paloaltonetworks:configuration:zone_protection
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| paloaltonetworks:configuration:zone_protection [2020/05/28 15:51] – bstafford | paloaltonetworks:configuration:zone_protection [2022/11/23 12:49] (current) – external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== Zone Protection ====== | ====== Zone Protection ====== | ||
| + | Remember, you should not have TCP-SYN enabled on both Zone Protection and DoS policies at the same time. | ||
| + | ===== Logging ===== | ||
| + | To enable the additional logging, run this operational command: | ||
| + | |||
| + | < | ||
| + | More data [[https:// | ||
| ===== Troubleshooting ===== | ===== Troubleshooting ===== | ||
| Information on troubleshooting Zone Protection Profiles can be found [[paloaltonetworks: | Information on troubleshooting Zone Protection Profiles can be found [[paloaltonetworks: | ||
| + | |||
| + | While not strictly Zone Protection, Device > Setup > Session > "Drop segments with null timestamp option" | ||
| + | |||
| + | ===== Logging ===== | ||
| + | Zone Protection Profile alerts appear in the Threat Prevention logs. | ||
| ===== Zone Protection Profile Logging ===== | ===== Zone Protection Profile Logging ===== | ||
| Line 18: | Line 29: | ||
| ===== Problems with Zone Protection ===== | ===== Problems with Zone Protection ===== | ||
| - | * **Strict IP Address Check** caused problems when doing BGP and ECMP with four ISP links after a HA failover. | + | * **Strict IP Address Check** |
| * **Fragmented traffic** broke the PS3 connection to the Internet. | * **Fragmented traffic** broke the PS3 connection to the Internet. | ||
| * **ICMP Drop > Suppress ICMP TTL Expired Error** This will break the first hop of a traceroute and mark the hop as " | * **ICMP Drop > Suppress ICMP TTL Expired Error** This will break the first hop of a traceroute and mark the hop as " | ||
| Line 24: | Line 35: | ||
| * **ICMP Drop > Suppress ICMP Frag Needed** This setting will interfere with the PMTUD process performed by hosts behind the firewall. | * **ICMP Drop > Suppress ICMP Frag Needed** This setting will interfere with the PMTUD process performed by hosts behind the firewall. | ||
| ===== Best Practice ===== | ===== Best Practice ===== | ||
| + | (Remember, Spoofed IP address is based on routing tables. Strict IP Address Check is based on ingress interface - be wary with aggregate links) | ||
| + | |||
| Palo Alto Network' | Palo Alto Network' | ||
paloaltonetworks/configuration/zone_protection.1590681106.txt.gz · Last modified: (external edit)
