cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

TCP-RST-FROM -CLIENT /SERVER for a category license-expired

L1 Bithead

Hello Community.

 

I have been observing the logs coming from one server that is behind the PA-FW and while going around the VM, trying to connect to the Azure admin portal, I have observed that it has a slow connection for a 600-700Mbps. While trying to track the logs from the firewall it shows that traffic is having TCP-RST-FROM-CLIENT or TCP-RST-FROM-SERVER. And also while doing research on this I only have the answer that when you see TCP-RST meaning is that the Firewall is seeing a vulnerability on it.

Here below is a sample of the log.

azure.PNG

 

CYmeh
Who Me Too'd this topic