<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: getting traffic after the interface is down in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/getting-traffic-after-the-interface-is-down/m-p/421925#M94028</link>
    <description>&lt;P&gt;Is this a single firewall or a cluster? I agree it does not make sense that there are logs when the interdace is down, but did you really rule out any possibility of this? Was the interface effectively down or did it maybe come back already or at least for a short time? Did you check what &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;asked for - check the detailed logs to see the start time? Is it possible that the start time was prior to the interface down? Was there maybe an application change in the connection - the firewall allowed a few packets, then the interface went down, then anwer packets reached the firewall wan side and them the firewall was able to see netbios so the connection was denied.&lt;/P&gt;</description>
    <pubDate>Sun, 25 Jul 2021 16:48:03 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2021-07-25T16:48:03Z</dc:date>
    <item>
      <title>getting traffic after the interface is down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-traffic-after-the-interface-is-down/m-p/421666#M93983</link>
      <description>&lt;P&gt;Hey guys hope you doing well I got a question I get a challenge one of my user getting traffic logs of NetBIOS by source Pvt IP from LAN to WAN&amp;nbsp;&lt;SPAN&gt;the device from the source side is down the 2 Pvt IP still hitting the cleanup rule. The Policy is denied by the firewall but why do the traffic logs show the two source IP which is down from that side. is that any command to clear cache or something please help. and In-application is NetBIOS-ns.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 12:48:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-traffic-after-the-interface-is-down/m-p/421666#M93983</guid>
      <dc:creator>FarhanKoujalgi</dc:creator>
      <dc:date>2021-07-23T12:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: getting traffic after the interface is down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-traffic-after-the-interface-is-down/m-p/421767#M93999</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/181525"&gt;@FarhanKoujalgi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you look at the detailed log information is the start_time actually associated with when these clients are known to be down? The logs are probably just session_end logs that are being generated after the firewall closes the session.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 18:31:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-traffic-after-the-interface-is-down/m-p/421767#M93999</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-07-23T18:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: getting traffic after the interface is down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-traffic-after-the-interface-is-down/m-p/421779#M94000</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The interface from the source side is down so why am I getting logs of netbios hitting to deny rule&amp;nbsp;&lt;/P&gt;&lt;P&gt;I check the logs time by the time it's generated in a gap of 2 5 minutes.&lt;/P&gt;&lt;P&gt;if that side of a link is down then why the firewall show us a log of netbios&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 19:23:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-traffic-after-the-interface-is-down/m-p/421779#M94000</guid>
      <dc:creator>FarhanKoujalgi</dc:creator>
      <dc:date>2021-07-23T19:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: getting traffic after the interface is down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-traffic-after-the-interface-is-down/m-p/421780#M94001</link>
      <description>&lt;P&gt;The interface from the source side is down so why am I getting logs of netbios hitting to deny rule&amp;nbsp;&lt;/P&gt;&lt;P&gt;I check the logs time by the time it's generated in a gap of 2 5 minutes.&lt;/P&gt;&lt;P&gt;if that side of a link is down then why the firewall show us a log of netbios&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 19:23:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-traffic-after-the-interface-is-down/m-p/421780#M94001</guid>
      <dc:creator>FarhanKoujalgi</dc:creator>
      <dc:date>2021-07-23T19:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: getting traffic after the interface is down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-traffic-after-the-interface-is-down/m-p/421925#M94028</link>
      <description>&lt;P&gt;Is this a single firewall or a cluster? I agree it does not make sense that there are logs when the interdace is down, but did you really rule out any possibility of this? Was the interface effectively down or did it maybe come back already or at least for a short time? Did you check what &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;asked for - check the detailed logs to see the start time? Is it possible that the start time was prior to the interface down? Was there maybe an application change in the connection - the firewall allowed a few packets, then the interface went down, then anwer packets reached the firewall wan side and them the firewall was able to see netbios so the connection was denied.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jul 2021 16:48:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-traffic-after-the-interface-is-down/m-p/421925#M94028</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-07-25T16:48:03Z</dc:date>
    </item>
  </channel>
</rss>

