<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL VPN client is sending the PA traffic with other local interface IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-is-sending-the-pa-traffic-with-other-local/m-p/3007#M2234</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I realised that some traffic from several remote clients is going through the firewall with another remote-local IP address, different from my remote assigned-pool. Obviously, this traffic is beeing dropped. It happens with users accessing correctly to other services (with the correct VPN-assigned IP). &lt;/P&gt;&lt;P&gt;Could it be a Global Protect issue?&lt;/P&gt;&lt;P&gt;It started to happen when we went up from version 3.1.4 to 4.0.5. Now we have 4.1.10 and Global Protect 1.2.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Jan 2013 17:24:16 GMT</pubDate>
    <dc:creator>CarlesGISA</dc:creator>
    <dc:date>2013-01-15T17:24:16Z</dc:date>
    <item>
      <title>SSL VPN client is sending the PA traffic with other local interface IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-is-sending-the-pa-traffic-with-other-local/m-p/3007#M2234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I realised that some traffic from several remote clients is going through the firewall with another remote-local IP address, different from my remote assigned-pool. Obviously, this traffic is beeing dropped. It happens with users accessing correctly to other services (with the correct VPN-assigned IP). &lt;/P&gt;&lt;P&gt;Could it be a Global Protect issue?&lt;/P&gt;&lt;P&gt;It started to happen when we went up from version 3.1.4 to 4.0.5. Now we have 4.1.10 and Global Protect 1.2.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 17:24:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-is-sending-the-pa-traffic-with-other-local/m-p/3007#M2234</guid>
      <dc:creator>CarlesGISA</dc:creator>
      <dc:date>2013-01-15T17:24:16Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN client is sending the PA traffic with other local interface IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-is-sending-the-pa-traffic-with-other-local/m-p/3008#M2235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are probalby meeting a split-tunneling issue; Check your access route in your Gateway configuration.&lt;/P&gt;&lt;P&gt;Some traffic is probalby still routed in your LAN and not in your tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 14:17:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-is-sending-the-pa-traffic-with-other-local/m-p/3008#M2235</guid>
      <dc:creator>nbilly</dc:creator>
      <dc:date>2013-01-16T14:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN client is sending the PA traffic with other local interface IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-is-sending-the-pa-traffic-with-other-local/m-p/3009#M2236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nicolas,&lt;/P&gt;&lt;P&gt;thanks for reply.&lt;/P&gt;&lt;P&gt;I think it's the opposite. Some local traffic of the remote client is being routed through the VPN, so I can see some incoming traffic from another physical interface the remote computer has.&lt;/P&gt;&lt;P&gt;For exemple: I'm assigning 192.168.1.0/24 IP's to the remote clients. If one client connects, I assign it 192.168.1.1 and I can see traffic to my internal IP's from this IP. But I can see also traffic from 10.10.10.10 (a remote local IP) to machines of my local 10.10.10.0/24 segment.&lt;/P&gt;&lt;P&gt;It's like the Global Protect agent is routing all the traffic (10.10.10.0 is in the acces route of my gateway) to my routed networks &lt;SPAN style="text-decoration: underline;"&gt;including&lt;/SPAN&gt; traffic from other interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Carlos.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 16:16:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-is-sending-the-pa-traffic-with-other-local/m-p/3009#M2236</guid>
      <dc:creator>CarlesGISA</dc:creator>
      <dc:date>2013-01-16T16:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN client is sending the PA traffic with other local interface IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-is-sending-the-pa-traffic-with-other-local/m-p/3010#M2237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Carlos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which access routes did you have configured?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 08:09:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-is-sending-the-pa-traffic-with-other-local/m-p/3010#M2237</guid>
      <dc:creator>nbilly</dc:creator>
      <dc:date>2013-01-17T08:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN client is sending the PA traffic with other local interface IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-is-sending-the-pa-traffic-with-other-local/m-p/3011#M2238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nicolas,&lt;/P&gt;&lt;P&gt;I have several networks in the access routes list. For example:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/5226_pastedImage_0.png" style="width: 324px; height: 208px;" /&gt;&lt;/P&gt;&lt;P&gt;But I don't have 0.0.0.0/0, if you mean that... But yes, unusual traffic I'm seeing is coming FROM IP's of these ranges of other interfaces of the remote client.&lt;/P&gt;&lt;P&gt;Here you can see I'm assigning remote IP's from another range, so I wouldn't see traffic from this zone EXCEPT from this range:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/5227_pastedImage_1.png" style="width: 322px; height: 236px;" /&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Carlos.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 12:20:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-is-sending-the-pa-traffic-with-other-local/m-p/3011#M2238</guid>
      <dc:creator>CarlesGISA</dc:creator>
      <dc:date>2013-01-18T12:20:12Z</dc:date>
    </item>
  </channel>
</rss>

