- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-30-2018 09:52 AM
I have IPTV at home.
Rule is any app and any service bit i see that video has no pic and sound.
PA logs traffic,url and threat does not show packet drop.
then i removed all the security profiles and video and sound was working.
is there any way we can check where PA is dropping the traffic for IPTV with security profile enabled?
Mike
10-01-2018 03:41 PM
Try re-enabling the profiles one at a time (start with URL filtering, commit; then add antivirus, commit...). Eventually you'll enable the profile that is causing the drops, and you should be able to find it there.
While the session is active, you can also check for sessions that match your IPTV's address (show session all match source 192.0.2.1...). If you see any sessions set to Discard state, review that session (show session id 12345678) to see the reason.
Beyond Traffic, URL, and Threat there Data Filtering logs (corresponding to File Blocking profiles) and Wildfire submissions. It may be a profile that you're using that you may not expect to drop the traffic.
09-30-2018 11:19 AM
If you are just testing stuff then add a “block all” (deny) policy that comes after all of your allow policies.
the packets will no longer be dropped but they will be blocked and logged if logging is turned on.
you can get similar diagnostics fron modifying inter/intranet polices but i prefer the block all option and just enable it when needed.
09-30-2018 11:21 AM
Oh sorry, just noticed you mentioned profiles and not policies, the previous post may be of no help.
09-30-2018 01:05 PM
yes they are security profiles not policies.
any idea where i can look for dropped traffic
10-01-2018 03:41 PM
Try re-enabling the profiles one at a time (start with URL filtering, commit; then add antivirus, commit...). Eventually you'll enable the profile that is causing the drops, and you should be able to find it there.
While the session is active, you can also check for sessions that match your IPTV's address (show session all match source 192.0.2.1...). If you see any sessions set to Discard state, review that session (show session id 12345678) to see the reason.
Beyond Traffic, URL, and Threat there Data Filtering logs (corresponding to File Blocking profiles) and Wildfire submissions. It may be a profile that you're using that you may not expect to drop the traffic.
10-02-2018 11:11 AM
Very pleasent reading Mr Gwesson.....
10-06-2018 12:10 PM
seems it was url filtering profile blocking url with ip addresses under category as unknown.
Many thanks for your answer
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!