<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intrazone rule - Can`t ssh in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554304#M1750</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/286268"&gt;@Richard_M&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry!&amp;nbsp; I thought you were trying to SSH to the IP address on the NGFW of the safe zone.&amp;nbsp; If you are trying to SSH to the NGFW, then you need to enable it in the management profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With regard to your issue, is the traffic going through 2 interfaces in the same zone on the NGFW?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Fri, 18 Aug 2023 12:34:51 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-08-18T12:34:51Z</dc:date>
    <item>
      <title>Intrazone rule - Can`t ssh</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554128#M1739</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;We have a case where a person is trying to ssh from zone "Safe" to zone "Safe". The src (a backup orchistrator) and dst (a compute) are though in different subnet. In this case he is not able to connect, but can ping.&lt;BR /&gt;As I understand since the src and dst ip addresses are in the same zones, this traffic is going through the Intrazone rule, and should therefore be allowed?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Does anyone know if there could be anything in the fw I need to check or is the problem another place?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 08:48:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554128#M1739</guid>
      <dc:creator>Richard_M</dc:creator>
      <dc:date>2023-08-17T08:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Intrazone rule - Can`t ssh</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554151#M1740</link>
      <description>&lt;P&gt;Hello Richard_M,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you enable the logging at session end for all rules including the default rules?&lt;BR /&gt;Once it is done, you can check in the traffic logs which rule is blocking the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also I invite you to read/listen this &lt;A href="https://live.paloaltonetworks.com/t5/pancast/pancast-episode-6-understanding-firewall-security-policies/ta-p/523106" target="_self"&gt;PANCast Episode about the security rules&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 09:40:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554151#M1740</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2023-08-17T09:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: Intrazone rule - Can`t ssh</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554159#M1741</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/109098"&gt;@ozheng&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;The logging is already enabled with "Log at Session End". In the traffic logs I can't see any log of either ssh or ping, even though it is reported that the ping is going through.&lt;BR /&gt;&lt;BR /&gt;Thank you the link!&lt;BR /&gt;&lt;BR /&gt;//Richard&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 10:37:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554159#M1741</guid>
      <dc:creator>Richard_M</dc:creator>
      <dc:date>2023-08-17T10:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Intrazone rule - Can`t ssh</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554167#M1742</link>
      <description>&lt;P&gt;Hello Richard_M,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;OK, on the firewall, you set a filter on the source/destination (and return traffic).&lt;/P&gt;
&lt;P&gt;You turn the filter on.&lt;/P&gt;
&lt;P&gt;You set the capture (1 distinct name for each stage).&lt;/P&gt;
&lt;P&gt;You turn the capture on.&lt;/P&gt;
&lt;P&gt;You initiate the SSH traffic.&lt;/P&gt;
&lt;P&gt;You refresh the page on the firewall.&lt;/P&gt;
&lt;P&gt;You see if there is any file for the drop stage.&lt;/P&gt;
&lt;P&gt;If there is no receive file, the firewall is not even receiving the packet.&lt;/P&gt;
&lt;P&gt;If there is no drop file, the firewall is not dropping the packet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 12:20:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554167#M1742</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2023-08-17T12:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: Intrazone rule - Can`t ssh</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554170#M1743</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/286268"&gt;@Richard_M&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is SSH allowed in your Interface Management Profile applied to the "safe" interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 12:24:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554170#M1743</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-08-17T12:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: Intrazone rule - Can`t ssh</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554259#M1745</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/109098"&gt;@ozheng&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Didn't receive any files when I ran the packet capture while ssh was in being run. Have asked the person to look at their config again.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;//Richard&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 06:15:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554259#M1745</guid>
      <dc:creator>Richard_M</dc:creator>
      <dc:date>2023-08-18T06:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: Intrazone rule - Can`t ssh</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554262#M1746</link>
      <description>&lt;P&gt;Hello Richard_M,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If there was no file captured, then the packets were not seen on the firewall.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;By the way, don't forget to disable the capture (I forgot to mentioned in my previous message).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 06:48:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554262#M1746</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2023-08-18T06:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: Intrazone rule - Can`t ssh</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554267#M1747</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/109098"&gt;@ozheng&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thank you for your help. I read that it was needed to turn the packet capture off, so that is done &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 07:02:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554267#M1747</guid>
      <dc:creator>Richard_M</dc:creator>
      <dc:date>2023-08-18T07:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: Intrazone rule - Can`t ssh</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554269#M1749</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;It seem that Ping is the only one check for in the Interface Management Profile applied to that interface. &lt;BR /&gt;But since the ssh traffic is not droped or received when running the packet capture there should be an issue at the source side?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have to look more into if ssh should be allowed at that&amp;nbsp;Interface Management Profile.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;//Richard&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 07:17:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554269#M1749</guid>
      <dc:creator>Richard_M</dc:creator>
      <dc:date>2023-08-18T07:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Intrazone rule - Can`t ssh</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554304#M1750</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/286268"&gt;@Richard_M&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry!&amp;nbsp; I thought you were trying to SSH to the IP address on the NGFW of the safe zone.&amp;nbsp; If you are trying to SSH to the NGFW, then you need to enable it in the management profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With regard to your issue, is the traffic going through 2 interfaces in the same zone on the NGFW?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 12:34:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554304#M1750</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-08-18T12:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: Intrazone rule - Can`t ssh</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554310#M1752</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I don`t see the that specific traffic in the logs, but when I search for the src and dst ip`s one by one (with other ip addresses in the other end) in the traffic log, they both use the same interface.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;//Richard&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 13:44:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554310#M1752</guid>
      <dc:creator>Richard_M</dc:creator>
      <dc:date>2023-08-18T13:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Intrazone rule - Can`t ssh</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554312#M1753</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/286268"&gt;@Richard_M&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If both IP addresses are on the same subnet, they will talk directly to each other and not go through the NGFW.&amp;nbsp; Your SSH issue is a problem with the hosts, and not the NGFW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 14:00:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/intrazone-rule-can-t-ssh/m-p/554312#M1753</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-08-18T14:00:29Z</dc:date>
    </item>
  </channel>
</rss>

