<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL VPN client ports in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-ports/m-p/31668#M23165</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We disabled IPsec on our PA500.&amp;nbsp; Tried reconnecting the SSL Client but still getting the same error.&amp;nbsp; I can see the clients attempting to connect but are never assigned an IP address from my SSL pool; but other clients are getting IP addresses.&amp;nbsp; Is it possible that 443 is used for authentication and another port is used for data ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a debug command i can use to view authentications and data coming into the firewall?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Apr 2011 17:45:01 GMT</pubDate>
    <dc:creator>cityofkingsland</dc:creator>
    <dc:date>2011-04-06T17:45:01Z</dc:date>
    <item>
      <title>SSL VPN client ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-ports/m-p/31664#M23161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;We have a few officers that connect from a remote location with a firewall of its own.&amp;nbsp; They are all using the SSL VPN client to connect back to home.&amp;nbsp; I can pull up the &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://external-ip"&gt;https://external-ip&lt;/A&gt;&lt;SPAN&gt; and login, but when the connection starts up i get a Disconnected; unable to connect to remote client. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I need to know what ports the SSL VPN client uses to connect back to our firewall so I can tell the IT guy what ports to open.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Mar 2011 14:26:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-ports/m-p/31664#M23161</guid>
      <dc:creator>cityofkingsland</dc:creator>
      <dc:date>2011-03-23T14:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN client ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-ports/m-p/31665#M23162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also high priority, the people using this VPN can't do their reports unless they have the VPN connection. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Mar 2011 18:33:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-ports/m-p/31665#M23162</guid>
      <dc:creator>cityofkingsland</dc:creator>
      <dc:date>2011-03-23T18:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN client ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-ports/m-p/31666#M23163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; If you do not have IPsec enabled, SSL VPN will use TCP 443.&amp;nbsp; If IPSec is enabled. TCP 443 will be used for authentication and the traffic will use UDP port 500.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Mar 2011 23:31:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-ports/m-p/31666#M23163</guid>
      <dc:creator>nrice</dc:creator>
      <dc:date>2011-03-23T23:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN client ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-ports/m-p/31667#M23164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe UDP port 4501 is used for the UDP encapsulated ESP (IPSEC) transit channel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2011 04:23:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-ports/m-p/31667#M23164</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-03-24T04:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN client ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-ports/m-p/31668#M23165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We disabled IPsec on our PA500.&amp;nbsp; Tried reconnecting the SSL Client but still getting the same error.&amp;nbsp; I can see the clients attempting to connect but are never assigned an IP address from my SSL pool; but other clients are getting IP addresses.&amp;nbsp; Is it possible that 443 is used for authentication and another port is used for data ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a debug command i can use to view authentications and data coming into the firewall?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Apr 2011 17:45:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-ports/m-p/31668#M23165</guid>
      <dc:creator>cityofkingsland</dc:creator>
      <dc:date>2011-04-06T17:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN client ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-ports/m-p/31669#M23166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Kelly is correct, IPSEC uses 4501.&amp;nbsp; With IPSEC disabled the traffic does use 443 and is identified as web-browsing. A couple of commands to look at authentication and traffic are:&lt;/P&gt;&lt;P&gt;&amp;gt;show ssl-vpn current-user - to show who is logged in.&amp;nbsp; You can also type portal &amp;lt;name&amp;gt; after the command to see who is logged in by portal.&lt;/P&gt;&lt;P&gt;&amp;gt;show log system subtype equal sslvpn - to show all ssl vpn authentication and connection requests. &lt;/P&gt;&lt;P&gt;You may want to disable antivirus or the firewall on the clients with the problem.&amp;nbsp; If you are unable to resolve, please contact your support provider to troubleshoot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Apr 2011 19:12:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-client-ports/m-p/31669#M23166</guid>
      <dc:creator>nrice</dc:creator>
      <dc:date>2011-04-06T19:12:56Z</dc:date>
    </item>
  </channel>
</rss>

