<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Web access issue in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/553206#M1695</link>
    <description>&lt;P&gt;Please update ?&lt;/P&gt;</description>
    <pubDate>Thu, 10 Aug 2023 07:43:10 GMT</pubDate>
    <dc:creator>sidhardhatech</dc:creator>
    <dc:date>2023-08-10T07:43:10Z</dc:date>
    <item>
      <title>Web access issue</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/552522#M1655</link>
      <description>&lt;P&gt;One URL does not access on browser, it shows error timed out. PA-3220 we are using.&lt;/P&gt;
&lt;P class="x_MsoNormal" aria-hidden="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;1. Create one test rule - Where you allow everything&amp;nbsp;for one source only.&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;2. Clone the test rule and deny the "Quic" application there and put it above the test rule.&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;But it is not working.&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;please help me for this&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2023 05:35:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/552522#M1655</guid>
      <dc:creator>sidhardhatech</dc:creator>
      <dc:date>2023-08-04T05:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: Web access issue</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/552720#M1674</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307553"&gt;@sidhardhatech&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Did you see the traffic is denied by the firewall due to the rule that you have created to deny the 'Quic' application? Are you able to access the URL with just the 'allow everything' rule? If the URL traffic matched to Quic application then as per your policy it will be denied hence the user won't be able to access it. You may try to narrow down it by looking into the traffic/threat/URL Filtering logs.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 03:04:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/552720#M1674</guid>
      <dc:creator>akuzhuppilly</dc:creator>
      <dc:date>2023-08-07T03:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: Web access issue</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/552757#M1676</link>
      <description>&lt;P&gt;we created test policy 1st rule in top of policy , any to any. Url is pinging but not opening in browser.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sidhardhatech_0-1691404627115.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52576iB25A6B9B5B7D8173/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="sidhardhatech_0-1691404627115.png" alt="sidhardhatech_0-1691404627115.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 10:37:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/552757#M1676</guid>
      <dc:creator>sidhardhatech</dc:creator>
      <dc:date>2023-08-07T10:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: Web access issue</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/552794#M1677</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307553"&gt;@sidhardhatech&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is the issue specific to a particular URL or affecting all traffic?&lt;/P&gt;
&lt;P&gt;Have you enabled SSL decryption in the firewall?&lt;/P&gt;
&lt;P&gt;Are you able to access the URL(s) when the firewall is bypassed?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 15:21:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/552794#M1677</guid>
      <dc:creator>akuzhuppilly</dc:creator>
      <dc:date>2023-08-07T15:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Web access issue</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/552865#M1678</link>
      <description>&lt;P&gt;sorry for late reply&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. paritcular url we facing this issue&lt;/P&gt;
&lt;P&gt;2. we are not using any decryption policy.&lt;/P&gt;
&lt;P&gt;3. we have access the url , firewall is bypassing it.&lt;/P&gt;
&lt;P&gt;The url is pinging in browser and In traffic logs it allow ping only.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please share any document or any solution for this.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 04:44:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/552865#M1678</guid>
      <dc:creator>sidhardhatech</dc:creator>
      <dc:date>2023-08-08T04:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Web access issue</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/553206#M1695</link>
      <description>&lt;P&gt;Please update ?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 07:43:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/553206#M1695</guid>
      <dc:creator>sidhardhatech</dc:creator>
      <dc:date>2023-08-10T07:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: Web access issue</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/553241#M1698</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307553"&gt;@sidhardhatech&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Sorry, didn't get you fully - What do you mean by "&lt;SPAN&gt;The url is pinging in browser and In traffic logs it allow ping only." ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would recommend you to confirm below things -&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. What are the traffic logs for the URL when accessed from the browser ? Is it matching desired security policy ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. Also if you have any security profiles attached to the security policy, kindly verify respective logs also for the web traffic.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3. Did you tried to take packet capture for the web traffic? Packet capture will give you more clarity.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 11:54:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/553241#M1698</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2023-08-10T11:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Web access issue</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/553467#M1708</link>
      <description>&lt;P&gt;while we are checking Pcap in Wireshark, we found tcp RST.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;problem is not solved&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 11:07:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/553467#M1708</guid>
      <dc:creator>sidhardhatech</dc:creator>
      <dc:date>2023-08-11T11:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: Web access issue</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/553468#M1709</link>
      <description>&lt;P&gt;while we are checking Pcap in Wireshark, we found tcp RST.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;problem is not solved&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 11:07:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/web-access-issue/m-p/553468#M1709</guid>
      <dc:creator>sidhardhatech</dc:creator>
      <dc:date>2023-08-11T11:07:48Z</dc:date>
    </item>
  </channel>
</rss>

