<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: strange connection from PA - help me please in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17472#M12760</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi slv,&lt;/P&gt;&lt;P&gt;i don't know if this is still an issue for you if so please check the router config for NAT. Maybe this is a reason to let appear the router a source towards to PA.&lt;/P&gt;&lt;P&gt;Regards Klaus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Mar 2014 09:16:30 GMT</pubDate>
    <dc:creator>kdd</dc:creator>
    <dc:date>2014-03-10T09:16:30Z</dc:date>
    <item>
      <title>strange connection from PA - help me please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17463#M12751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today I recognised that one of my security policy droppping trafiic from IP 192.168.1.1 adddress from one of my subinterfaces to IP adersses to port 135 from other subnets.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2014-02-26_103117.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11770_2014-02-26_103117.png" style="width: 620px; height: 392px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using CaptivePortal but not in that zone where is 192.168.1.1, I'm using AD integration but with agents not on 192.168.1.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to investigate what PAN process is doing that? Please give me some tips how to troubleshoot it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Feb 2014 13:50:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17463#M12751</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-02-26T13:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: strange connection from PA - help me please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17464#M12752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi slv,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;port 135 is netbios please look whether netbios is allowed in the rule Lan_A....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers Klaus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Feb 2014 14:00:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17464#M12752</guid>
      <dc:creator>kdd</dc:creator>
      <dc:date>2014-02-26T14:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: strange connection from PA - help me please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17465#M12753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;netbios isn't allowed in rules from Lan_A, 192.168.1.1 is a gateway in Lan_A. I have routing between my local networks so it couldn't be a traffic from other LAN network (I think).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have You any new sugestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Feb 2014 17:49:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17465#M12753</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-02-27T17:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: strange connection from PA - help me please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17466#M12754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi slv,&lt;/P&gt;&lt;P&gt;this paket isn't allowed by the rule "Lan_A - blokowanie". If you want the data to go through then there should be a rule to allow this traffic.&lt;/P&gt;&lt;P&gt;Port 135 belongs to MSRPC&amp;nbsp; (Netbios 137-139) . Let me know how ends.&lt;/P&gt;&lt;P&gt;Regards Klaus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Feb 2014 08:33:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17466#M12754</guid>
      <dc:creator>kdd</dc:creator>
      <dc:date>2014-02-28T08:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: strange connection from PA - help me please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17467#M12755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi kdd&lt;/P&gt;&lt;P&gt;I know that netbios isn't alloved - this is my intention. I'm looking for source of this traffic.&lt;/P&gt;&lt;P&gt;Gateway 192.168.1.1 in my opinion shouldn't generate such traffic (MSRPC). How to find real source of this traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regrds&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Mar 2014 17:01:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17467#M12755</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-03-02T17:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: strange connection from PA - help me please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17468#M12756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have user-identification enabled on the zone?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 22:19:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17468#M12756</guid>
      <dc:creator>prb</dc:creator>
      <dc:date>2014-03-05T22:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: strange connection from PA - help me please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17469#M12757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I have. I'm using user identyfiaction by agents on AD controller installed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Mar 2014 08:43:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17469#M12757</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-03-06T08:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: strange connection from PA - help me please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17470#M12758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have any nat interface for this zone?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, check the nat logs screening by this port.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Mar 2014 20:54:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17470#M12758</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-03-06T20:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: strange connection from PA - help me please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17471#M12759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Connected to the 192.168.1.1 interface?&lt;/P&gt;&lt;P&gt;If it is connecting to a different interface, you can uncheck user-identification from the zone in question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Mar 2014 21:09:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17471#M12759</guid>
      <dc:creator>prb</dc:creator>
      <dc:date>2014-03-06T21:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: strange connection from PA - help me please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17472#M12760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi slv,&lt;/P&gt;&lt;P&gt;i don't know if this is still an issue for you if so please check the router config for NAT. Maybe this is a reason to let appear the router a source towards to PA.&lt;/P&gt;&lt;P&gt;Regards Klaus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2014 09:16:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-connection-from-pa-help-me-please/m-p/17472#M12760</guid>
      <dc:creator>kdd</dc:creator>
      <dc:date>2014-03-10T09:16:30Z</dc:date>
    </item>
  </channel>
</rss>

