<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL VPN - Basic Questions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39958#M29292</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What basic steps have to be complete to allow a remote user to enter an ip address in their browser and get the ssl vpn authentication screen? We currently get an eventual timeout when we try to connect from a browser.&amp;nbsp; We followed the basic GlobalProtect setup steps, but, just wondering if there is something 'dumb' that we are missing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 May 2014 13:34:28 GMT</pubDate>
    <dc:creator>shank</dc:creator>
    <dc:date>2014-05-22T13:34:28Z</dc:date>
    <item>
      <title>SSL VPN - Basic Questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39958#M29292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What basic steps have to be complete to allow a remote user to enter an ip address in their browser and get the ssl vpn authentication screen? We currently get an eventual timeout when we try to connect from a browser.&amp;nbsp; We followed the basic GlobalProtect setup steps, but, just wondering if there is something 'dumb' that we are missing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 13:34:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39958#M29292</guid>
      <dc:creator>shank</dc:creator>
      <dc:date>2014-05-22T13:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN - Basic Questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39959#M29293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Shank,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a good document to start initial troubleshooting: &lt;A href="https://live.paloaltonetworks.com/message/39894"&gt; ?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can verify the session information on the PAN firewall CLI to understand where the packet is getting dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you trying to access the portal from inside network &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;from firewall stand point) or from public internet...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3210"&gt;How To Access External GP Portal/GW From Inside The Firewall&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 15:25:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39959#M29293</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-22T15:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN - Basic Questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39960#M29294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the public side of the firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 15:31:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39960#M29294</guid>
      <dc:creator>shank</dc:creator>
      <dc:date>2014-05-22T15:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN - Basic Questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39961#M29295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also, I get 'unauthorized' when I try to view the first link you provided. Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 15:32:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39961#M29295</guid>
      <dc:creator>shank</dc:creator>
      <dc:date>2014-05-22T15:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN - Basic Questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39962#M29296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FYI for DOC &lt;A _jive_internal="true" data-containerid="2057" data-containertype="14" data-objectid="39894" data-objecttype="2" href="https://live.paloaltonetworks.com/message/39894#39894" style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #006595;"&gt;Globalprotect portal uses web-browsing&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN&gt; ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;H1 style="font-style: inherit; font-size: 26px; font-family: inherit; color: #666666;"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/39894#39894" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #006595;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Globalprotect&lt;/SPAN&gt; portal uses web-browsing&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; ?&lt;/SPAN&gt;&lt;/A&gt;&lt;/H1&gt;&lt;P class="jive-answer-type font-color-meta jive-answer-type-answered" style="margin-top: 5px; font-weight: inherit; font-style: inherit; font-family: inherit; color: #8b8b8b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #0000ff;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;1) Are both &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;ssl&lt;/SPAN&gt; and web-browsing need to be allowed for GP portal to connect. In customer's case we needed to allow both SSL and WEB-BROWSING in order to display the GP portal page.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;PA-5050&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;PAN-OS&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; :&lt;/SPAN&gt; 5.0.4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;Tested in &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;lab&lt;/SPAN&gt; and with Pan-OS 5.0.11 and found that we need both SSL and Web-browsing to allow &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;GP portal page&lt;/SPAN&gt; to get displayed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000080;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;2) The web-browsing application that is being identified when we access the GP portal page uses port 443 instead of 80. &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Customer&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;needs to to know&lt;/SPAN&gt; why&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; ?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;c2s flow:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt;:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 115.114.47.125 [&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;untrust&lt;/SPAN&gt;]&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;dst&lt;/SPAN&gt;:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 86.36.50.9&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;proto&lt;/SPAN&gt;:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;sport&lt;/SPAN&gt;:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15579&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;STRONG style="font-style: inherit; font-family: Tahoma; color: #000000; background-color: #ffff00;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;dport&lt;/SPAN&gt;:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 443&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;state&lt;/SPAN&gt;:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACTIVE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FLOW&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;src&lt;/SPAN&gt; user:&amp;nbsp;&amp;nbsp;&amp;nbsp; unknown&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;dst&lt;/SPAN&gt; user:&amp;nbsp;&amp;nbsp;&amp;nbsp; unknown&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; s2c flow:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt;:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 86.36.50.9 [SSL-VPN]&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;dst&lt;/SPAN&gt;:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 115.114.47.125&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;proto&lt;/SPAN&gt;:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;sport&lt;/SPAN&gt;:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20077&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;dport&lt;/SPAN&gt;:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15579&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;state&lt;/SPAN&gt;:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACTIVE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FLOW&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;src&lt;/SPAN&gt; user:&amp;nbsp;&amp;nbsp;&amp;nbsp; unknown&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;dst&lt;/SPAN&gt; user:&amp;nbsp;&amp;nbsp;&amp;nbsp; unknown&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;qos&lt;/SPAN&gt; node:&amp;nbsp;&amp;nbsp;&amp;nbsp; ethernet1/13, &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;qos&lt;/SPAN&gt; member N/A Qid -2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;start&lt;/SPAN&gt; time&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; Sun Apr 27 18:46:24 2014&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;timeout&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; 60 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;sec&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;time&lt;/SPAN&gt; to live&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; 52 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;sec&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;total&lt;/SPAN&gt; byte count&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;(&lt;/SPAN&gt;c2s)&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; 7467&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;total&lt;/SPAN&gt; byte count&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;(&lt;/SPAN&gt;s2c)&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; 55677&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; layer7 packet count&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;(&lt;/SPAN&gt;c2s)&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; 79&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; layer7 packet count&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;(&lt;/SPAN&gt;s2c)&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; 45&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;vsys&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; vsys1&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;STRONG style="font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp; &lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit; background-color: #ffff00;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;application&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; web-browsing &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;rule&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; test &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;vpn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;session&lt;/SPAN&gt; to be logged at &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;end&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; True&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;session&lt;/SPAN&gt; in session ager&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; True&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;session&lt;/SPAN&gt; synced from HA peer&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; False&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;address&lt;/SPAN&gt;/port translation&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; source + destination&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;nat&lt;/SPAN&gt;-rule&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; (vsys1)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; layer7 processing&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; completed&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL filtering enabled&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; False&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;session&lt;/SPAN&gt; via &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;syn&lt;/SPAN&gt;-cookies&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; False&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;session&lt;/SPAN&gt; terminated on host&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; True&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;session&lt;/SPAN&gt; traverses tunnel&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; False&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;captive&lt;/SPAN&gt; portal session&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; False&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;ingress&lt;/SPAN&gt; interface&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; ethernet1/13&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;egress&lt;/SPAN&gt; interface&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;loopback&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;.&lt;/SPAN&gt;1&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;session&lt;/SPAN&gt; QoS rule&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt; N/A (class 4)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;session&lt;/SPAN&gt; tracker stage l7proc&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp; :&lt;/SPAN&gt; proxy timer expired&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #003366;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;3) When we access the GP portal page, the monitor logs shows DECRYPTED checked. There is no decryption policy enabled on firewall then why this session is shown as decrypted&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; ?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #003366;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #003366;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #003366;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;ANS:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: Tahoma; color: #003366;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;H6 style="font-style: inherit; font-family: inherit; color: #666666;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;&lt;A _jive_internal="true" class="font-color-meta-light" href="https://live.paloaltonetworks.com/message/39913#39913" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #a9a9a9;" title="Link to reply #1"&gt;1.&lt;/A&gt; &lt;A _jive_internal="true" class="font-color-meta-light" href="https://live.paloaltonetworks.com/message/39913#39913" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #a9a9a9;"&gt;Re: Globalprotect portal uses web-browsing&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; ?&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/H6&gt;&lt;P class="j-post-avatar" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: inherit; font-style: inherit; font-weight: inherit; font-size: 10pt; line-height: 1.5em;"&gt;1. Yes, you need to allow both &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-family: inherit; font-style: inherit; font-weight: inherit; font-size: 10pt; line-height: 1.5em;"&gt;ssl&lt;/SPAN&gt;&lt;SPAN style="font-family: inherit; font-style: inherit; font-weight: inherit; font-size: 10pt; line-height: 1.5em;"&gt; and web-browsing for GP page to work. This assumes you have a default deny-all &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-family: inherit; font-style: inherit; font-weight: inherit; font-size: 10pt; line-height: 1.5em;"&gt;policy&lt;/SPAN&gt;&lt;SPAN style="font-family: inherit; font-style: inherit; font-weight: inherit; font-size: 10pt; line-height: 1.5em;"&gt;, which is not standard. If you don't have a deny-all policy, the GP page is &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-family: inherit; font-style: inherit; font-weight: inherit; font-size: 10pt; line-height: 1.5em;"&gt;on&lt;/SPAN&gt;&lt;SPAN style="font-family: inherit; font-style: inherit; font-weight: inherit; font-size: 10pt; line-height: 1.5em;"&gt; the same zone as the client requesting the page (usually) and is allowed implicitly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;2. Any connection that is decrypted will show the real application (see answer below). SSL is an application only when we cannot decrypt the session and determine what is happening under the SSL transport.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;3. The reason it is decrypted is because the firewall itself is handling the SSL connection. There is nothing to decode because the firewall has the private &amp;amp; public key.&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-family: inherit; font-weight: inherit;"&gt;&lt;A _jive_internal="true" class="jive-acclaim-likelink" data-command="like" data-object-id="39913" data-object-type="2" href="https://live.paloaltonetworks.com/message/39894" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #006595;"&gt;Globalprotect portal uses web-browsing ?&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 15:44:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39962#M29296</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-22T15:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN - Basic Questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39963#M29297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The IP address of the portal has to be reachable from the internet. Do you have a destination NAT rule which already forwards traffic on the public IP address with port 443 to another host?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have an Any -&amp;gt; Any Deny rule? This could block the traffic on your public interface to the portal.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 15:45:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39963#M29297</guid>
      <dc:creator>Wenar</dc:creator>
      <dc:date>2014-05-22T15:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN - Basic Questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39964#M29298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a L3_Untrust TO L3_Untrust rule that has an action of ALLOW and currently it is any from address/user to a destination of VPN_IncomingAddress.&amp;nbsp; I allowed applications of ssl and web-browsing and during this test phase, this policy is the #1 policy.&amp;nbsp; When we monitor this we do see communication to port 443, with an action of allow.&amp;nbsp; I do see a lot of 0 byte entries as well as 60 byte entries.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 16:04:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39964#M29298</guid>
      <dc:creator>shank</dc:creator>
      <dc:date>2014-05-22T16:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN - Basic Questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39965#M29299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Shank,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the session details showing all the parameters i.e security policy, ingress/egress interface &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;etc&lt;/SPAN&gt; correctly.....?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 16:09:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39965#M29299</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-22T16:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN - Basic Questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39966#M29300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Security rule appears correct, Detail says app=ssl, NAT source=false, NAT Destination=true.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am actually going from a static computer to the static ip that I defined as the 'gateway web service', so, I am not sure why detail says NAT Destination= True.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Flow 1, c2s, looks good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Flow 2 from the IP_Gateway_Web_Service back to the static computer seems ok, I can't tell what else is happening?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 16:22:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39966#M29300</guid>
      <dc:creator>shank</dc:creator>
      <dc:date>2014-05-22T16:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN - Basic Questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39967#M29301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Shank,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please identify the session ID for the same traffic and open it in CLI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAN&amp;gt; show session id XYZ&amp;nbsp;&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; It will give you the detailed information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 16:35:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39967#M29301</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-22T16:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN - Basic Questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39968#M29302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;New device.&amp;nbsp; I haven't used CLI before. It will take me a moment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 16:40:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39968#M29302</guid>
      <dc:creator>shank</dc:creator>
      <dc:date>2014-05-22T16:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN - Basic Questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39969#M29303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The screen comes up now, but, only after the following change of the GlobalProtect Gateway &amp;gt; Network Settings IP Address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;was: 12.13.14.15/32&lt;/P&gt;&lt;P&gt;now: 12.13.14.15/8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So 12. addresses can bring up the authentication screen in their browser....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;still confused...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 17:45:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-basic-questions/m-p/39969#M29303</guid>
      <dc:creator>shank</dc:creator>
      <dc:date>2014-05-22T17:45:01Z</dc:date>
    </item>
  </channel>
</rss>

