session end threat

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

session end threat

L4 Transporter

I had a user that was not able to connect through a mapped drive to one of our servers. Looked in the monitor and it said session end reasson threat but it didn't identify anything about the threat not cve no ID information

4 REPLIES 4

Cyber Elite
Cyber Elite

Look what the session id is.

Go to threat log and filter out this session id to find the cause.

Traffic log will not tell you the cause.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Cyber Elite
Cyber Elite

Have you tried looking in the detailed log view?

if you click the little magnifying glass next to the traffic log, it will open a detailed view. In the detailed view, at the bottom, the correlated logs for this session should also be included (threats, file blocking, ...). If you click one of these correlated logs, the detail view will switch to that log entry

 

hope this helps ! 🙂

 

2016-06-30_09-26-49.jpg

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L4 Transporter

See detailed logs and share the results

PCNSE-7, ACE-6,ACE 7 , CCNP, CCNA,CCIE(theory) , RHCE
Firewalldog dot com

Yes I also found out that there was a bug involved with one of the threats and had to make an exception

  • 2110 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!