<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN SSL traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15310#M11250</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the GUI, Virtual Router --&amp;gt; Static Routes&lt;/P&gt;&lt;P&gt;Destination 10.2.0.0/16 and the tunnel interface, metric 10, next hop none.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traceroute times out without a list of hops.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Jul 2013 20:59:40 GMT</pubDate>
    <dc:creator>God</dc:creator>
    <dc:date>2013-07-12T20:59:40Z</dc:date>
    <item>
      <title>VPN SSL traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15302#M11242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a SSL VPN setup through the Global Protect Gateway. The SSL-VPN tunnel is in its own zone and I have an any - any rule for this zone to my trusted zone. I am able to pass traffic to one interface in a trusted zone but I am not able to pass traffic to another interface in the trusted zone. What am I missing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jul 2013 19:32:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15302#M11242</guid>
      <dc:creator>God</dc:creator>
      <dc:date>2013-07-12T19:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15303#M11243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;are you sure you configured an unused pool for vpn clients ?&lt;/P&gt;&lt;P&gt;can you share interface ip's of Trust and VR table &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jul 2013 19:40:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15303#M11243</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-12T19:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15304#M11244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are using an unused pool for vpn clients. interface eth1/2, eth1/2.161, and eth1/4 are all in the trust network. I can get to eth2 but not the others.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; id&amp;nbsp;&amp;nbsp;&amp;nbsp; vr&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; address&lt;/P&gt;&lt;P&gt;&amp;nbsp; - ---------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --&amp;nbsp;&amp;nbsp;&amp;nbsp; --&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -------&lt;/P&gt;&lt;P&gt;&amp;nbsp; * tunnel&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp;&amp;nbsp;&amp;nbsp; default&lt;/P&gt;&lt;P&gt;&amp;nbsp; * ethernet1/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16&amp;nbsp;&amp;nbsp;&amp;nbsp; default&amp;nbsp; 199.96.116.59/28&lt;/P&gt;&lt;P&gt;&amp;nbsp; * ethernet1/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 17&amp;nbsp;&amp;nbsp;&amp;nbsp; default&amp;nbsp; 192.168.11.4/24&lt;/P&gt;&lt;P&gt;&amp;nbsp; * ethernet1/4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 19&amp;nbsp;&amp;nbsp;&amp;nbsp; default&amp;nbsp; 10.2.100.255/16&lt;/P&gt;&lt;P&gt;&amp;nbsp; * ethernet1/2.161&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 259&amp;nbsp;&amp;nbsp; default&amp;nbsp; 192.168.161.6/24&lt;/P&gt;&lt;P&gt;&amp;nbsp; * default/i3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 61441 default&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jul 2013 19:53:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15304#M11244</guid>
      <dc:creator>God</dc:creator>
      <dc:date>2013-07-12T19:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15305#M11245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so you mean although you have interface management profile with ping(if not do that for troubleshoot)&lt;/P&gt;&lt;P&gt;you can not ping any except eth1/2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jul 2013 20:02:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15305#M11245</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-12T20:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15306#M11246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, We are getting somewhere. I can ping eth1/2 and eth1/4 but I cannot ping anything else on the eth1/4 network but I can on the eth1/2 network. Seems like a routing issue somewhere but I don't know where. I added 10.2.0.0/16 to the access route list in the GlobalProtect Gateway client config. I also added 10.2.0.0/16 to the static route table of the tunnel interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jul 2013 20:12:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15306#M11246</guid>
      <dc:creator>God</dc:creator>
      <dc:date>2013-07-12T20:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15307#M11247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what is the vpn pool ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jul 2013 20:15:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15307#M11247</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-12T20:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15308#M11248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The VPN pool is: 192.168.251.250-192.168.251.252. (I am keeping it small for now).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jul 2013 20:18:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15308#M11248</guid>
      <dc:creator>God</dc:creator>
      <dc:date>2013-07-12T20:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15309#M11249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"I also added 10.2.0.0/16 to the static route table of the tunnel interface." what do you mean with that&lt;/P&gt;&lt;P&gt;look for traceroute on the vpn client&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jul 2013 20:23:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15309#M11249</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-12T20:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15310#M11250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the GUI, Virtual Router --&amp;gt; Static Routes&lt;/P&gt;&lt;P&gt;Destination 10.2.0.0/16 and the tunnel interface, metric 10, next hop none.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traceroute times out without a list of hops.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jul 2013 20:59:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15310#M11250</guid>
      <dc:creator>God</dc:creator>
      <dc:date>2013-07-12T20:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15311#M11251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Problem resolved. Using multiple gateways outbound to the internet.&amp;nbsp; Thank you for your responses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jul 2013 21:31:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-traffic/m-p/15311#M11251</guid>
      <dc:creator>God</dc:creator>
      <dc:date>2013-07-12T21:31:06Z</dc:date>
    </item>
  </channel>
</rss>

