<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Able to see other peoples traffic on Comcast in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/able-to-see-other-peoples-traffic-on-comcast/m-p/423570#M94188</link>
    <description>&lt;P&gt;Is there anyone else that has Comcast Fiber circuits that is able to see other people's traffic on the public interface?&lt;/P&gt;&lt;P&gt;We have been POC'ing the DNS Security License on several FW's once we turned&amp;nbsp; it on we are seeing a large amount of DNS Tunneling alerts coming into XDR.&amp;nbsp; When we investigate they are coming from the Untrust network on the default intrazone rule.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After looking further into this it is on our sites that have Comcast Fiber circuits.&amp;nbsp; When we look at our intrazone traffic from Untrust, we are seeing traffic that is either src or dst from another Comcast network that is not on our segment.&amp;nbsp; When we filter down by interface this is only occurring on the comcast interface.&amp;nbsp; We have multiple circuits at our sites and all the other circuits are showing the expected behavior where the Untrust intrazone traffic only has our IP's in the src/dst.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Aug 2021 22:07:54 GMT</pubDate>
    <dc:creator>JasonPeterson</dc:creator>
    <dc:date>2021-08-03T22:07:54Z</dc:date>
    <item>
      <title>Able to see other peoples traffic on Comcast</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/able-to-see-other-peoples-traffic-on-comcast/m-p/423570#M94188</link>
      <description>&lt;P&gt;Is there anyone else that has Comcast Fiber circuits that is able to see other people's traffic on the public interface?&lt;/P&gt;&lt;P&gt;We have been POC'ing the DNS Security License on several FW's once we turned&amp;nbsp; it on we are seeing a large amount of DNS Tunneling alerts coming into XDR.&amp;nbsp; When we investigate they are coming from the Untrust network on the default intrazone rule.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After looking further into this it is on our sites that have Comcast Fiber circuits.&amp;nbsp; When we look at our intrazone traffic from Untrust, we are seeing traffic that is either src or dst from another Comcast network that is not on our segment.&amp;nbsp; When we filter down by interface this is only occurring on the comcast interface.&amp;nbsp; We have multiple circuits at our sites and all the other circuits are showing the expected behavior where the Untrust intrazone traffic only has our IP's in the src/dst.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 22:07:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/able-to-see-other-peoples-traffic-on-comcast/m-p/423570#M94188</guid>
      <dc:creator>JasonPeterson</dc:creator>
      <dc:date>2021-08-03T22:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: Able to see other peoples traffic on Comcast</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/able-to-see-other-peoples-traffic-on-comcast/m-p/424271#M94246</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;That is normal when on a common subnet. Its just traffic that the PAN see's as it hits its interface.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 17:13:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/able-to-see-other-peoples-traffic-on-comcast/m-p/424271#M94246</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-08-03T17:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: Able to see other peoples traffic on Comcast</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/able-to-see-other-peoples-traffic-on-comcast/m-p/424330#M94247</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really? Seeing such traffic from other customers is normal? I mean the IPs in the screenshot are not only one small subnet. It also does not look like broadcast traffic for tcp syn packets where arp entries timed out and the firewall was even seeing app-id's and not only 'incomplete'.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 20:53:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/able-to-see-other-peoples-traffic-on-comcast/m-p/424330#M94247</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-08-03T20:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: Able to see other peoples traffic on Comcast</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/able-to-see-other-peoples-traffic-on-comcast/m-p/424338#M94250</link>
      <description>&lt;P&gt;It is interesting to see the Untrust to Untrust with all of that traffic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is not the dropped traffic, which would probably be more.&amp;nbsp; But it is hard to say why you are seeing that traffic.. again due to routing.. you are seeing traffic pass thru your Untrust interface.&lt;/P&gt;
&lt;P&gt;Is that normal?&amp;nbsp; hard to say..&amp;nbsp; It all really depends.. but it sounds like dynamic routes are not as clean as they need to be.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you traceroute to those destination IP's, I wonder where they go.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 21:57:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/able-to-see-other-peoples-traffic-on-comcast/m-p/424338#M94250</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2021-08-03T21:57:40Z</dc:date>
    </item>
  </channel>
</rss>

