<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Client VPN traffic and routing over IPsec Tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/client-vpn-traffic-and-routing-over-ipsec-tunnel/m-p/18875#M13745</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;wwe have the same network configuration, but I don't know what I need to configure for give the VPN client access to the remote site resources. &lt;/P&gt;&lt;P&gt;Can an any one help me withe the configuration?&lt;/P&gt;&lt;P&gt;thank you. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 21 Sep 2013 16:04:18 GMT</pubDate>
    <dc:creator>Leonid</dc:creator>
    <dc:date>2013-09-21T16:04:18Z</dc:date>
    <item>
      <title>Client VPN traffic and routing over IPsec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-vpn-traffic-and-routing-over-ipsec-tunnel/m-p/18872#M13742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;Here is our scenario that I am trying to figure out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have two sites (main office and a rack in a data center) that are connected via PAN-2020's on both sides through a IPsec Tunnel. I am trying to route Client VPN traffic that connects at our main office to go over the site-to-site tunnel to access some web servers there. It seems the traffic goes over the tunnel, but all is marked as incomplete. Below is my config..is it a route metric issue or a routing issue in the Client VPN traffic config? Our VPN clients are obtaining DNS from internal domain controllers. Our web server are defined with internal zones on those domain controllers, that is why I am having this issue. Any help would be appreciated.&amp;nbsp; Can provide additional details as needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Main Office:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;STRONG&gt;Zones&lt;/STRONG&gt;:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Trust Zone - (192.168.x.x/16)&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;SSL-VPN Zone - (172.x.x.x/24) - no split brained routing (0.0.0.0/0)&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Site-to-Site Tunnel&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;STRONG&gt;Routes&lt;/STRONG&gt;:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Default Route: 0.0.0.0/0 - metric 10&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Trust Zone - metric 5&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;SSL-VPN Zone - next hop 0.0.0.0 - metric 8&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;All traffic over tunnel to remote zones - metric 5&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;STRONG&gt;Security Policies&lt;/STRONG&gt;:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Trust Zone &amp;amp; SSL-VPN zone to Tunnel - allow all traffic&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P&gt;Data Center Rack:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;STRONG&gt;Zones&lt;/STRONG&gt;:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Trust Zone - (10.20.x.x/16)&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Untrust Zone - (10.30.x.x/16) - were web servers are&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Site-to-Site Tunnel&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;STRONG&gt;Routes&lt;/STRONG&gt;:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Default Route: 0.0.0.0/0 - metric 10&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Trust Zone - metric 1&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Untrust Zone - metric 1&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;All traffic over tunnel to remote zones - metric 1&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;STRONG&gt;Security Policies&lt;/STRONG&gt;:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Trust Zone &amp;amp; Untrust Zone to Tunnel - allow all traffic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Sep 2013 20:50:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-vpn-traffic-and-routing-over-ipsec-tunnel/m-p/18872#M13742</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2013-09-19T20:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: Client VPN traffic and routing over IPsec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-vpn-traffic-and-routing-over-ipsec-tunnel/m-p/18873#M13743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN class="GINGER_SOFATWARE_correct"&gt;cmateam&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Incomplete means that either the three way &lt;SPAN class="GINGER_SOFATWARE_correct"&gt;tcp&lt;/SPAN&gt; handshake did NOT complete or the three way &lt;SPAN class="GINGER_SOFATWARE_correct"&gt;tcp&lt;/SPAN&gt; handshake did complete but there was no data after the handshake to identify the application. In other words that traffic you are seeing is not really an application.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;So to explain a little clearer, if a client sends a server a &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN class="GINGER_SOFATWARE_correct"&gt;syn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; and the &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Palo alto&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; device creates a session for that &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN class="GINGER_SOFATWARE_correct"&gt;syn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;,&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; but the server never sends a &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN class="GINGER_SOFATWARE_correct"&gt;syn&lt;/SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;ack&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; in response back to the client, then that session would be seen as incomplete.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Could you please share the session detail info here and d&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;o packet captures on the firewall at the transmit, receive and drop stage.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Example:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;IMG alt="traffoc-log-example.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8483_traffoc-log-example.JPG.jpg" style="width: 620px; height: 326px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Sep 2013 21:48:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-vpn-traffic-and-routing-over-ipsec-tunnel/m-p/18873#M13743</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-09-19T21:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Client VPN traffic and routing over IPsec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-vpn-traffic-and-routing-over-ipsec-tunnel/m-p/18874#M13744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the screen shots and packet captures.&amp;nbsp; Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet Captures: &lt;A href="https://www.dropbox.com/sh/vd8vbdbtve1cuvz/2iQUDOJZ1t" title="https://www.dropbox.com/sh/vd8vbdbtve1cuvz/2iQUDOJZ1t"&gt;Dropbox - PAN&lt;/A&gt; (doesn't look like I can upload the packet captures here) this is on the firewall handling the Client VPN traffic)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic on FW handling Client VPN traffic&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="8500" alt="MainOff_to_DC_overtunnel.jpg" class="jive-image jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/8500_MainOff_to_DC_overtunnel.jpg" style="width: 620px; height: 419px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Receiving FW&lt;/P&gt;&lt;P&gt;&lt;IMG alt="DC_to_Zone.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8501_DC_to_Zone.jpg" style="width: 620px; height: 419px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Sep 2013 15:38:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-vpn-traffic-and-routing-over-ipsec-tunnel/m-p/18874#M13744</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2013-09-20T15:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Client VPN traffic and routing over IPsec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-vpn-traffic-and-routing-over-ipsec-tunnel/m-p/18875#M13745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;wwe have the same network configuration, but I don't know what I need to configure for give the VPN client access to the remote site resources. &lt;/P&gt;&lt;P&gt;Can an any one help me withe the configuration?&lt;/P&gt;&lt;P&gt;thank you. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Sep 2013 16:04:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-vpn-traffic-and-routing-over-ipsec-tunnel/m-p/18875#M13745</guid>
      <dc:creator>Leonid</dc:creator>
      <dc:date>2013-09-21T16:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: Client VPN traffic and routing over IPsec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-vpn-traffic-and-routing-over-ipsec-tunnel/m-p/18876#M13746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may try to traceroute from servers to vpn clients and see what is wrong.seems to be routing issue.Try to add a route for a web server and forward its traffic for vpn subnet through tunnel.see if it works&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Sep 2013 18:23:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-vpn-traffic-and-routing-over-ipsec-tunnel/m-p/18876#M13746</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-09-21T18:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: Client VPN traffic and routing over IPsec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-vpn-traffic-and-routing-over-ipsec-tunnel/m-p/18877#M13747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Traceroute helped identify the problem and reading this post: &lt;A href="https://live.paloaltonetworks.com/thread/8762"&gt;Accessing all company networks with GlobalProtect client&lt;/A&gt; - turns out it was a route that needed to be added on the other side to return the traffic back to the client.&amp;nbsp; Looks like everything is working as expected. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cc: @&lt;SPAN class="j-post-author"&gt;&lt;STRONG&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="21297" data-username="leonidspect" href="https://live.paloaltonetworks.com/people/leonidspect"&gt;leonidspect&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Sep 2013 21:19:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-vpn-traffic-and-routing-over-ipsec-tunnel/m-p/18877#M13747</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2013-09-23T21:19:14Z</dc:date>
    </item>
  </channel>
</rss>

