PA sending TCP RST

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

PA sending TCP RST

Not applicable

Hey folks,

I've run into a following issue. We have a Juniper MAG box communicating with a web server and a rule in place allowing this communication (source Juniper, destination any production IP, on any port). I can also see in the traffic log that the communication is accepted. However when I did a packet capture on the FW I saw the following:

Receiving capture:

PA_recv.jpg

Transmitting capture:

PA_transm.jpg

Any idea why is this happening or what I am missing?

Thanks

1 ACCEPTED SOLUTION

Accepted Solutions

L1 Bithead

Hi Jakub

Are you running AppID version 482-2533? Try rolling back to a previous version, we had a similar issue

Cheers

View solution in original post

5 REPLIES 5

L7 Applicator

On the monitor tab, filter the threat logs and the url logs for these ip addresses and see if there are any hits.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

Hi Steven,

not for this traffic.

Then I would open a support case.  When the PA generates a reset we should have a log from the process that is creating the reset.

Here your policy, threat and url logs are clean so it would appear that this is a bug that needs to be investigated.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

L1 Bithead

Hi Jakub

Are you running AppID version 482-2533? Try rolling back to a previous version, we had a similar issue

Cheers

Hi,

Thanks. This has helped.

edit:

It's a bug - should be fixed in PanOS 6.1.3 with the AppID 482.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!