<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Bytes received zero for allowed udp ports in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/bytes-received-zero-for-allowed-udp-ports/m-p/413259#M93219</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In traffic allowed logs, I am seeing numbers in byte sent&amp;nbsp;however byte received is zero and connections are getting aged-out for UDP voice traffic.&lt;/P&gt;
&lt;P&gt;Can anyone know about such traffic whether it is dropping or since this&amp;nbsp; is UDP connection hence byte received is zero&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This traffic is allowing&amp;nbsp; via security policy configured for outside to inside NAT, NATED IP is of cisco meraki&amp;nbsp; server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Dhananjay Bhakte&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jun 2021 15:18:57 GMT</pubDate>
    <dc:creator>DhananjayBhakte</dc:creator>
    <dc:date>2021-06-15T15:18:57Z</dc:date>
    <item>
      <title>Bytes received zero for allowed udp ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bytes-received-zero-for-allowed-udp-ports/m-p/413259#M93219</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In traffic allowed logs, I am seeing numbers in byte sent&amp;nbsp;however byte received is zero and connections are getting aged-out for UDP voice traffic.&lt;/P&gt;
&lt;P&gt;Can anyone know about such traffic whether it is dropping or since this&amp;nbsp; is UDP connection hence byte received is zero&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This traffic is allowing&amp;nbsp; via security policy configured for outside to inside NAT, NATED IP is of cisco meraki&amp;nbsp; server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Dhananjay Bhakte&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 15:18:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bytes-received-zero-for-allowed-udp-ports/m-p/413259#M93219</guid>
      <dc:creator>DhananjayBhakte</dc:creator>
      <dc:date>2021-06-15T15:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: Bytes received zero for allowed udp ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bytes-received-zero-for-allowed-udp-ports/m-p/417030#M93502</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/129413"&gt;@DhananjayBhakte&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are just sessions that are allowed but don't have any reply. Allowed UDP sessions always have the session end reason aged out as this protocol is stateless. There isn't a packet like FIN or RST packet in TCP, so the firewall applies a timeout after a udp packet and if there is no answer or another UDP packet for the same session, this session will be removed from the session table after this timeout is reached and the session is then displayed as aged-out in the logs.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 22:24:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bytes-received-zero-for-allowed-udp-ports/m-p/417030#M93502</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-07-03T22:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: Bytes received zero for allowed udp ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bytes-received-zero-for-allowed-udp-ports/m-p/417080#M93508</link>
      <description>&lt;P&gt;Thank You Vsys_remo for reply,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes I agree with you, later I saw applications are discovering in same traffic logs, those applications was SIP&amp;nbsp; other voice related applications and these applications always runs on UDP protocol&amp;nbsp; since it is connection less protocol I was getting bytes received zero and aged-out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Dhananjay Bhakte&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 03:31:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bytes-received-zero-for-allowed-udp-ports/m-p/417080#M93508</guid>
      <dc:creator>DhananjayBhakte</dc:creator>
      <dc:date>2021-07-05T03:31:33Z</dc:date>
    </item>
  </channel>
</rss>

