delayed traffic logging

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

delayed traffic logging

L2 Linker

Hi All,

 

Some weird stuff going on on our unit: what are the chances that the firewall logged traffic that it received hours ago?

 

In our case, the firewall logged RDP connections that occurred in the early morning. However, the target servers didn't log any login attempts at all. The alleged source IP of the connections was down during that period(although we are not ruling out that some other device "borrowed" the source IP).

 

What i also found odd is that we would normally see RDP TCP connections...the log entries in question are RDP UDP, and had "aged-out" as Session End Reason.

 

Is it possible that somehow, those connections were initiated hours earlier, then somehow our firewall logged it as having occured in the early morning?

 

 

 

2 REPLIES 2

L4 Transporter

Hi @itassetbenilde ,

 

Please verify the traffic log setting configuration, as logging is depends on security policy log setting configuration. Please refer the below kb for more details.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clt5CAC



Best Regards,
Mohammad Talib

Cyber Elite
Cyber Elite

@itassetbenilde,

RDP can utilize TCP or UDP, so what you're seeing isn't really abnormal. You can disable the ability to utilize UDP for RDP via Group Policy, in fact for performance reasons it's actually something that I recommend anyone using PAN and GlobalProtect do as I've found it provides the best performance.

As @mshekh mentioned, the first thing that you'll want to look at is the actual log file that was generated. The traffic logs by default filter on receive_time, however for RDP you really should be looking at the actual log details themselves and looking for the start time if you're trying to locate associated events on the other end. Rules by default will only have log-end enabled; what I generally recommend is that you enable log-start on RDP rules in addition to log-end so that you can easily see if a session is on-going without having to look at the session table.

  • 192 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!