No Logs for matched rule

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

No Logs for matched rule

L0 Member

Hello everyone,

 

We are facing a strange problem with one of our PA-220.

I created a rule to allow all traffic between 2 different zones with our default log settings. The problem is that I only see a hand full hits and nothing in the traffic log.

Yes there is traffic because I see it when I start the paket capture. There is traffic in booth directions. When I disable the created policy I also see droped traffic in the "interzone-default deny" policy. After enabling the policy I didn't see the deny that traffic anymore because the rule match. I also tried the "Test Policy Match" and it shows also the created rule.

The traffic I'm searching is SIP Port 5060. The same policy match for example ICMP Ping which I see in the Traffic log!

 

Anyone an idea why I didn't see my SIP traffic but ICMP traffic?

 

Thank you

4 REPLIES 4

Cyber Elite
Cyber Elite

are your sip sessions long lived? a log is only created once a session ends so you wont see anything as long as the session is active

you can trace your sessions via `show session all filter source x destination y' (or from zoneX to zoneY)

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Cyber Elite
Cyber Elite

Hi @ARiegebauer ,

 

The solution is most likely what @reaper said.  In addition to the CLI he mentioned you can see the sessions:

 

  1. Under Monitor > Session Browser (active sessions)
  2. If you really want to see the logs in the traffic log you can check the Log at Session Start box in addition to Log at Session end for the 1 security policy rule.  This "puts extra load on the management plane's CPU" but should be fine for only 1 rule.  https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clt5CAC

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

L0 Member

I see a session in the session browser. Does it mean that there is an active session since 23:13:07 and it is still open and it should work?

 

 

Cyber Elite
Cyber Elite

Exactly!

Help the community: Like helpful comments and mark solutions.
  • 982 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!