Session created by Syn Cookie

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L2 Linker

Session created by Syn Cookie

Hello,

 

what process and what is going on if a session (SIP) is created by "Syn Cookie" ?

Is this a valid Session, does this indicate a Problem ?

 

We configured an App-Override Policy to mitigate Problems between Phone-System and SIP ALG.

We see now all Sessions are created based on Syn Cookies.

 

René

 

Highlighted
L7 Applicator

Syn cookies are part of zone protection(not app override)

It requires the client sending the original syn to complete a little "challenge" before the firewall accepts the connection as a valid session

 

The session is not created "by" the syn cookies, the syn cookie is an added tcp check to prevent syn floods

 

In regards to sip issues, you can try disabling the ALG via the application (objects > applications) before fiddling with app override

 

Hope this helps

 

 

Tom Piens - PANgurus.com
New to PAN-OS or getting ready to take the PCNSE? check out amazon.com/dp/1789956374
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!