Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Fragmented SIP traffic gets silently dropped

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Fragmented SIP traffic gets silently dropped

L1 Bithead

Hi guys,

PA-5250, 9.1.14

Can you help me with this one, please?

PA does not like fragmented SIP INVITE packets, and we can see them in the drop queue:

d_r.PNGNo traffic, threat or URL filtering logs were created (expected, I believe). 
Why is it doing that?

Thanks,
myky

1 accepted solution

Accepted Solutions

L1 Bithead

@Raido_Rattameister correction:
SSD was replaced, and when we failback traffic, the issue returned.
Eventually, TAC confirmed that we hit the following bug:

PAN-194395
Fixed an issue where the firewall dropped all decrypted outbound (SSL Forward Proxy) HTTP/2 traffic after you upgraded to PAN-OS 9.1.14, which caused websites that used HTTP/2 to become inaccessible.

 

Same issue, old discussion:
https://www.reddit.com/r/paloaltonetworks/comments/vzrann/panos_9114_software_buffer_depletion/

The bug description is way off.

thanks, myky 

View solution in original post

7 REPLIES 7

Cyber Elite
Cyber Elite

Do you have Zone Protection applied to zone this traffic comes from?

If you add filter to "Monitor > Packet Capture" to capture traffic from 10.125.3.23 and then run following command in cli what is output? Can you identify based on couters what caused packet drops?

 

> show counter global filter delta yes packet-filter yes

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Hey @Raido_Rattameister .
Long time! 

At one point, I thought that my PA skills completely got rusty, as I believe I have checked that earlier. 
There is no ZPP applied; we got only a basic one on the untrusted zone:

MykyUk_0-1677742692924.png
thanks,

myky

Cyber Elite
Cyber Elite

Hey @MykyUk 

In this case "show counter global filter delta yes packet-filter yes" is best next step figuring out why they are dropped.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Got yah, yes will arrange testing today and update this thread. Thanks! myky

L1 Bithead

@Raido_Rattameister have you seen this before:

fr.PNG
I have a feeling it might be a TAC case.

thanks,
myky

L1 Bithead

re-run it again; PA is clearly not happy:

MykyUk_0-1677776358357.png

MykyUk_1-1677776386993.png

 

L1 Bithead

@Raido_Rattameister correction:
SSD was replaced, and when we failback traffic, the issue returned.
Eventually, TAC confirmed that we hit the following bug:

PAN-194395
Fixed an issue where the firewall dropped all decrypted outbound (SSL Forward Proxy) HTTP/2 traffic after you upgraded to PAN-OS 9.1.14, which caused websites that used HTTP/2 to become inaccessible.

 

Same issue, old discussion:
https://www.reddit.com/r/paloaltonetworks/comments/vzrann/panos_9114_software_buffer_depletion/

The bug description is way off.

thanks, myky 

  • 1 accepted solution
  • 5951 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!