Connection Issues between servers

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Connection Issues between servers

L1 Bithead

I'm very new to PAN firewalls and are still learning as I go along, they've only been in a month or so and the only rule is currently set any any from the trust to untrust zones and vice versa.

 

We've got a couple of issues around some connections that traverse our 5250's (LAN to WAN and vice versa) but from the 5250's perspective its not seeing any traffic in the logs for the addresses in question, no deny drops allows nothing.

 

When we've done a packet capture from the servers on either end of the connection it shows the traffic leaving but its never seen on the 5250's. We've checked the routing and everything else in between but we've found nothing wrong.

 

Zone protection profile has been disabled.

 

Is there anything else that I can check to see if for one reason or another the 5250's are doing something they shouldn't to the traffic?

 

Any help would be much appreciated?

 

Thanks

 

Jon

2 REPLIES 2

Cyber Elite
Cyber Elite

@JonHill,

Ensure that you've actually enabled logging on the interzone-default policy and ensure you've checked interface counters for any dropped packets. Did you do a PCAP on the actual firewall yet or not? That would be my next stop if everything else checks out so you can see that it's at least hitting the firewall and being processed correctly. 

Cyber Elite
Cyber Elite

Hello,

Also check the logs to see where and why you are getting dropped. If you have Application set for any and Service set to Application-default, then the PAN may identify some apps over non-standard ports and block the traffic.

 

However as you mentioned your config, I would highly recommend that you not use any/any from untrust to trust, unless you have another firewall in between. Also there is free training online to help you along.

https://paloaltonetworks.csod.com

 

As always you can post in here and we'll help out the best we can :).

 

Cheers!

  • 2290 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!