<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA blocks outbound port 10443, doesn't show up in logs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/77031#M42504</link>
    <description>&lt;P&gt;Are you logging everything? Find a rule that should allow or drop the mentioned traffic and see if it's set to logging.&lt;/P&gt;</description>
    <pubDate>Tue, 26 Apr 2016 06:54:53 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2016-04-26T06:54:53Z</dc:date>
    <item>
      <title>PA blocks outbound port 10443, doesn't show up in logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/76994#M42496</link>
      <description>&lt;P&gt;I have and external website that I need to access on port 10443: https://&amp;lt;public IP&amp;gt;:10443. The connection never completes and times out.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I pull the PA FW out and throw in an ASA, works just fine. The logs on PA don't even show port 10443 being accessed or logged.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No matter what log I check, I find nothing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 14:41:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/76994#M42496</guid>
      <dc:creator>dclark1</dc:creator>
      <dc:date>2016-04-25T14:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: PA blocks outbound port 10443, doesn't show up in logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/76996#M42497</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you tried running a packet capture &amp;amp; global counters to check for any drops/reasons for drops? Is there any asymmetric routing in your network?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How to run a capture -&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Run-a-Packet-Capture/ta-p/62390" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Run-a-Packet-Capture/ta-p/62390&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Global counters -&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Troubleshoot-Using-Counters-via-the-CLI/ta-p/57496" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Troubleshoot-Using-Counters-via-the-CLI/ta-p/57496&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps!&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 14:54:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/76996#M42497</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-04-25T14:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: PA blocks outbound port 10443, doesn't show up in logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/77005#M42499</link>
      <description>&lt;P&gt;What's PAN-OS version on firewall?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check the application and service tab. Try to make application as ssl and keep service as any. Check if works or not.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 20:06:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/77005#M42499</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-04-25T20:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: PA blocks outbound port 10443, doesn't show up in logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/77031#M42504</link>
      <description>&lt;P&gt;Are you logging everything? Find a rule that should allow or drop the mentioned traffic and see if it's set to logging.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2016 06:54:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/77031#M42504</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-04-26T06:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: PA blocks outbound port 10443, doesn't show up in logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/77032#M42505</link>
      <description>&lt;P&gt;Also make sure that your only drop rule isn't the implicit one: interzone-default. That rule doesn't log. I always make a default drop rule which logs above implicit rules.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2016 06:57:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/77032#M42505</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-04-26T06:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: PA blocks outbound port 10443, doesn't show up in logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/77048#M42511</link>
      <description>&lt;P&gt;Good idea on the drop rule. It's a very basic setup, and all rules log start and end of session. Capture logs show retransmissions, and traffic is getting to device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additionally another app that uses SSL over a non stanard port also did not work. Swapped PA with an ASA and both apps worked.....definatley something on the PA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;INFO:&lt;/P&gt;
&lt;P&gt;PA-VM-100&lt;/P&gt;
&lt;P&gt;Pan-OS: 7.1.1&lt;/P&gt;
&lt;P&gt;All other software up to date.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2016 12:07:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/77048#M42511</guid>
      <dc:creator>dclark1</dc:creator>
      <dc:date>2016-04-26T12:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: PA blocks outbound port 10443, doesn't show up in logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/77049#M42512</link>
      <description>&lt;P&gt;So did you find this traffic in logs? If all rules are set to logging then you must see it. If you still don't see it then it's dropped by implicit rule.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2016 12:43:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/77049#M42512</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-04-26T12:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: PA blocks outbound port 10443, doesn't show up in logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/77067#M42517</link>
      <description>&lt;P&gt;Good call santonic on the deny rule.....it was getting caught in the implict rule. Adjusted regular rule and all is good.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thx guys....&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2016 16:54:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/77067#M42517</guid>
      <dc:creator>dclark1</dc:creator>
      <dc:date>2016-04-26T16:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: PA blocks outbound port 10443, doesn't show up in logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/77183#M42536</link>
      <description>&lt;P&gt;No problem.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 06:04:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-blocks-outbound-port-10443-doesn-t-show-up-in-logs/m-p/77183#M42536</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-04-28T06:04:44Z</dc:date>
    </item>
  </channel>
</rss>

