<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't Access Firewall while Connected to GP in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-t-access-firewall-while-connected-to-gp/m-p/594562#M5656</link>
    <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a working GP setup and our users connect to the VPN without issues. However, when trying to access the firewall via its management IP while connected to the GP, we cannot reach the firewall. Other network resources specified in the access routes are reachable. Here are the troubleshooting steps I conducted:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Ping, SSH, Access through HTTPS the MGMT IP of Firewall: &lt;STRONG&gt;Fail&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;2. I made sure that the Interface MGMT Settings have the remote user's IP is included in the permitted IP address. (HTTPS, SSH, PING also ticked)&lt;/P&gt;
&lt;P&gt;3. I made sure that the Firewall's Mgmt IP is included in the Split Tunnel - Access Route configuration in the GP Configurations (As well as in the Security Policy in Destination Addr.)&lt;/P&gt;
&lt;P&gt;4. I checked the logs, specifying the source addr and destination addr, it says "allow" but it shows Application Incomplete when accessing the GUI of Firewall.&lt;/P&gt;
&lt;P&gt;5. I made sure that there is a route from the remote user to the IP Addr of the Firewall by using "route print"&lt;/P&gt;
&lt;P&gt;6. I also tried disabling the local windows defender firewall of the remote user, disabling the IPv6 of the PANGP Network Adapter, and tried manually installing different versions of GP App. Result:&amp;nbsp;&lt;STRONG&gt;Fail&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are there any missing steps that I haven't tried yet?&lt;/P&gt;</description>
    <pubDate>Sat, 10 Aug 2024 00:27:10 GMT</pubDate>
    <dc:creator>zedexxx</dc:creator>
    <dc:date>2024-08-10T00:27:10Z</dc:date>
    <item>
      <title>Can't Access Firewall while Connected to GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-t-access-firewall-while-connected-to-gp/m-p/594562#M5656</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a working GP setup and our users connect to the VPN without issues. However, when trying to access the firewall via its management IP while connected to the GP, we cannot reach the firewall. Other network resources specified in the access routes are reachable. Here are the troubleshooting steps I conducted:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Ping, SSH, Access through HTTPS the MGMT IP of Firewall: &lt;STRONG&gt;Fail&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;2. I made sure that the Interface MGMT Settings have the remote user's IP is included in the permitted IP address. (HTTPS, SSH, PING also ticked)&lt;/P&gt;
&lt;P&gt;3. I made sure that the Firewall's Mgmt IP is included in the Split Tunnel - Access Route configuration in the GP Configurations (As well as in the Security Policy in Destination Addr.)&lt;/P&gt;
&lt;P&gt;4. I checked the logs, specifying the source addr and destination addr, it says "allow" but it shows Application Incomplete when accessing the GUI of Firewall.&lt;/P&gt;
&lt;P&gt;5. I made sure that there is a route from the remote user to the IP Addr of the Firewall by using "route print"&lt;/P&gt;
&lt;P&gt;6. I also tried disabling the local windows defender firewall of the remote user, disabling the IPv6 of the PANGP Network Adapter, and tried manually installing different versions of GP App. Result:&amp;nbsp;&lt;STRONG&gt;Fail&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are there any missing steps that I haven't tried yet?&lt;/P&gt;</description>
      <pubDate>Sat, 10 Aug 2024 00:27:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-t-access-firewall-while-connected-to-gp/m-p/594562#M5656</guid>
      <dc:creator>zedexxx</dc:creator>
      <dc:date>2024-08-10T00:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Access Firewall while Connected to GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-t-access-firewall-while-connected-to-gp/m-p/594832#M5671</link>
      <description>&lt;P&gt;Verify the routing between the your management interface subnet and the Vpn subnet. Even though the mgmt interface is part of the firewall it won't act as data interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the application shows as incomplete there is no tcp handshake between the source and destination.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Run the tcpdump in the mgmt interface and try to access to verify the traffic is reaching to the respective interface. Refer below kb for packet capture on mgmt interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 01:40:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-t-access-firewall-while-connected-to-gp/m-p/594832#M5671</guid>
      <dc:creator>Edsnow</dc:creator>
      <dc:date>2024-08-14T01:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Access Firewall while Connected to GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-t-access-firewall-while-connected-to-gp/m-p/594967#M5674</link>
      <description>&lt;P&gt;Thanks for your response,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue is now solved. Turns out that we had to adjust our pbf policies.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 01:57:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-t-access-firewall-while-connected-to-gp/m-p/594967#M5674</guid>
      <dc:creator>zedexxx</dc:creator>
      <dc:date>2024-08-15T01:57:50Z</dc:date>
    </item>
  </channel>
</rss>

