<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic check to check &amp;quot;deny&amp;quot; packages in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/check-to-check-quot-deny-quot-packages/m-p/34004#M24937</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have some rules that will allow IPSEC between two Windows Domain Controllers, but it only works when I allow "any" underapplication - unless I ping from both ends.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So how can I see what port I am missing in my custom application group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Nov 2011 16:09:44 GMT</pubDate>
    <dc:creator>FlexyZ</dc:creator>
    <dc:date>2011-11-24T16:09:44Z</dc:date>
    <item>
      <title>check to check "deny" packages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-to-check-quot-deny-quot-packages/m-p/34004#M24937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have some rules that will allow IPSEC between two Windows Domain Controllers, but it only works when I allow "any" underapplication - unless I ping from both ends.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So how can I see what port I am missing in my custom application group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Nov 2011 16:09:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-to-check-quot-deny-quot-packages/m-p/34004#M24937</guid>
      <dc:creator>FlexyZ</dc:creator>
      <dc:date>2011-11-24T16:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: check to check "deny" packages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-to-check-quot-deny-quot-packages/m-p/34005#M24938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to look at the session table via CLI to determine what's being discarded when utilizing your application group. Something along these lines. Use the information to modify your app group accordingly and continue to test until you've rectified the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; show session all filter source 10.10.10.10 destination 192.168.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Renato&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Nov 2011 09:41:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-to-check-quot-deny-quot-packages/m-p/34005#M24938</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2011-11-25T09:41:17Z</dc:date>
    </item>
  </channel>
</rss>

