Packet drops with Unknown-TCP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Packet drops with Unknown-TCP

L4 Transporter

Hi Team,

Need your suggestion on below. We have created a policy to allow access to a site with URL filtering.

Created new category to the specific set of URL and then allowed the same in URL Filtering Profile and called the same in ACL. Source is set to LAN Range, Destination is set to Any, Application is set to Any, Service is set to Any, URL Category is set to the specific category, Action Allow.

So while users try to access the URL i can see Insufficient data(App) is hitting the correct rule though, and then Unknown-TCP(App) hitting the interzone-default rule and getting dropped.

As per my understanding the packets should hit the rule i created as i have allowed Any application but it is being denied by default rule. I run the packet capture i can see some of the packets are getting Reset.Not understanding what could be the reason. I went through the below KB

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC#:~:text=Unknown%2D....

Though it is relavent not giving enough info to solve this issue. Please suggest how i can proceed further.

1 REPLY 1

Cyber Elite
Cyber Elite

@Sanjay_Ramaiah ,

Something isn't matching and the interzone-default policy is likely preventing you from identifying what it is. I would create a temporary rule at the bottom of your rulebase allowing all traffic from a test machine and attempt the same process again. Ensure that you have logging fully enabled on your temporary policy and that you have a URL profile that has every single category set to at least alert.

Once they run a test and it's functional, you'll want to review ever everything hitting the temporary rule and identify the traffic that is catching that policy. In the logs you'll be able to identify something that isn't matching your URL category you've created for some reason.

  • 157 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!