<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MS RDP via GlobalProtect is not working in some cases in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ms-rdp-via-globalprotect-is-not-working-in-some-cases/m-p/533954#M3777</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/278480"&gt;@MichaelCL&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Looking only at the session end reason and detected application will not give you the full picture of what is happening.&lt;/P&gt;
&lt;P&gt;I strongly recommend to everyone when reviewing logs to always add the two columns - "Bytes Sent" and "Bytes Received"&lt;/P&gt;
&lt;P&gt;By default log view include column Bytes, which is summary of sent and received traffic. When adding those two you can quickly identify if firewall receive return traffic.&lt;/P&gt;
&lt;P&gt;In my experience incomplete is always explained with missing return traffic. Of course why there is no return could be cause by various reasons:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the provided information it looks like Location 3 either does not have correct route for the GP pool or not allowing:&lt;/P&gt;
&lt;P&gt;- Check the IPsec tunnel between Location 2 and Location 3. Is GP IP pool part of the encryption domain for IPsec phase2?&lt;/P&gt;
&lt;P&gt;- Does Location 3 have correct route for GP IP pool pointing to tunnel to location 2?&lt;/P&gt;
&lt;P&gt;- Any firewall rules in location 3? &lt;/P&gt;
&lt;P&gt;- Any NAT being applied for the traffic over the tunnels?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Mar 2023 12:48:23 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2023-03-10T12:48:23Z</dc:date>
    <item>
      <title>MS RDP via GlobalProtect is not working in some cases</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ms-rdp-via-globalprotect-is-not-working-in-some-cases/m-p/533912#M3776</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;we need to allow to access different machines via MS RDP.&lt;/P&gt;
&lt;P&gt;I write here which accesses work/not work to get an idea of our problem:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Location 1 -&amp;gt; S2S -&amp;gt; Location 2 -&amp;gt; &lt;STRONG&gt;RDP working&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Location 1 -&amp;gt; S2S -&amp;gt; Location 2 -&amp;gt; S2S -&amp;gt; Location 3 - &lt;STRONG&gt;RDP working&lt;/STRONG&gt;&lt;BR /&gt;GlobalProtect -&amp;gt; Location 1 -&amp;gt; S2S -&amp;gt; Location 2 -&amp;gt; &lt;STRONG&gt;RDP working&lt;/STRONG&gt;&lt;BR /&gt;GlobalProtect -&amp;gt; Location 1 -&amp;gt; S2S -&amp;gt; Location 2 -&amp;gt; S2S -&amp;gt; Location 3 - &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;RDP not working&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only thing we see with the connection not working is that the TCP handshake is not working. It shows Application "incomplete". &lt;STRONG&gt;The firewall policies allow the traffic.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MichaelCL_0-1678433047226.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48613i8FA7FAF12EBCC16A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MichaelCL_0-1678433047226.png" alt="MichaelCL_0-1678433047226.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Test performed:&lt;/P&gt;
&lt;P&gt;- client-side UDP disabled&lt;BR /&gt;- RDP NLA disabled&lt;BR /&gt;- Windows firewall disabled&lt;/P&gt;
&lt;P&gt;It makes no difference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe someone here has an idea what else we could check.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 07:50:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ms-rdp-via-globalprotect-is-not-working-in-some-cases/m-p/533912#M3776</guid>
      <dc:creator>MichaelCL</dc:creator>
      <dc:date>2023-03-10T07:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: MS RDP via GlobalProtect is not working in some cases</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ms-rdp-via-globalprotect-is-not-working-in-some-cases/m-p/533954#M3777</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/278480"&gt;@MichaelCL&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Looking only at the session end reason and detected application will not give you the full picture of what is happening.&lt;/P&gt;
&lt;P&gt;I strongly recommend to everyone when reviewing logs to always add the two columns - "Bytes Sent" and "Bytes Received"&lt;/P&gt;
&lt;P&gt;By default log view include column Bytes, which is summary of sent and received traffic. When adding those two you can quickly identify if firewall receive return traffic.&lt;/P&gt;
&lt;P&gt;In my experience incomplete is always explained with missing return traffic. Of course why there is no return could be cause by various reasons:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the provided information it looks like Location 3 either does not have correct route for the GP pool or not allowing:&lt;/P&gt;
&lt;P&gt;- Check the IPsec tunnel between Location 2 and Location 3. Is GP IP pool part of the encryption domain for IPsec phase2?&lt;/P&gt;
&lt;P&gt;- Does Location 3 have correct route for GP IP pool pointing to tunnel to location 2?&lt;/P&gt;
&lt;P&gt;- Any firewall rules in location 3? &lt;/P&gt;
&lt;P&gt;- Any NAT being applied for the traffic over the tunnels?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 12:48:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ms-rdp-via-globalprotect-is-not-working-in-some-cases/m-p/533954#M3777</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-03-10T12:48:23Z</dc:date>
    </item>
  </channel>
</rss>

