<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: url_filtering problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-problem/m-p/21884#M15983</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Johan,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please try to clear URL cache from this PA&amp;nbsp; firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;clear&lt;/SPAN&gt; url-cache all&lt;/P&gt;&lt;P&gt;&amp;gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;delete&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;dymanic&lt;/SPAN&gt; –&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;url host&lt;/SPAN&gt; all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even after applying above command, issue persists, then apply below command. &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;it&lt;/SPAN&gt; will &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;not impact to your&lt;/SPAN&gt; production traffic)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;debug&lt;/SPAN&gt; software &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;restart&lt;/SPAN&gt; device-server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 15 Nov 2014 14:58:11 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-11-15T14:58:11Z</dc:date>
    <item>
      <title>url_filtering problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-problem/m-p/21881#M15980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI all,&lt;/P&gt;&lt;P&gt;We have a cluster of 2xPA3050, for protection to untrusted zone. Last week we enabled the trial license for url_filtering. Since that moment we have met a special problem. We use a citrix application over ssl in the cloud. This citrix server is perfectly reachable, but after the authentication, the application seems to hang. We disabled all rules referring to url_filter categories, so there is no reference in the policy to url-filter. Nevertheless, with the license enabled, the citrix application doesn't work. There is no reference in the monitor tab/logs that something is dropped. By doing a packet capture, we only see an rst tcp reset from the other side, but nothing seems to be dropped or logged.&lt;/P&gt;&lt;P&gt;Anybody knows how I can troubleshoot this ? Is there a possibility that with activating the pan-db database in the licenses, without activating any rules, that there is an interception on ssl traffic ?&lt;/P&gt;&lt;P&gt;We have panos6.1, url_filtering, also global protect is enabled. Ssl decription is not enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and greetz,&lt;/P&gt;&lt;P&gt;Johan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Nov 2014 09:17:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-problem/m-p/21881#M15980</guid>
      <dc:creator>johan.boeckx</dc:creator>
      <dc:date>2014-11-15T09:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: url_filtering problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-problem/m-p/21882#M15981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/u1/27165"&gt;johan.boeckx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you see any session in discard state for the concerned IP address, you can look at it using : show session all filter state discard source &amp;lt;ip-address&amp;gt; ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also can you compare the TTL value in RST packet that you are seeing with TTL that you see in any other packet from the source ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Nov 2014 09:19:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-problem/m-p/21882#M15981</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-11-15T09:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: url_filtering problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-problem/m-p/21883#M15982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the answer. I checked the session based on the source as on the destination. Both there were no active sessions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@FW01CO(active)&amp;gt; show session all filter state discard source 10.104.0.8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No Active Sessions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@FW01CO(active)&amp;gt; show session all filter state discard source 10.104.0.8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No Active Sessions&lt;/P&gt;&lt;P&gt;admin@FW01CO(active)&amp;gt; show session all filter state discard destination 193.109.234.40&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No Active Sessions&lt;/P&gt;&lt;P&gt;admin@FW01CO(active)&amp;gt; show session all filter state discard destination 193.109.234.43&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No Active Sessions&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Nov 2014 12:56:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-problem/m-p/21883#M15982</guid>
      <dc:creator>johan.boeckx</dc:creator>
      <dc:date>2014-11-15T12:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: url_filtering problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-problem/m-p/21884#M15983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Johan,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please try to clear URL cache from this PA&amp;nbsp; firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;clear&lt;/SPAN&gt; url-cache all&lt;/P&gt;&lt;P&gt;&amp;gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;delete&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;dymanic&lt;/SPAN&gt; –&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;url host&lt;/SPAN&gt; all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even after applying above command, issue persists, then apply below command. &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;it&lt;/SPAN&gt; will &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;not impact to your&lt;/SPAN&gt; production traffic)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;debug&lt;/SPAN&gt; software &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;restart&lt;/SPAN&gt; device-server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Nov 2014 14:58:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-problem/m-p/21884#M15983</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-15T14:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: url_filtering problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-problem/m-p/21885#M15984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried this, but didnt gave any result. I digged a bit deeper and read number of Palo alto docs regarding flow_tcp_non_syn_drop, which I had a lot. This is related to assymetric routing. Strange is that we dont have assymetric routing, but since this webside is in the cloud, the problem can have originated on the internet. Anyway, I disabled the TCP - reject non-SYN first packet: from true to false. Now,a number of applications work on this cloud based site, only not the citrix related, tunneled through ssl.Nothing is blocked through policies. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Nov 2014 11:57:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-problem/m-p/21885#M15984</guid>
      <dc:creator>johan.boeckx</dc:creator>
      <dc:date>2014-11-16T11:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: url_filtering problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-problem/m-p/248697#M70741</link>
      <description>&lt;P&gt;Just curious to know,how the problem is resolved&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 12:18:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-problem/m-p/248697#M70741</guid>
      <dc:creator>rkcchaitu</dc:creator>
      <dc:date>2019-02-04T12:18:16Z</dc:date>
    </item>
  </channel>
</rss>

