<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After connecting to Global Protect unable to use RDP in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/after-connecting-to-global-protect-unable-to-use-rdp/m-p/565269#M4616</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/265072"&gt;@Monicashree&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the NGFW captures packets in the drop stage, then it is dropping the packets. First, check the traffic logs to see the drops.&amp;nbsp; (Make sure logging is enabled for interzone default.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you don't see anything there, you may be able to see why with the last command in this article -&amp;gt; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Mon, 13 Nov 2023 00:18:37 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-11-13T00:18:37Z</dc:date>
    <item>
      <title>After connecting to Global Protect unable to use RDP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/after-connecting-to-global-protect-unable-to-use-rdp/m-p/565236#M4613</link>
      <description>&lt;P&gt;Hi Friends,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a customer who is facing issues while accessing RDP via Global Protect.&lt;/P&gt;
&lt;P&gt;User is not able to access the RDP machine after connecting to RDP. We have tried by adding the RDP ip in the include list.&lt;/P&gt;
&lt;P&gt;We have also tried by creating a specific policy for ms-rdp. It is hitting the correct rule but unable to access.&lt;/P&gt;
&lt;P&gt;For the logs we could see that application is showing as incomplete.&lt;/P&gt;
&lt;P&gt;We have tried by taking packet captures. Surprisingly we got all four packets drop, transmit, firewall and Transmit packets.&lt;/P&gt;
&lt;P&gt;I have merged all the four packets to see. I could see that TCP Port reused messages.&lt;/P&gt;
&lt;P&gt;Kindly help where and what could be done to solve this.&lt;/P&gt;
&lt;P&gt;I am attaching the screenshot for your reference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Monica.&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot (124).png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55110i8869F47D5DAC8B8C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot (124).png" alt="Screenshot (124).png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2023 05:13:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/after-connecting-to-global-protect-unable-to-use-rdp/m-p/565236#M4613</guid>
      <dc:creator>Monicashree</dc:creator>
      <dc:date>2023-11-11T05:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: After connecting to Global Protect unable to use RDP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/after-connecting-to-global-protect-unable-to-use-rdp/m-p/565250#M4615</link>
      <description>&lt;P&gt;At initial look I would say routing issue.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2023 22:24:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/after-connecting-to-global-protect-unable-to-use-rdp/m-p/565250#M4615</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-11T22:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: After connecting to Global Protect unable to use RDP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/after-connecting-to-global-protect-unable-to-use-rdp/m-p/565269#M4616</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/265072"&gt;@Monicashree&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the NGFW captures packets in the drop stage, then it is dropping the packets. First, check the traffic logs to see the drops.&amp;nbsp; (Make sure logging is enabled for interzone default.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you don't see anything there, you may be able to see why with the last command in this article -&amp;gt; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 00:18:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/after-connecting-to-global-protect-unable-to-use-rdp/m-p/565269#M4616</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-11-13T00:18:37Z</dc:date>
    </item>
    <item>
      <title>Re: After connecting to Global Protect unable to use RDP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/after-connecting-to-global-protect-unable-to-use-rdp/m-p/565274#M4618</link>
      <description>&lt;P&gt;Screenshot seems to show:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Packet 1 - SYN arrives to Palo&lt;BR /&gt;Packet 2 - SYN goes through firewall stage in Palo&lt;BR /&gt;Packet 3 - SYN is sent out from Palo&lt;BR /&gt;Packet 4 - SYN ACK arrives back to Palo&lt;BR /&gt;Packet 5 - SYN ACK goes through firewall stage in Palo&lt;BR /&gt;Packet 6 - ??? Either captured from "transmit" stage or "drop" stage&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If packet 6 is captured from "transmit" stage then&amp;nbsp;you need to figure out if 172.16.10.70 receives it and why it does not send ACK back.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Most likely it is captured from "drop" stage.&lt;/P&gt;
&lt;P&gt;This means that either routing back to 172.16.10.70 is broken, return traffic is routed to different zone compared where it came from or if some zone protection settings is dropping it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I suggest to add 2 packet capture filters one where source is&amp;nbsp;172.16.10.70 and destination&amp;nbsp;192.168.45.31 and second filter line with source/destination IPs flipped around.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Run command:&lt;/P&gt;
&lt;P&gt;&amp;gt; show counter global filter delta yes packet-filter yes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Generate some traffic and then run same command again.&lt;/P&gt;
&lt;P&gt;This shows reason why packets are dropped.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 02:19:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/after-connecting-to-global-protect-unable-to-use-rdp/m-p/565274#M4618</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-13T02:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: After connecting to Global Protect unable to use RDP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/after-connecting-to-global-protect-unable-to-use-rdp/m-p/565359#M4620</link>
      <description>&lt;P&gt;I notice that the packet is not reaching its destination from the basic flow. Is it possible for you to capture the same packets on the DC firewall? I think that firewall is causing the same issue that you are seeing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So the route cause analysis is that this is a down stream network issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 11:48:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/after-connecting-to-global-protect-unable-to-use-rdp/m-p/565359#M4620</guid>
      <dc:creator>AbdulAzim</dc:creator>
      <dc:date>2023-11-13T11:48:42Z</dc:date>
    </item>
  </channel>
</rss>

