<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how to allow NordVPN after done suggestion of BPA for advanced threat license in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-allow-nordvpn-after-done-suggestion-of-bpa-for-advanced/m-p/512915#M301</link>
    <description>&lt;P&gt;how to allow NordVPN after done suggestion of BPA for advanced threat license?&lt;/P&gt;
&lt;P&gt;I use flashrouter of nordvpn but page.asp can not load and even blank white page shown.&lt;/P&gt;
&lt;P&gt;I remove high risk and medium category blocking but can not solve&lt;/P&gt;
&lt;P&gt;PA220 configured C2 command and control traffic blocking but cannot find the reason of blocking and can not find which log represent the block because users are using firewall at the same.&lt;/P&gt;
&lt;P&gt;Is it possible to tag this flashrouter page.asp traffic to find the cause ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So far I added a temporary rule after the first block malicious IP list rule to allow ssl and web browsing for a workaround solution , but it need to disable and enable every time the openvpn is down. Openvpn may accumulate a over 8GB value in counter which I do not this value too large or due to the 8GB openvpn is stored so openvpn flow is down ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now I know not the C2 Block it , because after temporary rules are quic block rule and category block rule and SSH tunneling and SSH , telnet block rule. These are suspected rules&lt;/P&gt;</description>
    <pubDate>Thu, 25 Aug 2022 05:19:43 GMT</pubDate>
    <dc:creator>MavioLee</dc:creator>
    <dc:date>2022-08-25T05:19:43Z</dc:date>
    <item>
      <title>how to allow NordVPN after done suggestion of BPA for advanced threat license</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-allow-nordvpn-after-done-suggestion-of-bpa-for-advanced/m-p/512915#M301</link>
      <description>&lt;P&gt;how to allow NordVPN after done suggestion of BPA for advanced threat license?&lt;/P&gt;
&lt;P&gt;I use flashrouter of nordvpn but page.asp can not load and even blank white page shown.&lt;/P&gt;
&lt;P&gt;I remove high risk and medium category blocking but can not solve&lt;/P&gt;
&lt;P&gt;PA220 configured C2 command and control traffic blocking but cannot find the reason of blocking and can not find which log represent the block because users are using firewall at the same.&lt;/P&gt;
&lt;P&gt;Is it possible to tag this flashrouter page.asp traffic to find the cause ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So far I added a temporary rule after the first block malicious IP list rule to allow ssl and web browsing for a workaround solution , but it need to disable and enable every time the openvpn is down. Openvpn may accumulate a over 8GB value in counter which I do not this value too large or due to the 8GB openvpn is stored so openvpn flow is down ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now I know not the C2 Block it , because after temporary rules are quic block rule and category block rule and SSH tunneling and SSH , telnet block rule. These are suspected rules&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 05:19:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-allow-nordvpn-after-done-suggestion-of-bpa-for-advanced/m-p/512915#M301</guid>
      <dc:creator>MavioLee</dc:creator>
      <dc:date>2022-08-25T05:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: how to allow NordVPN after done suggestion of BPA for advanced threat license</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-allow-nordvpn-after-done-suggestion-of-bpa-for-advanced/m-p/513430#M337</link>
      <description>&lt;P&gt;Better see this article as to discover which rule blocks your traffic as you may have a rule where you have not enabled "log at the session end" and this is why to not see anything:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-palo-alto-checking-for-drops-rejects-discards/td-p/402102" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-palo-alto-checking-for-drops-rejects-discards/td-p/402102&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 09:33:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-allow-nordvpn-after-done-suggestion-of-bpa-for-advanced/m-p/513430#M337</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-08-31T09:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: how to allow NordVPN after done suggestion of BPA for advanced threat license</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-allow-nordvpn-after-done-suggestion-of-bpa-for-advanced/m-p/513434#M340</link>
      <description>&lt;P&gt;last week temporary allow rule works at rule three&amp;nbsp; after malicious ip rule block and before adult and high risk and medium risk and malware risk blocked&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;today this rule not work , page asp in flashrouter show blank page, i have to connect outside cable back to wifi router to make the page asp load first in firefox in mobile first&amp;nbsp; and then connect back to palo alto outside port to use page asp&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;last week this rule is for show openvpn location and provider dropdownlist , today application filter allow US, CA , GB with ssl and web browsing app not work to show page asp because&amp;nbsp; whole page asp is blank today.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i find log show this rule has characteristic malware and medium risk, so i suspect category rule block , but there is no exception option in category blocking and object section, it makes rules conflict. and need to enable and disable temporary rule when openvpn unstable need to press disconnect and connect again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 09:49:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-allow-nordvpn-after-done-suggestion-of-bpa-for-advanced/m-p/513434#M340</guid>
      <dc:creator>MavioLee</dc:creator>
      <dc:date>2022-08-31T09:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: how to allow NordVPN after done suggestion of BPA for advanced threat license</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-allow-nordvpn-after-done-suggestion-of-bpa-for-advanced/m-p/513708#M344</link>
      <description>&lt;P&gt;today I think that I need to buy second flash router , one is outside and one is dmz , in order to see inside openvpn traffic and at the same time , page asp not&amp;nbsp; blocked&amp;nbsp;&lt;/P&gt;
&lt;P&gt;because negate US location , other US high risk can bypass rule.&lt;/P&gt;
&lt;P&gt;though I worry flash router page asp is fake page, i check that session all show openvpn destination IP is the correct country I choose&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 09:01:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-allow-nordvpn-after-done-suggestion-of-bpa-for-advanced/m-p/513708#M344</guid>
      <dc:creator>MavioLee</dc:creator>
      <dc:date>2022-09-01T09:01:10Z</dc:date>
    </item>
  </channel>
</rss>

