<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem connecting SSH in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5257#M3868</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, its sending the trafiic to the interface1/22.250 and it should do it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@GOLIAT1(active)&amp;gt; test routing fib-lookup ip 10.98.200.16 virtual-router VR1 because the oowner of this ip is the PA. It shouldnt know the PA that it has this ip and not routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;runtime route lookup&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;virtual-router:&amp;nbsp;&amp;nbsp; VR1&lt;/P&gt;&lt;P&gt;destination:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.98.200.16&lt;/P&gt;&lt;P&gt;result:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; interface ethernet1/22.250&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@GOLIAT1(active)&amp;gt; show routing route destination 10.98.200.0/24 virtual-router VR1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;flags: A:active, ?:loose, C:connect, H:host, S:static, ~:internal, R:rip, O:ospf, B:bgp,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oi:ospf intra-area, Oo:ospf inter-area, O1:ospf ext-type-1, O2:ospf ext-type-2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VIRTUAL ROUTER: VR1 (id 2)&lt;/P&gt;&lt;P&gt;&amp;nbsp; ==========&lt;/P&gt;&lt;P&gt;destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nexthop&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; metric flags&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; age&amp;nbsp;&amp;nbsp; interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; next-AS&lt;/P&gt;&lt;P&gt;10.98.200.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.105.0.11&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A O2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1176268 ethernet1/22.250&lt;/P&gt;&lt;P&gt;total routes shown: 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Sep 2014 16:40:34 GMT</pubDate>
    <dc:creator>SOC_CSG</dc:creator>
    <dc:date>2014-09-16T16:40:34Z</dc:date>
    <item>
      <title>Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5251#M3862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a vpn configured (PA&amp;lt;-&amp;gt;PA) to manage my FWs.&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The problem is that when I open a ssh to the FW ip LAN (10.105.0.7), session ssh runs successfully and I can connect to the FW. But if I open ssh to the management ip 10.98.200.16 ssh remains frozen.&lt;/P&gt;&lt;P&gt;Looking at the log monitor, when i try the LAN ip i can see how the PA recognise the Application SSH, but trying with the management ip the FW is not recognising correctly and it shows INCOMPLETE.&lt;/P&gt;&lt;P&gt;Looking also at session browser when I run ssh session to the LAN ip, FW is not applying a Qos policy but is i try with management IP the FW is applying a Qos rule when it shouldnt do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why this strange behavior between ssh in LAN ip and management IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I attached all the tests.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="15574" alt="VPN rules.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15574_VPN rules.jpg" style="height: 76px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="15575" alt="MonitorLogVPN.jpg" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15575_MonitorLogVPN.jpg" style="height: 67px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="15576" alt="Session working.jpg" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/15576_Session working.jpg" style="height: 210px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="15577" alt="Session not working.jpg" class="jive-image image-3" src="https://live.paloaltonetworks.com/legacyfs/online/15577_Session not working.jpg" style="height: 215px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Qos rule.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15578_Qos rule.jpg" style="height: 106px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 14:24:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5251#M3862</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2014-09-16T14:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5252#M3863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Cos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Incomplete means that either the three way TCP handshake did NOT complete or the three way TCP handshake did complete but there was no data after the handshake to identify the application. In other words, that traffic you are seeing is not really an application.&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;So to explain a little clearer, if a client sends a server a &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;syn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; and the Palo Alto &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;device creates&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; a session for that &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;syn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;, but the server never sends a SYN ACK in response back to the client, then that session would be seen as incomplete.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE: From the above screenshot, it looks like, while you are trying to reach IP 10.98.200.16, only 78byte of data is being received at PAN FW. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 15:47:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5252#M3863</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-16T15:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5253#M3864</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Cos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;aslo&lt;/SPAN&gt; &lt;SPAN style="color: #3b3b3b; font-family: inherit; font-size: 10pt; line-height: 1.5em; font-weight: inherit; font-style: inherit;"&gt;check the real time session in the CLI by using 'show session all filter &lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: inherit; font-size: 10pt; line-height: 1.5em; font-weight: inherit; font-style: inherit;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: inherit; font-size: 10pt; line-height: 1.5em; font-weight: inherit; font-style: inherit;"&gt; IP_ADD_OF_THE_TESTING_PC&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;(&lt;/SPAN&gt;172.16.33.132)&amp;nbsp; destination IP_ADD_OF_THE_DESTINATION' &lt;SPAN style="color: #3b3b3b;"&gt;(&lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;10.98.200.16)&lt;/SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&amp;gt;&amp;nbsp; If there is &lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;a&lt;/SPAN&gt; session exist for the same traffic,&amp;nbsp; then please &lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;apply&amp;nbsp; CLI command PAN&amp;gt; show session id XYZ&amp;nbsp;&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; to get detailed information about that session, &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;i.e&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt; NAT rule, security rule, ingress/egress interface etc. I can see the session is not established here, that is why time out values shows only 5 seconds (pseudo session).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-size: 10pt; font-style: inherit; font-family: inherit; font-weight: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-size: 10pt; font-style: inherit; font-family: inherit; font-weight: inherit;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 15:54:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5253#M3864</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-16T15:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5254#M3865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, this is the result. Any idea???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="showsession.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15579_showsession.jpg" style="height: 114px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@GOLIAT1(active)&amp;gt; show session id 34480892&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Session&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 34480892&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; c2s flow:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; source:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.33.132 [VPN]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.98.200.16&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; proto:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sport:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 52478&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dport:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 22&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; INIT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FLOW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src user:&amp;nbsp;&amp;nbsp;&amp;nbsp; unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst user:&amp;nbsp;&amp;nbsp;&amp;nbsp; unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; qos node:&amp;nbsp;&amp;nbsp;&amp;nbsp; ethernet1/22.250, qos member N/A Qid 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; s2c flow:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; source:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.98.200.16 [TRANSITO]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.33.132&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; proto:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sport:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 22&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dport:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 52478&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; INIT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FLOW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src user:&amp;nbsp;&amp;nbsp;&amp;nbsp; unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst user:&amp;nbsp;&amp;nbsp;&amp;nbsp; unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; qos node:&amp;nbsp;&amp;nbsp;&amp;nbsp; tunnel.1, qos member N/A Qid 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; index(local):&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 182575&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; start time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Tue Sep 16 18:05:01 2014&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 5 sec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; total byte count(c2s)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 156&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; total byte count(s2c)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; layer7 packet count(c2s)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; layer7 packet count(s2c)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : vsys1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; application&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : incomplete&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rule&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Trafico VPN &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; session to be logged at end&amp;nbsp;&amp;nbsp; : True&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; session in session ager&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : False&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; session synced from HA peer&amp;nbsp;&amp;nbsp; : False&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; layer7 processing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL filtering enabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : False&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; session via syn-cookies&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : False&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; session terminated on host&amp;nbsp;&amp;nbsp;&amp;nbsp; : False&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; session traverses tunnel&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : True&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; captive portal session&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : False&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ingress interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : tunnel.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; egress interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : ethernet1/22.250&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; session QoS rule&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Capar-Jesus (class 4)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tracker stage firewall&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Aged out&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 16:07:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5254#M3865</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2014-09-16T16:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5255#M3866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello COS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Edited:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;total&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; byte count&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;(&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;c2s)&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; 156&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;total&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; byte count&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;(&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;s2c)&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; 0 &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; layer7 packet count&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;(&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;c2s)&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; 2&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; layer7 packet count&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;(&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;s2c)&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; 0 &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;You are trying to reach management IP of the PAN firewall&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;...&lt;/SPAN&gt;&lt;/SPAN&gt;right..? Could you please share the service route configuration and how you are expecting this traffic to be routed. &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;i&lt;/SPAN&gt; can see traffic coming from Tunnel.1 interface and going out through &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;ethernet1/22.250.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 16:18:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5255#M3866</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-16T16:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5256#M3867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I attached the service route config. I thought that to access by SSH you only needed to permit SSH in the Management interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ServiceRoute.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15580_ServiceRoute.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ServicerouteDestination.jpg" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15581_ServicerouteDestination.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 16:28:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5256#M3867</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2014-09-16T16:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5257#M3868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, its sending the trafiic to the interface1/22.250 and it should do it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@GOLIAT1(active)&amp;gt; test routing fib-lookup ip 10.98.200.16 virtual-router VR1 because the oowner of this ip is the PA. It shouldnt know the PA that it has this ip and not routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;runtime route lookup&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;virtual-router:&amp;nbsp;&amp;nbsp; VR1&lt;/P&gt;&lt;P&gt;destination:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.98.200.16&lt;/P&gt;&lt;P&gt;result:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; interface ethernet1/22.250&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@GOLIAT1(active)&amp;gt; show routing route destination 10.98.200.0/24 virtual-router VR1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;flags: A:active, ?:loose, C:connect, H:host, S:static, ~:internal, R:rip, O:ospf, B:bgp,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oi:ospf intra-area, Oo:ospf inter-area, O1:ospf ext-type-1, O2:ospf ext-type-2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VIRTUAL ROUTER: VR1 (id 2)&lt;/P&gt;&lt;P&gt;&amp;nbsp; ==========&lt;/P&gt;&lt;P&gt;destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nexthop&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; metric flags&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; age&amp;nbsp;&amp;nbsp; interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; next-AS&lt;/P&gt;&lt;P&gt;10.98.200.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.105.0.11&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A O2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1176268 ethernet1/22.250&lt;/P&gt;&lt;P&gt;total routes shown: 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 16:40:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5257#M3868</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2014-09-16T16:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5258#M3869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you are correct. But, how the PAN will forward this traffic to the management-interface, where no specific service (SSH) is is available on the service route&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; .&lt;/SPAN&gt; Could you please try to add a route there for destination IP &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;172.16.33.132 through &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;ethernet1/22.250 ( service route).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 16:54:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5258#M3869</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-16T16:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5259#M3870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;but the network 172.16.33.132 is reached through the tunnel. i think you mean destination 1&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;0.98.200.16 (management ip), but i think i will happen the same. Now its working like if i create the route that you want.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;admin@GOLIAT1(active)&amp;gt; test routing fib-lookup ip 10.98.200.16 virtual-router VR1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;runtime route lookup&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;virtual-router:&amp;nbsp;&amp;nbsp; VR1&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;destination:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.98.200.16&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;result:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; interface ethernet1/22.250&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 17:17:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5259#M3870</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2014-09-16T17:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5260#M3871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello COS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can think about an alternative option, according to this situation&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;/SPAN&gt;as a workaround).&lt;/P&gt;&lt;P&gt;&lt;IMG happy="" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have a layer-3 device which physically connected to the PAN FW's &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;dataplane&lt;/SPAN&gt;&lt;/SPAN&gt; interface and an another connection to the management interface, we can send the SSH traffic coming through the VPN to router R1 and R1 will re-route the traffic to the management interface of the PAN. &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;i&lt;/SPAN&gt;&lt;/SPAN&gt; have tested it in my PAN FW and it's working perfectly).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. &lt;SPAN __jive_emoticon_name="_happy.png'"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 17:46:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5260#M3871</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-16T17:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5261#M3872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi COS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From thread I understood two things.&lt;/P&gt;&lt;P&gt;1. Packets are flowing through Data Plane.&lt;/P&gt;&lt;P&gt;2. SYN Is coming to firewall but, SYN/ACK is not being sent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This conclude that, first packets are allowed and session is created. After that due to some reason packet is being dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this situation I would suggest you to do packet capture to check any drop packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer following document for the same.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2313"&gt;How to Run a Packet Capture&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once captures are configured execute following command.&lt;/P&gt;&lt;P&gt;show counter global filter packet-filter yes delta yes.&lt;/P&gt;&lt;P&gt;Again execute above command.&lt;/P&gt;&lt;P&gt;show counter global filter packet-filter yes delta yes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And provide us output for second command and let us know if you see any drops.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 17:59:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5261#M3872</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-16T17:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5262#M3873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi, i did several captures. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i try to open ssh to the management IP, i only can see the SYN, not SYN/ACK is generated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="wiresharkflow.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15583_wiresharkflow.jpg" style="height: 244px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i try to open ssh to the LAN IP, i oan see how SYN,SYN/ACK, and ACK are generated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="packet.jpg" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15587_packet.jpg" style="height: 25px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 18:43:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5262#M3873</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2014-09-16T18:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5263#M3874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi COS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most likely its following bellow pattern.&lt;/P&gt;&lt;P&gt;1. SYN comes from Data Plane and hits Management Interface.&lt;/P&gt;&lt;P&gt;2. Now Management interface has different default gateway and its sending SYN/ACK out of Management Interface. And not on Data plane.&lt;/P&gt;&lt;P&gt;3. To verify same do packet capture on Management interface.&lt;/P&gt;&lt;P&gt;tcpdump filter "host 172.16.33.132"&lt;/P&gt;&lt;P&gt;4. Then execute following command to view capture.&lt;/P&gt;&lt;P&gt; view-pcap mgmt-pcap mgmt.pcap&lt;/P&gt;&lt;P&gt;5. If you see SYN/ACK in above output, then its confirm routing issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this is helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regars,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 18:47:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5263#M3874</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-16T18:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5264#M3875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi COS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Long story short.&lt;/P&gt;&lt;P&gt;1. Login to CLI&lt;/P&gt;&lt;P&gt;2. put following command, its assumed source is 172.16.33.132.&lt;/P&gt;&lt;P&gt;tcpdump filter "host 172.16.33.132"&lt;/P&gt;&lt;P&gt;3. Execute Following command.&lt;/P&gt;&lt;P&gt;view-pcap mgmt-pcap mgmt.pcap&lt;/P&gt;&lt;P&gt;4. If you see SYN/ACK going out than its a assymetric routing issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following document will help for packet capture.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" data-containerid="2027" data-containertype="14" data-objectid="4595" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-4595"&gt;https://live.paloaltonetworks.com/docs/DOC-4595&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 18:51:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5264#M3875</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-16T18:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5265#M3876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If i use like filter 172.16.33.132 i cant see anything. I dont know what PA is doing with the traffic....&lt;/P&gt;&lt;P&gt;&lt;IMG alt="capturepcap.jpg" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15591_capturepcap.jpg" style="height: 156px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;If, for example, i use like filter 10.98.200.16, i see several connections.... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="pcap.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15590_pcap.jpg" style="height: 110px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 19:05:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5265#M3876</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2014-09-16T19:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5266#M3877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI COS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It&amp;nbsp; seems Management interface has not even seen SYN Packet. It proves SYN is dropped on Data plane.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you see any drop packet in capture, if NO than final thing is to do flow basics.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Follow bellow instructions for flow basics, if its not used with care than it can crash firewall. Let me know for any question.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1506"&gt;Packet Capture, Debug Flow-basic and Counter Commands&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 19:09:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5266#M3877</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-16T19:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5267#M3878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi COS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please verify if there are any set permitted IP addresses defined under management interface settings?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="permitted_ip.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15594_permitted_ip.JPG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And if the source IP from which you are doing SSH is in that permit IP address list ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 19:22:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5267#M3878</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-09-16T19:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5268#M3879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, the ip 172.16.33.132 is allowed.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="interfaces allowed.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15593_interfaces allowed.jpg" style="height: 311px; width: 620px;" /&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ill do this debug tomorrow. Please confirm this config (filter), it could crash using this short filter???? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;debug dataplane packet-diag set filter on&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;debug dataplane packet-diag set filter match source 172.16.33.132 destination 10.98.200.16&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;&lt;SPAN style="font-family: 'courier new', courier; color: #3b3b3b;"&gt;debug dataplane packet-diag set log feature flow basic&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier; color: #3b3b3b;"&gt;debug dataplane packet-diag set log on&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-size: 10pt; font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 19:28:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5268#M3879</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2014-09-16T19:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5269#M3880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi COS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt;NOTE: I strongly encourage to contact TAC for flow basics, unless you are confortable.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debug appears good to me. Make sure you disable logging once you try to access firewall. Use following command for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-style: inherit; font-weight: inherit; font-size: 10pt; line-height: 1.5em;"&gt;debug dataplane packet-diag set log off&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-style: inherit; font-weight: inherit; font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-style: inherit; font-weight: inherit; font-size: 10pt; line-height: 1.5em;"&gt;Following command to view output of flow basics.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-style: inherit; font-weight: inherit; font-size: 10pt; line-height: 1.5em;"&gt;less dp0-log pan_packet_diag.log &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-style: inherit; font-weight: inherit; font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-style: inherit; font-weight: inherit; font-size: 10pt; line-height: 1.5em;"&gt;Then following commands to disable everything&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set log off&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set filter off&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag clear log log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer following guide for details.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-style: inherit; font-weight: inherit; font-size: 10pt; line-height: 1.5em;"&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2542"&gt;Packet Based Troubleshooting - Configuring Packet Captures and Debug Logs&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 19:36:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5269#M3880</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-16T19:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: Problem connecting SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5270#M3881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello COS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only for routing info, &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;mgmt&lt;/SPAN&gt;&lt;/SPAN&gt; interface has the default gateway, but service route is for firewall services. For &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;mgmt&lt;/SPAN&gt;&lt;/SPAN&gt; access, the &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;mgmt&lt;/SPAN&gt;&lt;/SPAN&gt; interface will have to respond which will only happen if there is a default gateway. You have 2 options here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For example: Option-1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;If you want to keep Mgmt and physical interface in the same broadcast domain:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mgmt interface IP-1.1.1.1/24&lt;/P&gt;&lt;P&gt;Data-plane Ethernet interface IP- &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;1.1.1.2&lt;/SPAN&gt;&lt;/SPAN&gt;/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="15596" alt="SSH-service route-1.jpg" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15596_SSH-service route-1.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For example: Option-2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If you want to keep Mgmt and physical interface in 2 different broadcast domain:&lt;/P&gt;&lt;P&gt;Mgmt interface IP-2.2.2.1/24&amp;nbsp;&amp;nbsp; Default gateway- R1&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;(&lt;/SPAN&gt;&lt;/SPAN&gt;2.2.2.2)&lt;/P&gt;&lt;P&gt;Data-plane Ethernet interface IP- &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;1.1.1.2&lt;/SPAN&gt;&lt;/SPAN&gt;/24&amp;nbsp; Default gateway- R1 (1.1.1.2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="SSH-service route.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15597_SSH-service route.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2014 20:10:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-connecting-ssh/m-p/5270#M3881</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-16T20:10:31Z</dc:date>
    </item>
  </channel>
</rss>

