Seeing alot of drops on incoming interface to palo, trying to understand if this is normal.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Seeing alot of drops on incoming interface to palo, trying to understand if this is normal.

L1 Bithead

New to palo's.  I did search the topics and didnt find anything.

Is it normal to see drop on the incoming interface to the firewall?  Are the drops caused by policy?

Also, what is a drop from flow state check?

 

packets dropped 69498455
packets dropped by flow state check 14915663

 

thanks

3 REPLIES 3

L4 Transporter

Hi @D.Tamburin ,

 

you can use packet capture and refer the global counter to verify the drops but it's cpu intensive, ensure that you are doing it during maintenance window to avoid any unforeseen.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVOCA0

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008V0lCAE

 

 

 



Best Regards,
Mohammad Talib

Community Team Member

Hi @D.Tamburin ,

 

Depending on your policy it can be expected behavior.

Are you dropping or denying traffic ?

 

The difference being that a drop is silent where you simply discard the packet and don't tell anyone about it.  A deny on the other hand sends a notification to the sender that something happened and their packet was rejected.

 

Here are some posts that explain the difference between drop and deny:

https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/td-p/206863

https://live.paloaltonetworks.com/t5/community-blogs/what-a-difference-a-deny-makes/ba-p/188811

 

As @mshekh explained you can also check with global counters and filter on the the 'drop' action.

 

Here's a video explaining the process on how to go about troubleshooting silent drops on the firewall using global counters:

https://www.youtube.com/watch?v=lwYLS-dSq7I

 

Kind regards,

-Kim.

 

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Cyber Elite
Cyber Elite

Hello,

Along with the above advise, check the Unified logs, they will tell you why the traffic was blocked. If you are not hosting any services that require access from the internet, I would put in a DENY ALL incoming policy.

 

Regards,

  • 299 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!