<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Port 80 ,443 Incomplete in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15434#M11319</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try do add an application with port 80 and timeout values big&lt;/P&gt;&lt;P&gt;Then write app override rule for that traffic(you attached its picture) with this app. &lt;/P&gt;&lt;P&gt;Let's see if something will change when disabling inspection&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Apr 2013 20:32:27 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-04-24T20:32:27Z</dc:date>
    <item>
      <title>GlobalProtect Port 80 ,443 Incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15427#M11312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hi&lt;/P&gt;&lt;P&gt;I'm Trying to set an enviorment to my mobile users (Laptops of Salesman), I used the Globalprotect to provide a secure tunnel to the office Firewall and&lt;/P&gt;&lt;P&gt;then gave the users access to terminal server, and it worked fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;last week we installed a new SharePoint Server, I need to give the users with laptops direct access to my SharePoint Server&lt;/P&gt;&lt;P&gt;I used the same method to access the Server , meening&lt;/P&gt;&lt;P&gt;I opened Port 80 to the server through GlobalProtect access, with no luck - the monitor shows incomplete in the application section.&lt;/P&gt;&lt;P&gt;whan i open ping to the server, i recive an answer, the same issue happens with https.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now, I do have web servers in the DMZ that works fine, the only exception is that they are wide open to the world&lt;/P&gt;&lt;P&gt;and in this senario I'm tring to give access only through VPN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a panos 5.0.4 version with GlobalProtect 1.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any sugestions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 19:41:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15427#M11312</guid>
      <dc:creator>ShayBar</dc:creator>
      <dc:date>2013-04-24T19:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Port 80 ,443 Incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15428#M11313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;is this sharepoint server have both public and private ip address ?&lt;/P&gt;&lt;P&gt;or just ip with 20.x.x.x&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 19:49:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15428#M11313</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-04-24T19:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Port 80 ,443 Incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15429#M11314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;its only a private network with 20.1.1.16 address , i can ping him and remote access him through GlobalProtect client&lt;/P&gt;&lt;P&gt;but no access with http or https, the SharePoint Windows firewall is off&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 19:52:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15429#M11314</guid>
      <dc:creator>ShayBar</dc:creator>
      <dc:date>2013-04-24T19:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Port 80 ,443 Incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15430#M11315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean RDP with remote access ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 19:56:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15430#M11315</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-04-24T19:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Port 80 ,443 Incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15431#M11316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes RDP with remote access, i even accessed his harddrive throuth network access (ms-ds-smb 445) and was able to copy files from his share folders&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 19:59:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15431#M11316</guid>
      <dc:creator>ShayBar</dc:creator>
      <dc:date>2013-04-24T19:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Port 80 ,443 Incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15432#M11317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if you can do RDP than this is not a session issue.There is somehting special for sharepoint server than.&lt;/P&gt;&lt;P&gt;And incomplete means&lt;/P&gt;&lt;P&gt;1- syn ack not coming (but this fails because you can make RDP)&lt;/P&gt;&lt;P&gt;2-&amp;nbsp; 3way handshake complete but after than not any packets coming(maybe timeout)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 20:09:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15432#M11317</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-04-24T20:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Port 80 ,443 Incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15433#M11318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried to access another server with http , same problem.&lt;/P&gt;&lt;P&gt;if it's a timeout issue, what can i change to make it work?&lt;IMG alt="panos2.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6353_panos2.PNG" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 20:21:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15433#M11318</guid>
      <dc:creator>ShayBar</dc:creator>
      <dc:date>2013-04-24T20:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Port 80 ,443 Incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15434#M11319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try do add an application with port 80 and timeout values big&lt;/P&gt;&lt;P&gt;Then write app override rule for that traffic(you attached its picture) with this app. &lt;/P&gt;&lt;P&gt;Let's see if something will change when disabling inspection&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 20:32:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15434#M11319</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-04-24T20:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Port 80 ,443 Incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15435#M11320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I disabled Policy base forwarding, and it's working......&lt;/P&gt;&lt;P&gt;&lt;IMG alt="panos3.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6354_panos3.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;We configured a police to push all the youtube ,facebook ,etc through ADSL line,&lt;/P&gt;&lt;P&gt;when disabling this police the sites work with GlobalProtect access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I will try to understand what was misconfigured in the Policy base forwarding&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 20:41:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15435#M11320</guid>
      <dc:creator>ShayBar</dc:creator>
      <dc:date>2013-04-24T20:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Port 80 ,443 Incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15436#M11321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wauvvv I have not known you have pbf rules.&lt;/P&gt;&lt;P&gt;what rules of pbf you have&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 20:47:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15436#M11321</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-04-24T20:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Port 80 ,443 Incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15437#M11322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tnx 4 all the help,&lt;/P&gt;&lt;P&gt;I have found the problem&lt;/P&gt;&lt;P&gt;if yor tring to "talk" to a computer in the network that has a PBF rule redirecting it to another route - it wont work.....&lt;/P&gt;&lt;P&gt;I excluded the servers from the ip range I used to redirect to ADSL with PBF , now everything WORK!!!&lt;/P&gt;&lt;P&gt;here is the rule&lt;/P&gt;&lt;P&gt;&lt;IMG alt="adsl.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6355_adsl.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;Shay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 21:00:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15437#M11322</guid>
      <dc:creator>ShayBar</dc:creator>
      <dc:date>2013-04-24T21:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Port 80 ,443 Incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15438#M11323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's fine.&lt;/P&gt;&lt;P&gt;I'm Glad that it is solved.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 21:03:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-port-80-443-incomplete/m-p/15438#M11323</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-04-24T21:03:27Z</dc:date>
    </item>
  </channel>
</rss>

