<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pc does not join into Domain in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45775#M33652</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello mikand,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my wireshark capture (done using port mirroring in the switch) any packet does not show bad checksum error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I disable offloading the packet hit the received stage and pass through firewall and users complete the pre-authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This case has appeared when I tried to change a Fortigate firewall with a PaloAlto. With Fortigate firewall the problem did not exists, like PaloAlto without offloading enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This facts let us think it is a PaloAlto issue on his session hardware acceleration but only on this client, because we are not able to reproduce the scenario.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Aug 2012 08:58:03 GMT</pubDate>
    <dc:creator>david_rivas1</dc:creator>
    <dc:date>2012-08-21T08:58:03Z</dc:date>
    <item>
      <title>Pc does not join into Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45763#M33640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can not join into a domain when the computer pass through PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my scennario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC - PaloAlto - Switch - DomainController&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PC and Domain controller are in the same Zone (trust) and I have a security rule: from zone trust, to zone trust, permit all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see a lot og kerberos v5 packet with bad checksum.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 11:04:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45763#M33640</guid>
      <dc:creator>david_rivas1</dc:creator>
      <dc:date>2012-06-01T11:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Pc does not join into Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45764#M33641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unless you have a deny all rule, you don't need a rule that specifies that from trust to trust is allowed. By default, any traffic staying in the same zone is allowed by the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the workstation in the same subnet as the domain controller?&lt;/P&gt;&lt;P&gt;Have you looked at logs for traffic originating from that source for a connection that could have been blocked? I would doubt it since it's same zone but it's good to check to be sure, there might be a block rule in your policy somewhere that blocks some of the connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would also consider NAT, can the PC reach the domain controller and vice versa.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 14:33:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45764#M33641</guid>
      <dc:creator>npare</dc:creator>
      <dc:date>2012-06-01T14:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Pc does not join into Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45765#M33642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If this is a fresh install you need to setup "deny + log" as last rule (traffic is denied by default as hidden last rule but that hidden rule doesnt log the blocked traffic).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 18:39:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45765#M33642</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-06-01T18:39:32Z</dc:date>
    </item>
    <item>
      <title>Re: Pc does not join into Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45766#M33643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a default block rule for log all traffic. I do not see any block between trust and trust zone. I can see ldap and kerberos application allowed. Also I can see ldap acctive sessions in the Session log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured the permit rule from/to trust zone. The Pc and DC are not in the same network, they are connected through layer 3 routing with static routes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the past I had troubles with multicast, this traffic was not displayed on traffic logs. I thank join into windows 2008 domain could use multicast traffic but I did not see it on the sniffed traffic on PC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 20:31:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45766#M33643</guid>
      <dc:creator>david_rivas1</dc:creator>
      <dc:date>2012-06-01T20:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: Pc does not join into Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45767#M33644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have mount a lab (DC - PaloAlto - Client), both on same zone and I got the same error. I tried without a explicit block roule and I tried with PanOS 4.0 and 4.1 with no success.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We finally decide to open a case to PaloAlto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2012 16:26:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45767#M33644</guid>
      <dc:creator>david_rivas1</dc:creator>
      <dc:date>2012-06-06T16:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: Pc does not join into Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45768#M33645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have done a packet capture and I see netbios packets dropped.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2012 15:23:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45768#M33645</guid>
      <dc:creator>david_rivas1</dc:creator>
      <dc:date>2012-06-12T15:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: Pc does not join into Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45769#M33646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;disabling session offload, the packets are cached by PaloAlto device.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2012 11:45:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45769#M33646</guid>
      <dc:creator>david_rivas1</dc:creator>
      <dc:date>2012-08-09T11:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Pc does not join into Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45770#M33647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you mean by that the are cached by the PA device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Session offloading is as far as I understand a way to optimize resources of the FPGA/ASIC in the PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you disabled session offloading I assume this is done globally, did you notice any other behaviour changes when you did this (performance decrease or such)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Aug 2012 22:14:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45770#M33647</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-08-20T22:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: Pc does not join into Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45771#M33648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would mean, when I do a packet capture I do not see the kerberos pre-authentication packet, and If I do a port mirroring on the switch where is connected the PA or disabiling session offloading and lookin packet capture again, then I can see the kerberos pre-authentication packet.&lt;/P&gt;&lt;P&gt;I have a case opened in PaloAlto support to solve this problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Aug 2012 06:52:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45771#M33648</guid>
      <dc:creator>david_rivas1</dc:creator>
      <dc:date>2012-08-21T06:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: Pc does not join into Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45772#M33649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please keep us updated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To me it sounds like this preauth packet somehow is incorrectly dropped (didnt match any allow policy).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If possible, will it be dropped even if you use appid:any and service:any between the two ip addresses?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Aug 2012 07:41:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45772#M33649</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-08-21T07:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Pc does not join into Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45773#M33650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The packet is not dropped because when you use packet capture, you can choose different stages. If it was dropped it shoud appear in drop stage, and even if it is dropped or not it should appear on received stage and it does not appears in any stage. It only appears in received stage when I use no session offline.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PaloAlto has a permit any any any ... and both sides of traffic are in the same security zone. Also multicast is allowed (but it is not a multicast traffic).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This case is only happening in one scenario. We tryed to reproduce it in a lab and we have not this problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Aug 2012 08:19:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45773#M33650</guid>
      <dc:creator>david_rivas1</dc:creator>
      <dc:date>2012-08-21T08:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Pc does not join into Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45774#M33651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since its not reproducable, could it be that the packet have bad checksum or something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which with offloading would drop the packet straight away but with offloading disabled would hit the received stage (and then being discarded)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Aug 2012 08:38:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45774#M33651</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-08-21T08:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Pc does not join into Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45775#M33652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello mikand,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my wireshark capture (done using port mirroring in the switch) any packet does not show bad checksum error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I disable offloading the packet hit the received stage and pass through firewall and users complete the pre-authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This case has appeared when I tried to change a Fortigate firewall with a PaloAlto. With Fortigate firewall the problem did not exists, like PaloAlto without offloading enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This facts let us think it is a PaloAlto issue on his session hardware acceleration but only on this client, because we are not able to reproduce the scenario.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Aug 2012 08:58:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/45775#M33652</guid>
      <dc:creator>david_rivas1</dc:creator>
      <dc:date>2012-08-21T08:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Pc does not join into Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/430266#M94989</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also experienced the same issue, do we have already solution on this one?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 03:11:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pc-does-not-join-into-domain/m-p/430266#M94989</guid>
      <dc:creator>ftbaraoidan</dc:creator>
      <dc:date>2021-08-31T03:11:40Z</dc:date>
    </item>
  </channel>
</rss>

