<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PAN OS 5.0.0 &amp;quot;killing&amp;quot; remote connections in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-0-quot-killing-quot-remote-connections/m-p/33145#M24290</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry for the "bad" title, bat that's whats actually happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a NAT rule translating the external interface IP to an internal server from Port 443 to 8443 (for OpenVPN) and to the same server for ssh (no port translation)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I connect with OpenVPN to the VPN Server, it connects fine, but as soon as I have a certain amount of traffic (i.e. opening a webpage), the client drops the connection with:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----cut---&lt;/P&gt;&lt;P&gt;Nov 20 19:38:21: Authenticate/Decrypt packet error: packet HMAC authentication failed&lt;/P&gt;&lt;P&gt;Nov 20 19:38:21: Fatal decryption error (process_incoming_link), restarting&lt;/P&gt;&lt;P&gt;Nov 20 19:38:21: SIGUSR1[soft,decryption-error] received, process restarting&lt;/P&gt;&lt;P&gt;---cut---&lt;/P&gt;&lt;P&gt;I first assumed a problem on the VPN Server, but connecting to it bypassing the PA works perfectly fine.&lt;/P&gt;&lt;P&gt;I also tried configuring "Disable server response" in the security policy with no effect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above mentioned does not only kill my openvpn connections, but also does the same for a SSH connection to the same server (Error Message: HMAC Error, connection reset) as soon as there is some traffic on the connection (e.g. less a bigger log file)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone give me a hint where to dig deeper in order to find the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andre&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Nov 2012 18:56:32 GMT</pubDate>
    <dc:creator>u13550</dc:creator>
    <dc:date>2012-11-20T18:56:32Z</dc:date>
    <item>
      <title>PAN OS 5.0.0 "killing" remote connections</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-0-quot-killing-quot-remote-connections/m-p/33145#M24290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry for the "bad" title, bat that's whats actually happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a NAT rule translating the external interface IP to an internal server from Port 443 to 8443 (for OpenVPN) and to the same server for ssh (no port translation)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I connect with OpenVPN to the VPN Server, it connects fine, but as soon as I have a certain amount of traffic (i.e. opening a webpage), the client drops the connection with:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----cut---&lt;/P&gt;&lt;P&gt;Nov 20 19:38:21: Authenticate/Decrypt packet error: packet HMAC authentication failed&lt;/P&gt;&lt;P&gt;Nov 20 19:38:21: Fatal decryption error (process_incoming_link), restarting&lt;/P&gt;&lt;P&gt;Nov 20 19:38:21: SIGUSR1[soft,decryption-error] received, process restarting&lt;/P&gt;&lt;P&gt;---cut---&lt;/P&gt;&lt;P&gt;I first assumed a problem on the VPN Server, but connecting to it bypassing the PA works perfectly fine.&lt;/P&gt;&lt;P&gt;I also tried configuring "Disable server response" in the security policy with no effect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above mentioned does not only kill my openvpn connections, but also does the same for a SSH connection to the same server (Error Message: HMAC Error, connection reset) as soon as there is some traffic on the connection (e.g. less a bigger log file)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone give me a hint where to dig deeper in order to find the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andre&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Nov 2012 18:56:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-0-quot-killing-quot-remote-connections/m-p/33145#M24290</guid>
      <dc:creator>u13550</dc:creator>
      <dc:date>2012-11-20T18:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0.0 "killing" remote connections</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-0-quot-killing-quot-remote-connections/m-p/33146#M24291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;do you have specific application policies other than the nat rule ? I would try to do some logging on the security policies and some packet caputure to see if and how the traffic passes through the pan..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2013 12:44:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-0-quot-killing-quot-remote-connections/m-p/33146#M24291</guid>
      <dc:creator>mne</dc:creator>
      <dc:date>2013-05-02T12:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0.0 "killing" remote connections</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-0-quot-killing-quot-remote-connections/m-p/33147#M24292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Auth failures could imply fragmented encrypted traffic with some missing fragments. PCAPs should help determine if this is the case. Also ensure that you do not have any zone protection profiles which block frags. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2013 23:58:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-0-quot-killing-quot-remote-connections/m-p/33147#M24292</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-05-02T23:58:42Z</dc:date>
    </item>
  </channel>
</rss>

