflow_module_breakdown_2.jpg" alt="pktflow_module_breakdown_2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Available at&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com//t5/image/serverpage/image-id/12862i950F549C7D4E6309" target="_blank"&gt;https://live.paloaltonetworks.com//t5/image/serverpage/image-id/12862i950F549C7D4E6309&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Jun 2021 16:19:03 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2021-06-22T16:19:03Z</dc:date>
    <item>
      <title>Packet Flow Query - FW Inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-query-fw-inspection/m-p/414312#M93103</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been madly studying the Packet Flow Diagram that outlines the different checks/stages that a Packet goes through via a PA FW and I had a question with the 3rd check in the Ingress phase called 'FW Inspection applicable'. If Inspection is applicable then it carries into the IPSec/SSL VPN tunnel check but if Inspection is not applicable I see it go directly to the Forwarding/Egress stage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was hoping to understand what scenarios FW Inspection would be disabled thus triggering this type of path?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 12:19:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-query-fw-inspection/m-p/414312#M93103</guid>
      <dc:creator>RoutingWithJon</dc:creator>
      <dc:date>2021-06-21T12:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Flow Query - FW Inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-query-fw-inspection/m-p/414490#M93133</link>
      <description>&lt;P&gt;Hello there&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are a few diagrams and training materials that detail the Packet Flow Logic.&amp;nbsp; Can you share a screen share or snippet to ensure we are all discussing the same thing?&amp;nbsp; I am aware of the flow logic, and after a packet ingress, it could hit IPSec/SSL VPN traffic or it goes slowpath or fast path.&amp;nbsp; So either a VPN is found, or it is not, and we would continue analysis.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is where I am getting confused.&amp;nbsp; Just show/point out specifically where you have questions, and we will be glad to assist you.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 14:59:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-query-fw-inspection/m-p/414490#M93133</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-06-22T14:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Flow Query - FW Inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-query-fw-inspection/m-p/414521#M93139</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163836"&gt;@RoutingWithJon&lt;/a&gt;&amp;nbsp;is talking about this one here:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pktflow_module_breakdown_2.jpg" style="width: 2880px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34534i88E8B128D931F9DF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pktflow_module_breakdown_2.jpg" alt="pktflow_module_breakdown_2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Available at&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com//t5/image/serverpage/image-id/12862i950F549C7D4E6309" target="_blank"&gt;https://live.paloaltonetworks.com//t5/image/serverpage/image-id/12862i950F549C7D4E6309&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 16:19:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-query-fw-inspection/m-p/414521#M93139</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-06-22T16:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Flow Query - FW Inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-query-fw-inspection/m-p/414536#M93141</link>
      <description>&lt;P&gt;Thanks for that... yet I do not believe that document is 100% accurate (although it is hugely popular)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is what happens at the ingress stage:&amp;nbsp; Note, there is no bypassing slow/fastpath, as shown in the Day in a Life of a Packet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SteveCantwell_0-1624381293972.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34537i87C2934127E4835F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SteveCantwell_0-1624381293972.png" alt="SteveCantwell_0-1624381293972.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am only stating that a packet could be inbound towards the physical interface and we exam the packet to see if the DestAddr is behind the FW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is possible that arps/broadcasts would be seen by the FW, agreed, but the FW would not respond.&lt;/P&gt;
&lt;P&gt;It is possible that intrazone traffic could be ingressed, be seen by the FW, and then egress from the same interface that the packet just ingressed from, I guess, that would bypass any FW processing, because there would not be any FW processing needed.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 17:11:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-query-fw-inspection/m-p/414536#M93141</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-06-22T17:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Flow Query - FW Inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-query-fw-inspection/m-p/414555#M93146</link>
      <description>&lt;P&gt;With arp I agree (even though I don't know exactly). Maybe also routing protocol traffic is taking that path. But in both cases it wouldn't be as this path is showing. There definately is packet processing involved - simply not the same processing as "normal" traffix has to go through.&lt;/P&gt;
&lt;P&gt;"Normal" traffic which arrives at an interface and has the same egress interface also is precessed / inspected by the firewall, so - as far as I know - there is no packet in and directly out for such traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt;&amp;nbsp;or &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;could add some more information here about what traffic is meant by this direct path between ingress and egress stage?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 18:13:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-query-fw-inspection/m-p/414555#M93146</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-06-22T18:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Flow Query - FW Inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-query-fw-inspection/m-p/415235#M93235</link>
      <description>&lt;P&gt;Hey Steve, Interesting to hear your thoughts on the "Day in the life of a packet" diagram. That diagram you included looks fairly clear around the absence of the "FW Inspection" Process.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Any chance you should share that diagram? I'm keen to take a look at it as it sounds more accurate than the "Day in the life" diagram.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 10:04:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-flow-query-fw-inspection/m-p/415235#M93235</guid>
      <dc:creator>RoutingWithJon</dc:creator>
      <dc:date>2021-06-25T10:04:07Z</dc:date>
    </item>
  </channel>
</rss>

