01-28-2022 07:55 PM
I looked at several answers posted previously but am still unsure what is actually the end result.
I'm looking at the monitor\traffic and I can see traffic leaving the local network going to the internet that shows the action is 'allow' and but the session end reason is 'threat'. Did the traffic actually get forwarded or because the session end reason says 'threat' it may have started the packet forward but stopped it because of the threat? Ideally I'd like to have it drop that traffic rather than allow.
My hardware is a PA220 running 10.1.4.
01-28-2022 11:26 PM
Thank you for the post @rmcrae
What I assume that happened to the traffic you described, the traffic matched policy where based on 6 tuple the policy action was to allow traffic, however during further L7 inspection, threat signature triggered the session end.
If you want to see details of this session, please navigate to magnifying glass on very left, then from detailed log view get session id. From cli, you can check session details:
show session id <session id>
Kind Regards
Pavel
01-28-2022 11:26 PM
Thank you for the post @rmcrae
What I assume that happened to the traffic you described, the traffic matched policy where based on 6 tuple the policy action was to allow traffic, however during further L7 inspection, threat signature triggered the session end.
If you want to see details of this session, please navigate to magnifying glass on very left, then from detailed log view get session id. From cli, you can check session details:
show session id <session id>
Kind Regards
Pavel
01-28-2022 11:53 PM
That makes sense. Thank you. So the traffic was able to initiate the session but deeper packet inspection identified a threat and then cut it off.
01-29-2022 12:44 AM
Thank you for response @rmcrae
Yes, this is correct. This behavior is described in this KB: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HCQlCAO
Kind Regards
Pavel
08-04-2022 11:55 AM
Hello, there's a way to stop the traffic being classified and ending the session because of threat? Sometimes it does not categorized this as threat but others do.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!