<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISSUE WITH GLOBAL PROTECT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-global-protect/m-p/51784#M38096</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN lang="EN-US" style="font-weight: inherit; font-style: inherit; font-family: Arial, sans-serif;"&gt;We cannot access to the LAN of the PA-500 .......... from where? Please add more details&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN lang="EN-US" style="font-weight: inherit; font-style: inherit; font-family: Arial, sans-serif;"&gt;We cannot access to Internet using the PA-500............. again, access the Internet?&amp;nbsp; I guess you mean from the LAN, but using which ISP?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN lang="EN-US" style="font-weight: inherit; font-style: inherit; font-family: Arial, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN lang="EN-US" style="font-weight: inherit; font-style: inherit; font-family: Arial, sans-serif;"&gt;I believe you might be running into some asymmetric routing issue because of the different ISPs that you have configured. I could suggest segregating them by using different virtual routers, but you need to make sure you have the proper routes in place in each of the VRs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN lang="EN-US" style="font-weight: inherit; font-style: inherit; font-family: Arial, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Mar 2015 14:12:08 GMT</pubDate>
    <dc:creator>parmas</dc:creator>
    <dc:date>2015-03-10T14:12:08Z</dc:date>
    <item>
      <title>ISSUE WITH GLOBAL PROTECT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-global-protect/m-p/51783#M38095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;We have configured One VR-1 only&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;Ethernet 1/1 is a WAN interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;Ethernet 1/2 is a WAN interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;Ethernet 1/3 is a WAN interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;Ethernet 1/4 is a LAN interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;We’ve created &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;ETH1-ZONE for Ethernet 1/1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;ETH2-ZONE for Ethernet 1/2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;ETH3-ZONE for Ethernet 1/3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;ETH4-ZONE for Ethernet 1/4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;VP –ZONE for all the tunnels (used for remote connection site with site-1 and site-2)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;GP-ZONE used for GLOBAL PROTECT&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;STATIC ROUTE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;We’ve a set of static&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;LAN to ETH1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;LAN to ETH2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;LAN to ETH3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;LAN to LAN&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;And VPN route using tunnels&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;POLICIES&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;We’ve setted up a bunch of policies&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;LAN to WAN1 (ISP1) for Tunnel traffic and VPN traffic&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;LAN to WAN2 (ISP2) for Webmail&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;LAN to WAN3 (For Web browsing)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;We’ve created a PBF for forwading traffic from LAN to Ethernet 1/2 when it is about MAIL/WebMAIL activities&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;We’ve an application override to force FTP application goes to LAN to LAN (through the MPLS network) due to asymmetric issues&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;We've a Laptop which is connecte outside the office, and we&amp;nbsp; setup a connection through the PALO ALTO using GLOBAL PROTECT, the connection is established using ISP1.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;The VPN for Global Protect is UP and RUNNING&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;The issue is the following&lt;/STRONG&gt;&lt;/SPAN&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;We cannot access to the LAN of the PA-500&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;We cannot access to Internet using the PA-500&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;&lt;STRONG&gt;BUT&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;We can connect to remote-site-1; Remote-2 and last but not the least we can connect to the remote site which located accross the MPLS network.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;Does anyone has an idea or some guidance about this issue? Have we missed something? Could it be possible that the configuration is wrong?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: 'Arial',sans-serif;"&gt;&lt;IMG __jive_id="18625" alt="FIGURE1.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/18625_FIGURE1.PNG" style="height: 773px; width: 620px;" /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Mar 2015 09:20:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-global-protect/m-p/51783#M38095</guid>
      <dc:creator>mbeghdadi</dc:creator>
      <dc:date>2015-03-10T09:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISSUE WITH GLOBAL PROTECT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-global-protect/m-p/51784#M38096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN lang="EN-US" style="font-weight: inherit; font-style: inherit; font-family: Arial, sans-serif;"&gt;We cannot access to the LAN of the PA-500 .......... from where? Please add more details&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN lang="EN-US" style="font-weight: inherit; font-style: inherit; font-family: Arial, sans-serif;"&gt;We cannot access to Internet using the PA-500............. again, access the Internet?&amp;nbsp; I guess you mean from the LAN, but using which ISP?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN lang="EN-US" style="font-weight: inherit; font-style: inherit; font-family: Arial, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN lang="EN-US" style="font-weight: inherit; font-style: inherit; font-family: Arial, sans-serif;"&gt;I believe you might be running into some asymmetric routing issue because of the different ISPs that you have configured. I could suggest segregating them by using different virtual routers, but you need to make sure you have the proper routes in place in each of the VRs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN lang="EN-US" style="font-weight: inherit; font-style: inherit; font-family: Arial, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Mar 2015 14:12:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-global-protect/m-p/51784#M38096</guid>
      <dc:creator>parmas</dc:creator>
      <dc:date>2015-03-10T14:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISSUE WITH GLOBAL PROTECT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-global-protect/m-p/51785#M38097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your feedback, after investigation the issue was related to PFB..It was necessary to write a new rule stating that&lt;/P&gt;&lt;P&gt;trafi from LAN to GP (global protect Zone) should not use PBF...&lt;/P&gt;&lt;P&gt;After the commit, trafic is UP...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Mar 2015 14:48:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-global-protect/m-p/51785#M38097</guid>
      <dc:creator>mbeghdadi</dc:creator>
      <dc:date>2015-03-10T14:48:03Z</dc:date>
    </item>
  </channel>
</rss>

