Hey Steven, thanks for your reply. I captured the transaction - and here is the "Follow TCP Stream" output from Wireshark of the relevant packets... POST /wp-login.php HTTP/1.1 Host: www.sant-media.co.uk Connection: keep-alive Content-Length: 110 Cache-Control: max-age=0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Origin: http://www.redacted.co.uk User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36 Content-Type: application/x-www-form-urlencoded DNT: 1 Referer: http://www.redacted.co.uk/wp-login.php Accept-Encoding: gzip,deflate,sdch Accept-Language: en-GB,en-US;q=0.8,en;q=0.6 Cookie: wordpress_test_cookie=WP+Cookie+check log=admin&pwd=xxxxxx&wp-submit=Log+In&redirect_to=http%3A%2F%2Fwww.redacted.co.uk%2Fwp-admin%2F&testcookie=1 HTTP/1.1 200 OK Server: nginx Date: Mon, 04 Aug 2014 09:36:41 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: keep-alive X-Powered-By: PHP/5.3.28 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache X-Frame-Options: SAMEORIGIN Set-Cookie: wordpress_test_cookie=WP+Cookie+check; path=/ Content-Encoding: gzip The actual Hex dump of the POST and the response (respectively) are: Wireshark has no difficulty seeing this transaction and correctly decodes the Status Code as 200 in the analysis frame at the bottom of the window. I can only assume that there is a bug in PAN OS or this is by design (i.e. unable to mix req and rsp contexts in a single signature)? https://dl.dropboxusercontent.com/u/247153/FileChute/Screenshot-20140804-1111.png
... View more