<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PenTest GlobalProtect Subnet in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/544011#M4071</link>
    <description>&lt;P&gt;Do you have a rule on the Azure NGFW that allows traffic to GP for S2S VPN?&lt;/P&gt;
&lt;P&gt;- On-prem NGFW tunnels with Azure Native VPN Gateway. I enabled the intra and interzone loggs – this should capture anything not matched right?&lt;/P&gt;</description>
    <pubDate>Tue, 30 May 2023 15:55:45 GMT</pubDate>
    <dc:creator>popoymaster</dc:creator>
    <dc:date>2023-05-30T15:55:45Z</dc:date>
    <item>
      <title>PenTest GlobalProtect Subnet</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543491#M4047</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our Palo GP is setup inside Azure - and it is working and serving its purpose. GP can reach everything, but not the other way around.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We can't ping GP Clients, we can't RDP to them, any traffic destined to GP Subnet has literally no logs at all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looking for some expert advice. Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 13:26:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543491#M4047</guid>
      <dc:creator>popoymaster</dc:creator>
      <dc:date>2023-05-26T13:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: PenTest GlobalProtect Subnet</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543494#M4048</link>
      <description>&lt;P&gt;Traffic log in 10.29.2.4 firewall shows pen tester traffic going to tunnel.1 towards GlobalProtect client?&lt;/P&gt;
&lt;P&gt;If yes and you don't get any replies it means Windows firewall is dropping incoming traffic.&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 14:00:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543494#M4048</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-05-26T14:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: PenTest GlobalProtect Subnet</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543495#M4049</link>
      <description>&lt;P&gt;Traffic log in 10.29.2.4 firewall shows pen tester traffic going to tunnel.1 towards GlobalProtect client?&lt;/P&gt;
&lt;P&gt;If yes and you don't get any replies it means Windows firewall of the GlobalProtect client is dropping incoming traffic.&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 14:04:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543495#M4049</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-05-26T14:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: PenTest GlobalProtect Subnet</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543671#M4052</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/294368"&gt;@popoymaster&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have a security rule allowing traffic to your GP zone?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you do not see logs, it may be because you have not enabled logging on your interzone-default rule which drops all traffic not matched by any rules.&amp;nbsp; Click on the interzone-default rule; click Override; select Log at Session End; and click Ok.&amp;nbsp; Commit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sat, 27 May 2023 17:47:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543671#M4052</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-05-27T17:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: PenTest GlobalProtect Subnet</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543685#M4054</link>
      <description>&lt;P&gt;This actually works! Traffic is dropped by the interzone-default rule.&lt;BR /&gt;&lt;BR /&gt;Ok, so we have 2 palo alto firewalls;&lt;BR /&gt;&lt;BR /&gt;1. On-prem with site-to-site tunnel to azure native vpn gateway&lt;BR /&gt;2. The other one is dedicated for GP.&lt;BR /&gt;&lt;BR /&gt;Now, GP palo can reach the GP clients, thanks to you i allow interzone comms.&lt;BR /&gt;&lt;BR /&gt;Problem now is, our on prem palo can reach all the interfaces Eth1 Untrust, Eth2 Trust of the GP FW but not the GP subnets. And this time, no logs at all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additionally, GP clients can reach the on-prem palo and subnets inside it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="753161C0-0B58-4469-A21D-770DC8C3E448.jpeg" style="width: 2208px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50412i92A502FB425440BE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="753161C0-0B58-4469-A21D-770DC8C3E448.jpeg" alt="753161C0-0B58-4469-A21D-770DC8C3E448.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Sun, 28 May 2023 05:18:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543685#M4054</guid>
      <dc:creator>popoymaster</dc:creator>
      <dc:date>2023-05-28T05:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: PenTest GlobalProtect Subnet</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543692#M4055</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/294368"&gt;@popoymaster&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Do you have a route on the on-prem NGFW to the GP subnet that points to the tunnel?&lt;/LI&gt;
&lt;LI&gt;Do you have a rule on the on-prem NGFW that allows traffic to the GP subnet?&lt;/LI&gt;
&lt;LI&gt;Do you have a rule on the Azure NGFW that allows traffic to GP for S2S VPN?&lt;/LI&gt;
&lt;LI&gt;What do the traffic logs show on the on-prem and Azure NGFWs for the pings that fail?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sun, 28 May 2023 13:38:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543692#M4055</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-05-28T13:38:28Z</dc:date>
    </item>
    <item>
      <title>Re: PenTest GlobalProtect Subnet</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543985#M4063</link>
      <description>Do you have a route on the on-prem NGFW to the GP subnet that points to the tunnel?&lt;BR /&gt;- YES! Azure NGFW's management and GP subnets are pointing to tunnel.&lt;BR /&gt;[cid:image001.png@01D992EA.9FD5C5D0]&lt;BR /&gt;&lt;BR /&gt;Do you have a rule on the on-prem NGFW that allows traffic to the GP subnet?&lt;BR /&gt; - YES! Bi-directional.&lt;BR /&gt;&lt;BR /&gt;Do you have a rule on the Azure NGFW that allows traffic to GP for S2S VPN?&lt;BR /&gt;- On-prem NGFW tunnels with Azure Native VPN Gateway. I enabled the intra and interzone loggs - this should capture anything not matched right?&lt;BR /&gt;&lt;BR /&gt;What do the traffic logs show on the on-prem and Azure NGFWs for the pings that fail?&lt;BR /&gt; - I can see the traffic going out of On-prem NGFW but not arriving at Azure NGFW. Ping test to interfaces logged and worked but not to the GP Subnet.&lt;BR /&gt;[cid:image002.png@01D992EA.9FD5C5D0]&lt;BR /&gt;&lt;BR /&gt;Azure NGFW only sees traffic going to the interfaces, but not destined to GP subnet.&lt;BR /&gt;[cid:image003.png@01D992EA.9FD5C5D0]&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 30 May 2023 15:34:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543985#M4063</guid>
      <dc:creator>popoymaster</dc:creator>
      <dc:date>2023-05-30T15:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: PenTest GlobalProtect Subnet</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543989#M4064</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have a route on the on-prem NGFW to the GP subnet that points to the tunnel?&lt;/P&gt;
&lt;P&gt;- YES! Azure NGFW’s management and GP subnets are pointing to tunnel.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="popoymaster_0-1685461049236.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50449i3E5F62FEE385C291/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="popoymaster_0-1685461049236.png" alt="popoymaster_0-1685461049236.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have a rule on the on-prem NGFW that allows traffic to the GP subnet?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- YES! Bi-directional.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have a rule on the Azure NGFW that allows traffic to GP for S2S VPN?&lt;/P&gt;
&lt;P&gt;- On-prem NGFW tunnels with Azure Native VPN Gateway. I enabled the intra and interzone loggs – this should capture anything not matched right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do the traffic logs show on the on-prem and Azure NGFWs for the pings that fail?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- I can see the traffic going out of On-prem NGFW but not arriving at Azure NGFW. Ping test to interfaces logged and worked but not to the GP Subnet.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="popoymaster_1-1685461049263.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50451iA38FBFC1E6CAB4E3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="popoymaster_1-1685461049263.png" alt="popoymaster_1-1685461049263.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Azure NGFW only sees traffic going to the interfaces, but not destined to GP subnet.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="popoymaster_2-1685461049282.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50450i5B0555C5E138D020/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="popoymaster_2-1685461049282.png" alt="popoymaster_2-1685461049282.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 15:37:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543989#M4064</guid>
      <dc:creator>popoymaster</dc:creator>
      <dc:date>2023-05-30T15:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: PenTest GlobalProtect Subnet</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543992#M4065</link>
      <description>&lt;P&gt;PING from Azure NGFW works but not from the Onprem NGFW.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="popoymaster_0-1685461687706.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50452i10F8EAEEE999A9EC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="popoymaster_0-1685461687706.png" alt="popoymaster_0-1685461687706.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 15:48:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543992#M4065</guid>
      <dc:creator>popoymaster</dc:creator>
      <dc:date>2023-05-30T15:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: PenTest GlobalProtect Subnet</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543997#M4066</link>
      <description>&lt;P&gt;Hi Tom,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have a route on the on-prem NGFW to the GP subnet that points to the tunnel?&lt;/P&gt;
&lt;P&gt;- YES! Azure NGFW’s management and GP subnets are pointing to tunnel.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="popoymaster_0-1685461793684.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50453iDC84D525E7CB6C4F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="popoymaster_0-1685461793684.png" alt="popoymaster_0-1685461793684.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have a rule on the on-prem NGFW that allows traffic to the GP subnet?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- YES! Bi-directional.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have a rule on the Azure NGFW that allows traffic to GP for S2S VPN?&lt;/P&gt;
&lt;P&gt;- On-prem NGFW tunnels with Azure Native VPN Gateway. I enabled the intra and interzone loggs – this should capture anything not matched right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do the traffic logs show on the on-prem and Azure NGFWs for the pings that fail?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- I can see the traffic going out of On-prem NGFW but not arriving at Azure NGFW. Ping test to interfaces logged and worked but not to the GP Subnet.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="popoymaster_1-1685461793717.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50455i011147365306E86C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="popoymaster_1-1685461793717.png" alt="popoymaster_1-1685461793717.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Azure NGFW only sees traffic going to the interfaces, but not destined to GP subnet.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="popoymaster_2-1685461793752.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50454iA21B59A960DD1100/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="popoymaster_2-1685461793752.png" alt="popoymaster_2-1685461793752.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 15:50:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/543997#M4066</guid>
      <dc:creator>popoymaster</dc:creator>
      <dc:date>2023-05-30T15:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: PenTest GlobalProtect Subnet</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/544001#M4067</link>
      <description>&lt;P&gt;Hi Tom,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have a route on the on-prem NGFW to the GP subnet that points to the tunnel?&lt;/P&gt;
&lt;P&gt;- YES! Azure NGFW’s management and GP subnets are pointing to tunnel.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="popoymaster_0-1685461865605.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50456iFE04045C3445DBBA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="popoymaster_0-1685461865605.png" alt="popoymaster_0-1685461865605.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have a rule on the on-prem NGFW that allows traffic to the GP subnet?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- YES! Bi-directional.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have a rule on the Azure NGFW that allows traffic to GP for S2S VPN?&lt;/P&gt;
&lt;P&gt;- On-prem NGFW tunnels with Azure Native VPN Gateway. I enabled the intra and interzone loggs – this should capture anything not matched right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do the traffic logs show on the on-prem and Azure NGFWs for the pings that fail?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- I can see the traffic going out of On-prem NGFW but not arriving at Azure NGFW. Ping test to interfaces logged and worked but not to the GP Subnet.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="popoymaster_1-1685461865637.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50458i9A8C11B2D1864961/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="popoymaster_1-1685461865637.png" alt="popoymaster_1-1685461865637.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Azure NGFW only sees traffic going to the interfaces, but not destined to GP subnet.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="popoymaster_2-1685461865686.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50457i82E56ECA17719760/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="popoymaster_2-1685461865686.png" alt="popoymaster_2-1685461865686.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 15:51:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/544001#M4067</guid>
      <dc:creator>popoymaster</dc:creator>
      <dc:date>2023-05-30T15:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: PenTest GlobalProtect Subnet</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/544006#M4068</link>
      <description>&lt;P&gt;Do you have a route on the on-prem NGFW to the GP subnet that points to the tunnel?&lt;/P&gt;
&lt;P&gt;- YES! Azure NGFW’s management and GP subnets are pointing to tunnel.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="popoymaster_3-1685462038760.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50459i96006FB7AA1CAE78/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="popoymaster_3-1685462038760.png" alt="popoymaster_3-1685462038760.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have a rule on the on-prem NGFW that allows traffic to the GP subnet?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- YES! Bi-directional.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have a rule on the Azure NGFW that allows traffic to GP for S2S VPN?&lt;/P&gt;
&lt;P&gt;- On-prem NGFW tunnels with Azure Native VPN Gateway. I enabled the intra and interzone loggs – this should capture anything not matched right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do the traffic logs show on the on-prem and Azure NGFWs for the pings that fail?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- I can see the traffic going out of On-prem NGFW but not arriving at Azure NGFW. Ping test to interfaces logged and worked but not to the GP Subnet.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="popoymaster_4-1685462038786.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50461i16CFAD0C14AC486D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="popoymaster_4-1685462038786.png" alt="popoymaster_4-1685462038786.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Azure NGFW only sees traffic going to the interfaces, but not destined to GP subnet.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="popoymaster_5-1685462038808.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50460i51FFB3FE419C6D8C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="popoymaster_5-1685462038808.png" alt="popoymaster_5-1685462038808.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 15:54:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/544006#M4068</guid>
      <dc:creator>popoymaster</dc:creator>
      <dc:date>2023-05-30T15:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: PenTest GlobalProtect Subnet</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/544009#M4069</link>
      <description>&lt;P&gt;Do you have a route on the on-prem NGFW to the GP subnet that points to the tunnel?&lt;/P&gt;
&lt;P&gt;- YES! Azure NGFW’s management and GP subnets are pointing to tunnel.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="popoymaster_0-1685462115164.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50462i179B35438DA19B45/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="popoymaster_0-1685462115164.png" alt="popoymaster_0-1685462115164.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 15:55:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/544009#M4069</guid>
      <dc:creator>popoymaster</dc:creator>
      <dc:date>2023-05-30T15:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: PenTest GlobalProtect Subnet</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/544010#M4070</link>
      <description>&lt;P&gt;Do you have a rule on the on-prem NGFW that allows traffic to the GP subnet?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- YES! Bi-directional.&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 15:55:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/544010#M4070</guid>
      <dc:creator>popoymaster</dc:creator>
      <dc:date>2023-05-30T15:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: PenTest GlobalProtect Subnet</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/544011#M4071</link>
      <description>&lt;P&gt;Do you have a rule on the Azure NGFW that allows traffic to GP for S2S VPN?&lt;/P&gt;
&lt;P&gt;- On-prem NGFW tunnels with Azure Native VPN Gateway. I enabled the intra and interzone loggs – this should capture anything not matched right?&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 15:55:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/544011#M4071</guid>
      <dc:creator>popoymaster</dc:creator>
      <dc:date>2023-05-30T15:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: PenTest GlobalProtect Subnet</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/544014#M4072</link>
      <description>&lt;P&gt;What do the traffic logs show on the on-prem and Azure NGFWs for the pings that fail?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- I can see the traffic going out of On-prem NGFW but not arriving at Azure NGFW. Ping test to interfaces logged and worked but not to the GP Subnet.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="popoymaster_1-1685462159594.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50464i592BD1B097F9D1A2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="popoymaster_1-1685462159594.png" alt="popoymaster_1-1685462159594.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Azure NGFW only sees traffic going to the interfaces, but not destined to GP subnet.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="popoymaster_2-1685462159623.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50463i5C97087B5D74AF24/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="popoymaster_2-1685462159623.png" alt="popoymaster_2-1685462159623.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 15:56:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pentest-globalprotect-subnet/m-p/544014#M4072</guid>
      <dc:creator>popoymaster</dc:creator>
      <dc:date>2023-05-30T15:56:07Z</dc:date>
    </item>
  </channel>
</rss>

