paloaltonetworks:configuration:zone_protection
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| paloaltonetworks:configuration:zone_protection [2020/08/31 06:30] – external edit 127.0.0.1 | paloaltonetworks:configuration:zone_protection [2022/11/23 12:49] (current) – external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== Zone Protection ====== | ====== Zone Protection ====== | ||
| + | Remember, you should not have TCP-SYN enabled on both Zone Protection and DoS policies at the same time. | ||
| + | ===== Logging ===== | ||
| + | To enable the additional logging, run this operational command: | ||
| + | |||
| + | < | ||
| + | More data [[https:// | ||
| ===== Troubleshooting ===== | ===== Troubleshooting ===== | ||
| Information on troubleshooting Zone Protection Profiles can be found [[paloaltonetworks: | Information on troubleshooting Zone Protection Profiles can be found [[paloaltonetworks: | ||
| + | |||
| + | While not strictly Zone Protection, Device > Setup > Session > "Drop segments with null timestamp option" | ||
| ===== Logging ===== | ===== Logging ===== | ||
| Line 21: | Line 29: | ||
| ===== Problems with Zone Protection ===== | ===== Problems with Zone Protection ===== | ||
| - | * **Strict IP Address Check** caused problems when doing BGP and ECMP with four ISP links after a HA failover. This also causes internal hosts to not be able to ping past the ISP router when you failover from ISP1 to ISP2 using a PBF rule and this is enabled on the " | + | * **Strict IP Address Check** |
| * **Fragmented traffic** broke the PS3 connection to the Internet. | * **Fragmented traffic** broke the PS3 connection to the Internet. | ||
| * **ICMP Drop > Suppress ICMP TTL Expired Error** This will break the first hop of a traceroute and mark the hop as " | * **ICMP Drop > Suppress ICMP TTL Expired Error** This will break the first hop of a traceroute and mark the hop as " | ||
| Line 27: | Line 35: | ||
| * **ICMP Drop > Suppress ICMP Frag Needed** This setting will interfere with the PMTUD process performed by hosts behind the firewall. | * **ICMP Drop > Suppress ICMP Frag Needed** This setting will interfere with the PMTUD process performed by hosts behind the firewall. | ||
| ===== Best Practice ===== | ===== Best Practice ===== | ||
| - | (Remember, Spoofed IP address is based on routing tables. | + | (Remember, Spoofed IP address is based on routing tables. |
| Palo Alto Network' | Palo Alto Network' | ||
paloaltonetworks/configuration/zone_protection.1598855443.txt.gz · Last modified: (external edit)
