<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL VPN users unable to access the internet though Palo in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-users-unable-to-access-the-internet-though-palo/m-p/35865#M26358</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Problems like this usually fall into one of two catagories.&lt;/P&gt;&lt;P&gt;1) The range allocated for SSL VPN users is not getting the proper NAT applied when the traffic goes out to&amp;nbsp; the internet&lt;/P&gt;&lt;P&gt;2) There is another router involved in the path and that router is not aware of the SSL VPN subnet or is directing the traffic to the incorrect next hop.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If neither of these is the case you should open a case with support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 31 Oct 2011 17:02:42 GMT</pubDate>
    <dc:creator>skrall</dc:creator>
    <dc:date>2011-10-31T17:02:42Z</dc:date>
    <item>
      <title>SSL VPN users unable to access the internet though Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-users-unable-to-access-the-internet-though-palo/m-p/35864#M26357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;Hi&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have setup SSL VPN and its been in use for a few weeks without any issue with the exception of one minor annoyance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;I have been unable to get the SSL VPN users to be able to see the internet when connected. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;1) The access route is set to 0.0.0.0/0 to force all traffic back though the Palo Alto.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I don’t want users getting internet direct when they are VPN'ed in but force them to be filtered just like when they are in the office.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;2) If I use a laptop with Firefox on and point it to a temporary internal proxy on port 8080 i can get back out again to the internet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;3) The VPN users get an IP address in a range outside the normal local LAN range.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;4) There is a router which is the default gateway points all traffic not destined for one of our other networks though the Palo alto.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;I think this issue is that the VPN traffic is exiting the Palo on the same interface that it has to come back on to get out of the internet and there is nothing to point it back were all other traffic is being forwarded to the Palo Alto by the gateway. Therefore I think I need some sort of rule on the Palo that internally forwards VPN traffic not destined for one of internal networks back out of the WAN port????&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;Ethernet 1/1 (WAN) (DefaultVR) (L3-untrust) 194.123.123.18/28&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;Ethernet 1/2 (LAN) (DefaultVR) (L3-untrust) 10.1.1.20/8&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;Management 10.1.1.23&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;----&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;SSL-VPN range 10.3.1.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;SSL Gateway (eth1/1) 194.123.123.18/28&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;----&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;Tunnel (DefaultVR) L3-Trust (no IP)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;----&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;DefaultVR Static routes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;default&lt;SPAN style="mso-tab-count:1"&gt; &lt;/SPAN&gt;0.0.0.0/0&lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt; &lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;ip&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;194.123.123.17&lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;none&lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;none&lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt; &lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;Site2&lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;10.2.0.0/16&lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt; &lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;ip&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;10.1.1.11&lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;none&lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;none&lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt; &lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;Site3&lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;10.5.0.0/16&lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt; &lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;ip&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;10.1.1.11&lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;none&lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;none&lt;SPAN style="mso-tab-count:1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;---&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;Border Router (for Site to site links) 10.1.1.11&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Forwards all traffic for other networks e.g. 10.2.0.0/16 over site to site link&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;mso-bidi-font-size:12.0pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Forwards everything else to Palo &amp;gt; 10.1.1.20&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Oct 2011 14:29:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-users-unable-to-access-the-internet-though-palo/m-p/35864#M26357</guid>
      <dc:creator>parkcakes</dc:creator>
      <dc:date>2011-10-27T14:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN users unable to access the internet though Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-users-unable-to-access-the-internet-though-palo/m-p/35865#M26358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Problems like this usually fall into one of two catagories.&lt;/P&gt;&lt;P&gt;1) The range allocated for SSL VPN users is not getting the proper NAT applied when the traffic goes out to&amp;nbsp; the internet&lt;/P&gt;&lt;P&gt;2) There is another router involved in the path and that router is not aware of the SSL VPN subnet or is directing the traffic to the incorrect next hop.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If neither of these is the case you should open a case with support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Oct 2011 17:02:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-users-unable-to-access-the-internet-though-palo/m-p/35865#M26358</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2011-10-31T17:02:42Z</dc:date>
    </item>
  </channel>
</rss>

