<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect Not able to access external application in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-able-to-access-external-application/m-p/553796#M112579</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi, I have a web application hosted by OCI,&amp;nbsp; from on Prem I and my users can access the application without any problems.&amp;nbsp; However when connecting to our PA setup through global protect we cant access the application.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a very similar setup for some AWS hosted web applications and these work without any issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas as I am stumped by this one.&amp;nbsp; I am fairly new to PA so please be gentle with your replys!!&amp;nbsp; Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 15 Aug 2023 14:45:12 GMT</pubDate>
    <dc:creator>paul-b</dc:creator>
    <dc:date>2023-08-15T14:45:12Z</dc:date>
    <item>
      <title>Global Protect Not able to access external application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-able-to-access-external-application/m-p/553796#M112579</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi, I have a web application hosted by OCI,&amp;nbsp; from on Prem I and my users can access the application without any problems.&amp;nbsp; However when connecting to our PA setup through global protect we cant access the application.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a very similar setup for some AWS hosted web applications and these work without any issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas as I am stumped by this one.&amp;nbsp; I am fairly new to PA so please be gentle with your replys!!&amp;nbsp; Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 14:45:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-able-to-access-external-application/m-p/553796#M112579</guid>
      <dc:creator>paul-b</dc:creator>
      <dc:date>2023-08-15T14:45:12Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Not able to access external application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-able-to-access-external-application/m-p/553913#M112590</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/309534"&gt;@paul-b&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Welcome to LiveCommunity! Thanks for reaching out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How are you currently routing your GP traffic? Is all traffic being routed through GP or are you using a split tunnel for external connections?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are routing all traffic through GP, do you currently have security policies in place to allow traffic from your GP zone to Untrust zone with the required Apps/Services? If so, in the monitor tab, what do the traffic logs look like? Are you able to see the GP IPs as the source and external APP in OCI as the destination?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 07:16:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-able-to-access-external-application/m-p/553913#M112590</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2023-08-16T07:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Not able to access external application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-able-to-access-external-application/m-p/553988#M112610</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/309534"&gt;@paul-b&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I'm gonna echo a lot of what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;already mentioned and add one of my own.&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Check how you're routing traffic through GlobalProtect. If you aren't routing everything through the tunnel, you may be sending you're hosted application traffic out locally which could be causing access issues for your hosted application.&lt;/LI&gt;
&lt;LI&gt;Check that your security policy is actually allowing the traffic for GlobalProtect users. Remember that denied traffic isn't logged by default, so you may have to temporarily enable interzone-default logging.&lt;/LI&gt;
&lt;LI&gt;Check to see how you're NAT'ing traffic from GlobalProtect and if you're potentially using a different public IP than what you use for users working on-prem. If the hosted application is heavily restricted (or you have a static NAT statement to force on-prem from a single IP that you haven't included GlobalProtect in) you would be getting access issues.&lt;/LI&gt;
&lt;LI&gt;Check to see if it's an MTU issue. If everything else checks out, the one thing that&amp;nbsp;&lt;EM&gt;has&amp;nbsp;&lt;/EM&gt;to be different is the max MTU size. The tunnel has an overhead and by default the tunnel-mtu is going to be set to 1400.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 16 Aug 2023 13:29:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-able-to-access-external-application/m-p/553988#M112610</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-08-16T13:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Not able to access external application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-able-to-access-external-application/m-p/560051#M113558</link>
      <description>&lt;P&gt;I use Global Protect for home workers to connect to th ecorp network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, I have a tunnel setup for AWS, which all works fine, from within the office and when using global protect from home.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However the OCI connection only works from within the office, as soon as i try from global protect it does not respond.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So there is something in the way that the AWS ipsec tunnel is working than the OCI tunnel is working.&amp;nbsp; &amp;nbsp;I cant see any difference but clearly I am missing something could it be routing or policy, I am completely stumped.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 15:10:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-able-to-access-external-application/m-p/560051#M113558</guid>
      <dc:creator>paul-b</dc:creator>
      <dc:date>2023-09-29T15:10:41Z</dc:date>
    </item>
  </channel>
</rss>

