<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL VPN Problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-problem/m-p/49891#M36721</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check your "Application" for msrpc and netbios-ss in your Policy rules&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Sep 2013 16:10:16 GMT</pubDate>
    <dc:creator>Oleksandr</dc:creator>
    <dc:date>2013-09-30T16:10:16Z</dc:date>
    <item>
      <title>SSL VPN Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-problem/m-p/49889#M36719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured SSL VPN on my Palo Alto and it is working properly (e.g., internal websites, ssh, rdp, etc remotely) except accessing our corporate shared folder on our Windows server. However, this problem does not happen to our existing SSL VPN product that I am supposed to replace. Do I miss any steps or need additional configurations?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Peter Man&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 13:36:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-problem/m-p/49889#M36719</guid>
      <dc:creator>peterpan13888</dc:creator>
      <dc:date>2013-09-30T13:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-problem/m-p/49890#M36720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check your windows server's routing table and be sure traffic is coming back to paloalto so that clients can access from vpn.&lt;/P&gt;&lt;P&gt;you can debug with traceroute and packet capture&lt;/P&gt;&lt;P&gt;Also check if vpn user can send traffic to that server or not ?&lt;/P&gt;&lt;P&gt;can they access to other servers on the same zone ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 13:40:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-problem/m-p/49890#M36720</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-09-30T13:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-problem/m-p/49891#M36721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check your "Application" for msrpc and netbios-ss in your Policy rules&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 16:10:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-problem/m-p/49891#M36721</guid>
      <dc:creator>Oleksandr</dc:creator>
      <dc:date>2013-09-30T16:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-problem/m-p/49892#M36722</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need to verify if the application needed are being allowed in the security policy.&lt;/P&gt;&lt;P&gt;To further narrow down the issue you can use the following commands to debug the issue.&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;1. Need to setup the filters for the traffic we are interested in. To do this, execute the following steps:&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Navigate to Monitor--Packet Capture&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Click 'Manage Filters'&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Set Filter ID 1 to be the source IP and destination IP of traffic you feel is affected ( leave all other fields blank )&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Set Filter ID 2 to be the exact inverse of what you did in step 3 (destination IP in source field, Source IP in destination field)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;2. Setup up the captures&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Create and name the file stage for a packet capture on all the stages (receive, transmit, firewall and drop)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;3. Enable filters and captures &lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;debug dataplane packet-diag set filter on&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;debug dataplane packet-diag set capture on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;4. open 2 CLI windows&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;on 1 run the following command to look at the counter ( make sure it run this command once before running the traffic)&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;show counter global filter packet-filter yes delta yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;on the 2nd window run the following command to look at he sessions&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;show session all filter source &amp;lt;ip address&amp;gt; destination &amp;lt;ip address&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;After your test has been done stop all the captures and filters and see if global counter show you anything why it is dropping the traffic or if you have getting pcap with drop stage.&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;This will help you narrow down the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Let us know if this helps you resolve the issue.&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Thanks&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 17:10:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-problem/m-p/49892#M36722</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-09-30T17:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-problem/m-p/49893#M36723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think it is "any" application&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 21:22:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-problem/m-p/49893#M36723</guid>
      <dc:creator>peterpan13888</dc:creator>
      <dc:date>2013-10-07T21:22:13Z</dc:date>
    </item>
  </channel>
</rss>

