DNS aged-out, tcp-rst-from-client, and tcp-fin

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

DNS aged-out, tcp-rst-from-client, and tcp-fin

L0 Member

I'm pretty new to Palo Alto products, and I just inherited one.  I was having some small issues getting to a site (just a minute or two delay).  When I went to the Monitor tab, and saw something that looked a little strange, but could be completely normal.

 

DNSage-outEdit.png

 

 

There are a lot of these every second.  Is it normal for a DNS to go to aged-out or tcp-rst-from-client, or tcp-fin after it returns the information requested?  Or is this a sign of something else being wrong.

 

2 REPLIES 2

Cyber Elite
Cyber Elite

Hi John

 

In the case of DNS this is normal as DNS is a UDP protocol which has no means of terminating a session other than no longer transferring packets (where TCP can send FIN or RST packets)

 

The rst-from-client packets may be your client timing out and deciding to give up gracefully by sending a rst to the server

Since there is a delay I'd recommend setting up a packetcapture to see if you can detect where packets may be getting lost or where a delay me be introduced

please take a look at this article to get you started: Getting Started: Packet Capture

 

 

For future reference: you posted your question in the community feedback forum. You'll reach a much wider audience (all of our other customers, partners, Palo Alto Networks staff etc), if you post questions in the general forum 🙂

 

general forum.png

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Just to let you know that I moved this article to the General Topics area.

LIVEcommunity team member
Stay Secure,
Joe
Don't forget to Like items if a post is helpful to you!
  • 5717 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!