Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A security engineer is troubleshooting an issue where users are intermittently experiencing slow application performance when accessing an internal web server protected by a Palo Alto Networks firewall. The firewall logs show a high number of 'deny' actions for 'incomplete' and 'aged-out' sessions originating from the user subnet to the web server. What is the MOST likely cause of these symptoms?

  1. AAsymmetric routing is preventing the firewall from seeing both sides of the TCP handshake.
  2. BThe web server is overloaded and dropping connections.
  3. CThe security policy allowing traffic to the web server has a strict application filter.
  4. DThe firewall's session timeout for TCP is set too low for the application.
Show answer & explanation

Correct answer: A. Asymmetric routing is preventing the firewall from seeing both sides of the TCP handshake.

Incomplete and aged-out sessions often point to the firewall not seeing the full TCP handshake or subsequent traffic. Asymmetric routing is a common cause where the firewall sees the SYN but not the SYN-ACK or ACK, leading to an incomplete session that eventually ages out.

Why the other options are wrong

  • B. While an overloaded web server could cause slow performance, it typically wouldn't result in 'incomplete' or 'aged-out' sessions from the firewall's perspective if the firewall sees the full flow.
  • C. A strict application filter would likely result in 'deny' actions for the specific application, but not necessarily 'incomplete' or 'aged-out' sessions unless the filter prevents the initial handshake completion.
  • D. A low TCP session timeout would cause 'aged-out' sessions, but typically affects established sessions that go idle, not 'incomplete' sessions which point to problems with the initial handshake.

Asymmetric Routing on Firewall

Asymmetric routing occurs when traffic takes different paths for ingress and egress through a network, causing stateful firewalls to only observe one part of a connection, leading to session drops.

  • Firewalls are stateful devices.
  • Requires seeing both directions of a session (e.g., TCP 3-way handshake).
  • Can lead to 'incomplete' or 'aged-out' session logs.

Memory trick: When the conversation is broken or forgotten, routing often took a detour.

More Troubleshoot questions