why firewall drop server hello message

Reply
L2 Linker

why firewall drop server hello message

network flow 

Lan Network -->Firewall A----->switch -->-Firewall B ---->Internet-------->Database server 

We are facing issue to connect database server from our lan network.

We took packet capture on Firewall A and firewall B .

When we initiate traffic from LAN network to database server:

Firewall B ; We are getting client Hello and server hello message on Firewall B

Firewall A: Only client hello message we got means server hello message drop by firewall A 

that why we could not able to connect with database server.

We are not using any decryption and proxy we have checked counter value also we did not get any drop.

traffic monitor logs session end reason: TCP-rst by client

@ 

 

 

 

 

 

 

Highlighted
Cyber Elite

Hi @bit_byte 

Is the assumption correct, that both firewalls are paloalto firewalls?

Anyway, when you say "Firewall A: Only client hello message we got means server hello message drop by firewall A", does this really mean the server hello is dropped by firewall A or isn't there any server hello on firewall A which would mean that the server hello is dropped by firewall B.

Highlighted
L2 Linker

@vsys_remo 

Yes, both firewalls are PA.

We have already bypass firewall A and we did the test from the switch then we can able to connect with the database server.

That means Lan pc did not get server hello that why TLS connection would not able to establish.

 

Highlighted
Cyber Elite

@bit_byte So when you did a packet capture, was the server hello in the drop stage of the capture? How does the session look like in the traffic log? Did you try a packet log debug via cli and checked the global counters when testing the connection?

Highlighted
Cyber Elite

@bit_byte 

 

Are both firewalls have same model and same PAN OS?

Check the security policy on Firewall  A and B and compare them?

Make sure they are similar in security profiles.

 

Look for threat logs in Firewall A if any traffic is denied there?

When you did packet capture do you see any drops on firewall A and B?

Use this command test security policy on both Firewall A and B

Also as Remo mentioned when you do the pcap check global counters on both Firewalls and look for drops?

 

Regards

 

 

MP
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!