<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL VPN Configuration - HELP! in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-configuration-help/m-p/48132#M35394</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Marct,&lt;/P&gt;&lt;P&gt;if you are already able to get the client to connect and get an ip then the issue probably has to do with policy or routing.&lt;/P&gt;&lt;P&gt;Can you verify the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;make sure that the zone that the tunnel interface for the ssl vpn has policies/rules allowing the traffic to other desired zones&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;make sure that the ssl vpn tunnel interface is attached to a virtual router (this virtual router should also have interfaces facing the other subnets that you want the ssl vpn users to be able to connect to)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;make sure that the ip range or the subnet that you have assigned to the sslvpn users is not the same as any of the other subnets in your network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Stephen Whyte&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Jul 2010 15:18:18 GMT</pubDate>
    <dc:creator>swhyte</dc:creator>
    <dc:date>2010-07-16T15:18:18Z</dc:date>
    <item>
      <title>SSL VPN Configuration - HELP!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-configuration-help/m-p/48131#M35393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have been strugeling to get set up the SSL VPN on v3.1.3&lt;/P&gt;&lt;P&gt;I have managed to get the page to login appear&lt;/P&gt;&lt;P&gt;I have managed to be able to login&lt;/P&gt;&lt;P&gt;I have been able to dowload and get the client connect&lt;/P&gt;&lt;P&gt;but for some odd reason it will not communicate to the network !!! :smileyconfused:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have followed the article on the VPN connection on this site, I have also check the logs with a deny rule at the end of my policy to see if there is anything being denied which does not hit a rule and added in a rule accordingly to what I have seen from the logs but still nothing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would someone be able (who has got this running) to post a quick pictorial and sugestions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jul 2010 12:42:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-configuration-help/m-p/48131#M35393</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2010-07-16T12:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Configuration - HELP!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-configuration-help/m-p/48132#M35394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Marct,&lt;/P&gt;&lt;P&gt;if you are already able to get the client to connect and get an ip then the issue probably has to do with policy or routing.&lt;/P&gt;&lt;P&gt;Can you verify the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;make sure that the zone that the tunnel interface for the ssl vpn has policies/rules allowing the traffic to other desired zones&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;make sure that the ssl vpn tunnel interface is attached to a virtual router (this virtual router should also have interfaces facing the other subnets that you want the ssl vpn users to be able to connect to)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;make sure that the ip range or the subnet that you have assigned to the sslvpn users is not the same as any of the other subnets in your network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Stephen Whyte&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jul 2010 15:18:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-configuration-help/m-p/48132#M35394</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-07-16T15:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Configuration - HELP!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-configuration-help/m-p/48133#M35395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stephen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got the similar problem on configuring SSL VPN in PA. Actually, my network is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eth1/5 l3-untrust 10.0.0.0/8 network&lt;/P&gt;&lt;P&gt;Eth1/6 l3-trust 192.168.4.0/24 network&lt;/P&gt;&lt;P&gt;Tunnel l3-trust&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Those three interfaces are under the same virtual router with below routing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;default-route 0.0.0.0/0 int eth1/5 next_hop 10.1.1.254&lt;/P&gt;&lt;P&gt;tunnel traffic to corp 172.16.1.0/24 int tunnel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;172.16.4.0/24 is a SSL VPN portal client IP pool&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anything I missed? Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Johnny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jul 2010 09:55:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-configuration-help/m-p/48133#M35395</guid>
      <dc:creator>johnnywong</dc:creator>
      <dc:date>2010-07-19T09:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Configuration - HELP!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-configuration-help/m-p/48134#M35396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have already verified all of my previous suggestion, then you may want to start looking into other factors like the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;make sure that the device you are trying to reach does not have a firewall that is on or limiting connections to it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;make sure that the device you are trying to reach is routing back to the pan device when trying to get back to ssl vpn users.....in other words when your device tries to reach this network (172.16.1.0/24), it should routed back to pan device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jul 2010 20:52:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-configuration-help/m-p/48134#M35396</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-07-19T20:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Configuration - HELP!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-configuration-help/m-p/48135#M35397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you mean the device I want to reach have to add a routing table for SSLVPN pool (172.16.1.0/24) via 192.168.4.51? The source of the packet will use 172.16.1.x info?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW, I tested before but it seems cannot be done. I already added the routing table 172.16.1.0 to the device I want to go which is 192.168.4.61.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Johnny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Jul 2010 08:44:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-configuration-help/m-p/48135#M35397</guid>
      <dc:creator>johnnywong</dc:creator>
      <dc:date>2010-07-20T08:44:35Z</dc:date>
    </item>
  </channel>
</rss>

