<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow only global protect from trust to untrust. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allow-only-global-protect-from-trust-to-untrust/m-p/591311#M117753</link>
    <description>&lt;P&gt;Hi, thank you for replying to my post. So, I checked in the monitoring log and found that there's an MS Office application that needs to be allowed for login. I've already restricted it so that only the Global Protect application is permitted.&lt;/P&gt;</description>
    <pubDate>Sun, 07 Jul 2024 12:29:31 GMT</pubDate>
    <dc:creator>ariiero</dc:creator>
    <dc:date>2024-07-07T12:29:31Z</dc:date>
    <item>
      <title>Allow only global protect from trust to untrust.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-only-global-protect-from-trust-to-untrust/m-p/589815#M117533</link>
      <description>&lt;DIV class="flex flex-grow flex-col max-w-full"&gt;
&lt;DIV class="min-h-[20px] text-message flex flex-col items-start whitespace-pre-wrap break-words [.text-message+&amp;amp;]:mt-5 juice:w-full juice:items-end overflow-x-auto gap-2" dir="auto" data-message-author-role="assistant" data-message-id="746c466d-b931-4236-9a07-5e3d8a9fcd87"&gt;
&lt;DIV class="flex w-full flex-col gap-1 juice:empty:hidden juice:first:pt-[3px]"&gt;
&lt;DIV class="markdown prose w-full break-words dark:prose-invert light"&gt;
&lt;P&gt;Hi Everyone Greeting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need to allow only the GlobalProtect application from the trust to the untrust zone, by allowing:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&amp;nbsp;First security policies : source trust -&amp;gt; destination untrust -&amp;gt; Application DNS -&amp;gt; Allow&lt;/LI&gt;
&lt;LI&gt;Second security policies : source trust -&amp;gt; destination untrust -&amp;gt; The Paloalto-shared-services application, by opening TCP port 443 and UDP port 4501&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;However, it sometimes works and sometimes does not. Can someone help me?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Arie&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 18 Jun 2024 14:30:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-only-global-protect-from-trust-to-untrust/m-p/589815#M117533</guid>
      <dc:creator>ariiero</dc:creator>
      <dc:date>2024-06-18T14:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: Allow only global protect from trust to untrust.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-only-global-protect-from-trust-to-untrust/m-p/590012#M117566</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/376740489"&gt;@ariiero&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your security policies look pretty standard. The first place I would check is the monitor tab and view the traffic logs for the various connections going through your policy 1 and policy 2 (traffic being allowed? bytes sent and bytes returned? session end reason, application registering? etc.)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would also compare the advanced details logs of the connections that work and the connections that aren't working.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2024 17:12:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-only-global-protect-from-trust-to-untrust/m-p/590012#M117566</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-06-20T17:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: Allow only global protect from trust to untrust.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-only-global-protect-from-trust-to-untrust/m-p/591311#M117753</link>
      <description>&lt;P&gt;Hi, thank you for replying to my post. So, I checked in the monitoring log and found that there's an MS Office application that needs to be allowed for login. I've already restricted it so that only the Global Protect application is permitted.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jul 2024 12:29:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-only-global-protect-from-trust-to-untrust/m-p/591311#M117753</guid>
      <dc:creator>ariiero</dc:creator>
      <dc:date>2024-07-07T12:29:31Z</dc:date>
    </item>
  </channel>
</rss>

