- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-24-2025 05:36 AM
New to palo's. I did search the topics and didnt find anything.
Is it normal to see drop on the incoming interface to the firewall? Are the drops caused by policy?
Also, what is a drop from flow state check?
packets dropped 69498455
packets dropped by flow state check 14915663
thanks
02-24-2025 07:40 PM
Hi @D.Tamburin ,
you can use packet capture and refer the global counter to verify the drops but it's cpu intensive, ensure that you are doing it during maintenance window to avoid any unforeseen.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVOCA0
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008V0lCAE
02-25-2025 12:59 AM
Hi @D.Tamburin ,
Depending on your policy it can be expected behavior.
Are you dropping or denying traffic ?
The difference being that a drop is silent where you simply discard the packet and don't tell anyone about it. A deny on the other hand sends a notification to the sender that something happened and their packet was rejected.
Here are some posts that explain the difference between drop and deny:
https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/td-p/206863
https://live.paloaltonetworks.com/t5/community-blogs/what-a-difference-a-deny-makes/ba-p/188811
As @mshekh explained you can also check with global counters and filter on the the 'drop' action.
Here's a video explaining the process on how to go about troubleshooting silent drops on the firewall using global counters:
https://www.youtube.com/watch?v=lwYLS-dSq7I
Kind regards,
-Kim.
02-26-2025 12:14 PM
Hello,
Along with the above advise, check the Unified logs, they will tell you why the traffic was blocked. If you are not hosting any services that require access from the internet, I would put in a DENY ALL incoming policy.
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!