Prisma Cloud Compute: Packet dropped by 3rd Party Firewall/Network Security Device after enabling Network Monitoring/CNNS/CNNF

Prisma Cloud Compute: Packet dropped by 3rd Party Firewall/Network Security Device after enabling Network Monitoring/CNNS/CNNF

2011
Created On 07/25/23 01:45 AM - Last Modified 05/15/24 03:01 AM


Symptom


  • The connection cannot be established after enabling Network Monitoring with a certain path or a certain remote website


Environment


  • Prisma Cloud Compute
  • Waas


Cause


  • Based on the design of WAAS, we will insert an additional "TCP Option(flag)" at SYN packet. For example:
Screenshot 2023-07-25 at 9.38.46 AM.png


Resolution


Please choose one of below options:
  • Disable Network Monitoring on Prisma Cloud Compute: Console > Radars > Settings > (Disable Container network monitoring & Host network monitoring)
  • Check with the 3rd Party Vendor to check which security feature would block the unknown TCP Options:
    • Check Point: Disable SecureXL
    • Sonicwall: Enable Fix/ignore malformed TCP headers and disable Enable TCP sequence number randomization


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kIN6CAM&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail