when i run command
show counter global filter delta yes
i see below counters incrementing need to understand which are these drops and why PA is dropping these packets?
do they impact the performance of the PA?
Those names are pretty self explaining.
Also description field helps to explain.
For example description for flow_tcp_non_syn_drop says:
Packets dropped: non-SYN TCP without session match
It means that if the first packet in a session is a TCP packet and it does not have the SYN bit set, the firewall discards it (default).
It might help you to get familiar how Palo processes packet.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The Live Community thanks you for your participation!