I want to know where to find the allowed traffic drop and to correct it

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

I want to know where to find the allowed traffic drop and to correct it

L1 Bithead

Hi friend,

 

I already done the security policy, but it seem there are some traffic drop. Where can i find it out for the traffic drop?

Thank you.

2 accepted solutions

Accepted Solutions

L3 Networker

Hi there,

Assuming you have configured your deny/drop security policy rules to log traffic, you will see these log entries in the Monitor -> Traffic tab on the webGUI.

 

cheers,

Seb.

View solution in original post

L4 Transporter

@SebRupik is completely correct, the session end will tell you what the reason was, look out for session timeout as this can indicate that there was no reply from the destination side, but I would also do a packet capture on the ingress and egress interfaces, this can be found in monitor>packet capture, I would be tempted, in the first instance, to do a capture on the receive on the ingress and a capture on the transmit stage on the egress, that way you will be able to confirm that traffic is leaving the firewall. 

PCCSA PCNSA PCNSE PCSAE
Mode44 LTD Palo Alto Consultants

View solution in original post

5 REPLIES 5

L3 Networker

Hi there,

Assuming you have configured your deny/drop security policy rules to log traffic, you will see these log entries in the Monitor -> Traffic tab on the webGUI.

 

cheers,

Seb.

Thanks,

And if i want to know is there any packet drop for Traffic that i allow.
Can i see it?

If the traffic is being permitted but not received by the client then it could be that the FW marking the flow as 'Threat'.

On the Monitor -> Traffic tab, filter out the flows your are interested in, what entries do you have in the 'Session End' column?

 

cheers,

Seb.

L4 Transporter

@SebRupik is completely correct, the session end will tell you what the reason was, look out for session timeout as this can indicate that there was no reply from the destination side, but I would also do a packet capture on the ingress and egress interfaces, this can be found in monitor>packet capture, I would be tempted, in the first instance, to do a capture on the receive on the ingress and a capture on the transmit stage on the egress, that way you will be able to confirm that traffic is leaving the firewall. 

PCCSA PCNSA PCNSE PCSAE
Mode44 LTD Palo Alto Consultants

L1 Bithead

Thank you guy.

  • 2 accepted solutions
  • 5171 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!