07-11-2018 12:59 PM
Having a weird issue. I installed an 820. I have internet traffic being NAT'ed. My gateway is set to the Palo. My hops to the internet look like this
Windows Box ---> Palo 820 --> Cisco Pix --> Internet Provider
Pretty basic.. I have a rule in place to allow all internal to 0.0.0.0/0 443, 80..
I can get to anything google even your tube just fine. works fast no hesitation. If I go anywhere else ( MSN, Yahoo, CNN) I get nothing. Traffic drops. I cant figure this out for the life of me.
I got a pcap going to google and going to red.com (18.104.22.168)
I can get to google but not red. I cant find a difference. Any ideas would be appreciated.
07-11-2018 02:05 PM
07-12-2018 06:54 AM
If you're able to quantify a reliable source and destination IP address for a flow that isn't working, I would recommend taking a look at the global counters. This will show you what is being blocked, whether it be due to a policy deny or MTU issues like @BPry states.
07-12-2018 10:39 AM
I did look at the counters and there were no drops. I cleared all sessions to the destination. I set up my filters to 22.214.171.124. I turned my filters on.
I ran this command to clear the counters data out. ( show counter global filter delta yes packet-filter yes severity drop ) . I turned the capture on and ran (show counter global filter delta yes packet-filter yes severity drop) again to make sure I had 0 counters...
I then iniated the connection to the above address.. I ran a local wireshark to watch the connection so I knew when it was finished. When the connection was finished I ran ( show counter global filter delta yes packet-filter yes severity drop ) again and it came back with 0 counters hit...
Looking at the PCAPS packets do not appear to be getting dropped at all.. I can zip the pcaps and upload them to my server if anyone wants to take a look at them to see if they see something I do not.
07-12-2018 10:41 AM
Thinking it might be a TCP window sizing issue but not 100%
07-12-2018 01:35 PM
Do you see the packet going to red.com hitting your PIX?
Is your DNS doing proper resolution for red.com?
Can you issue a show session all filter destination 126.96.36.199?
If you see the session please open it in the session browser and see the progress of the connectin.
Collecting this information will be a good start.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!