- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-21-2023 04:06 AM
Hello everyone,
We are facing a strange problem with one of our PA-220.
I created a rule to allow all traffic between 2 different zones with our default log settings. The problem is that I only see a hand full hits and nothing in the traffic log.
Yes there is traffic because I see it when I start the paket capture. There is traffic in booth directions. When I disable the created policy I also see droped traffic in the "interzone-default deny" policy. After enabling the policy I didn't see the deny that traffic anymore because the rule match. I also tried the "Test Policy Match" and it shows also the created rule.
The traffic I'm searching is SIP Port 5060. The same policy match for example ICMP Ping which I see in the Traffic log!
Anyone an idea why I didn't see my SIP traffic but ICMP traffic?
Thank you
11-21-2023 04:18 AM
are your sip sessions long lived? a log is only created once a session ends so you wont see anything as long as the session is active
you can trace your sessions via `show session all filter source x destination y' (or from zoneX to zoneY)
11-21-2023 04:30 AM
Hi @ARiegebauer ,
The solution is most likely what @reaper said. In addition to the CLI he mentioned you can see the sessions:
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!