<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Website blocked automatically by the firewall in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/website-blocked-automatically-by-the-firewall/m-p/1264939#M7138</link>
    <description>&lt;P&gt;ok, this session tells us the connection is being allowed, the source is being NAT'ed but the session timed out during the handshake. this could mean the remote IP is not reachable or not accepting your connections quietly (no RST or FIN but silent drop), or there could be some routing issue upstream&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have you doublechecked your source NAT IP, that it is correct and 'reachable' from the internet? are other hosts able to reach that destination IP address?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Sep 2026 07:54:19 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2026-09-24T07:54:19Z</dc:date>
    <item>
      <title>Website blocked automatically by the firewall</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/website-blocked-automatically-by-the-firewall/m-p/1264880#M7133</link>
      <description>&lt;P&gt;I am using PA-410. In our network, one specific website is blocked automatically by the firewall. I created a URL filtering, added URLs to the whitelist, and allow in the profile.&amp;nbsp;Nevertheless, users cannot access the website. When I monitor the traffic, there is&amp;nbsp;"undecided" in front of the application. End Reason is unknown. State is Active.&lt;BR /&gt;Could you please help me to solve this issue?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2026 11:08:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/website-blocked-automatically-by-the-firewall/m-p/1264880#M7133</guid>
      <dc:creator>gdu_palo</dc:creator>
      <dc:date>2026-09-23T11:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Website blocked automatically by the firewall</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/website-blocked-automatically-by-the-firewall/m-p/1264881#M7134</link>
      <description>&lt;P&gt;sounds like its getting blocked before the url even matters (else i would expect the app-id to be ssl or web-browsing.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;are you able to copy (redacted) output from the log or session state here&amp;nbsp; so we get a little more context ?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2026 11:36:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/website-blocked-automatically-by-the-firewall/m-p/1264881#M7134</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2026-09-23T11:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: Website blocked automatically by the firewall</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/website-blocked-automatically-by-the-firewall/m-p/1264884#M7135</link>
      <description>&lt;P&gt;Thank you for the quick response. I have attached the screenshot here.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2026 11:54:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/website-blocked-automatically-by-the-firewall/m-p/1264884#M7135</guid>
      <dc:creator>gdu_palo</dc:creator>
      <dc:date>2026-09-23T11:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: Website blocked automatically by the firewall</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/website-blocked-automatically-by-the-firewall/m-p/1264939#M7138</link>
      <description>&lt;P&gt;ok, this session tells us the connection is being allowed, the source is being NAT'ed but the session timed out during the handshake. this could mean the remote IP is not reachable or not accepting your connections quietly (no RST or FIN but silent drop), or there could be some routing issue upstream&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have you doublechecked your source NAT IP, that it is correct and 'reachable' from the internet? are other hosts able to reach that destination IP address?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 07:54:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/website-blocked-automatically-by-the-firewall/m-p/1264939#M7138</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2026-09-24T07:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Website blocked automatically by the firewall</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/website-blocked-automatically-by-the-firewall/m-p/1265030#M7139</link>
      <description>&lt;P&gt;Everything is OK with NAT. Other hosts are not able to reach that site either. But when I change the network, the site opens without any problem.&amp;nbsp;&lt;BR /&gt;Recently, we updated licenses. Since this process, we have been experiencing issues like this. Some low-risk websites also could not open on the network. I tried disabling all restriction rules and checking them, but nothing has changed. That's why I decided to ask for help.&lt;BR /&gt;Is it possible to bypass the firewall for a short period?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2026 10:38:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/website-blocked-automatically-by-the-firewall/m-p/1265030#M7139</guid>
      <dc:creator>gdu_palo</dc:creator>
      <dc:date>2026-09-25T10:38:21Z</dc:date>
    </item>
  </channel>
</rss>

