- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-05-2019 06:47 AM
I'm very new to PAN firewalls and are still learning as I go along, they've only been in a month or so and the only rule is currently set any any from the trust to untrust zones and vice versa.
We've got a couple of issues around some connections that traverse our 5250's (LAN to WAN and vice versa) but from the 5250's perspective its not seeing any traffic in the logs for the addresses in question, no deny drops allows nothing.
When we've done a packet capture from the servers on either end of the connection it shows the traffic leaving but its never seen on the 5250's. We've checked the routing and everything else in between but we've found nothing wrong.
Zone protection profile has been disabled.
Is there anything else that I can check to see if for one reason or another the 5250's are doing something they shouldn't to the traffic?
Any help would be much appreciated?
Thanks
Jon
07-05-2019 07:38 AM
Ensure that you've actually enabled logging on the interzone-default policy and ensure you've checked interface counters for any dropped packets. Did you do a PCAP on the actual firewall yet or not? That would be my next stop if everything else checks out so you can see that it's at least hitting the firewall and being processed correctly.
07-05-2019 10:09 AM
Hello,
Also check the logs to see where and why you are getting dropped. If you have Application set for any and Service set to Application-default, then the PAN may identify some apps over non-standard ports and block the traffic.
However as you mentioned your config, I would highly recommend that you not use any/any from untrust to trust, unless you have another firewall in between. Also there is free training online to help you along.
https://paloaltonetworks.csod.com
As always you can post in here and we'll help out the best we can :).
Cheers!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!