That is a good question... I have my FW configured for Syn Cookies per PANW. RED is typically only for UDP traffic, not TCP... so perhaps there is some internal logic at play here. Best to swap it (correctly... ) to SYN Cookies. This is per PANW recommendations.
Oh, I also think.. that proper 3 way TCP handshake will be random dropped, but if some src IP did not respond and sent a 2nd SYN packet, the FW will probably DROP that... that is what I think is happening...
Anything else I can assist with?
@SteveCantwell Thanks for your effort to answer this. I will probably ask support to have a good clarification.
And regarding your SYN-Cookie suggestion, I had it enabled recently but reverted back to RED when we found during an internal scan, that because firewall is replying SYN's on servers behalf it was also giving SYN replies when the servers did not even exist. We would not like to have that when we have /24 range facing internet.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!