<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL VPN Routing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-routing/m-p/21701#M15852</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Result from that CLI is "no session active"...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 May 2012 14:04:47 GMT</pubDate>
    <dc:creator>cenders</dc:creator>
    <dc:date>2012-05-02T14:04:47Z</dc:date>
    <item>
      <title>SSL VPN Routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-routing/m-p/21699#M15850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Client SSL VPN configuration is working from client to server.&amp;nbsp; The client can ping the server no problem.&amp;nbsp; The server however, can not ping the client.&amp;nbsp; What am I missing?&amp;nbsp; The routes on the server appear to be correct, and I'm confident the packets are getting to the firewall but being dropped.&amp;nbsp; I can't see them in the logs though... which to me screams like a routing issue.&amp;nbsp; Any quick tips?&amp;nbsp; Off to break out the manual...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2012 02:32:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-routing/m-p/21699#M15850</guid>
      <dc:creator>cenders</dc:creator>
      <dc:date>2012-05-02T02:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-routing/m-p/21700#M15851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since the client can ping the server, this does not seem to be a routing issue.&amp;nbsp; This could be a security policy issue.&amp;nbsp; Do you have a security policy that allows pings from the server to the client?&amp;nbsp; Also, try the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Start a continuous ping from the server to the client.&lt;/P&gt;&lt;P&gt;2. Open a CLI session to PAN and run the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; show session all filter source &amp;lt;server-ip&amp;gt; destination &amp;lt;client-ip&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should see some ping sessions here.&amp;nbsp; Are they in the ACTIVE state or DISCARD state?&amp;nbsp; If you see sessions in ACTIVE state, try disabling the windows firewall on the client if not already disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ahsan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2012 03:22:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-routing/m-p/21700#M15851</guid>
      <dc:creator>akhan</dc:creator>
      <dc:date>2012-05-02T03:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-routing/m-p/21701#M15852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Result from that CLI is "no session active"...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2012 14:04:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-routing/m-p/21701#M15852</guid>
      <dc:creator>cenders</dc:creator>
      <dc:date>2012-05-02T14:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-routing/m-p/21702#M15853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok, my bad... mixup in the policies.&amp;nbsp; Was odd that I didn't see it dropping in the logs and such, but it is figured out now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2012 16:25:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-routing/m-p/21702#M15853</guid>
      <dc:creator>cenders</dc:creator>
      <dc:date>2012-05-02T16:25:21Z</dc:date>
    </item>
  </channel>
</rss>

