<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to access a site, please try for me in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/80048#M43269</link>
    <description>&lt;P&gt;Obviously i defined 3 rules for my pc originating IP at the top to exit anywhere, to not decrypt, to not captive portal&lt;/P&gt;
&lt;P&gt;I have PAN OS 7.1.2&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Jun 2016 15:45:58 GMT</pubDate>
    <dc:creator>nicolap</dc:creator>
    <dc:date>2016-06-08T15:45:58Z</dc:date>
    <item>
      <title>Unable to access a site, please try for me</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/79812#M43258</link>
      <description>&lt;P&gt;I am unable to access this site in any way throuth my PA 3020 With Pan Os 7.1&lt;BR /&gt;Obviously is possible through&amp;nbsp;a direct connection&lt;BR /&gt;Can someone try and temm me if is the same ?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.spcconnect.com/" target="_blank"&gt;https://www.spcconnect.com/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2016 12:33:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/79812#M43258</guid>
      <dc:creator>nicolap</dc:creator>
      <dc:date>2016-06-08T12:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access a site, please try for me</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/79814#M43259</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Able:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="able.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4337i270A3B747DE782E6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="able.PNG" alt="able.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2016 12:34:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/79814#M43259</guid>
      <dc:creator>Transporter</dc:creator>
      <dc:date>2016-06-08T12:34:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access a site, please try for me</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/80036#M43268</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The site seems to be using TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Support for this suite was added in PAN-OS 7.1 :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please check the following article :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Articles/PAN-OS-7-1-Supported-ciphers/ta-p/71969" target="_blank"&gt;PAN-OS-7-1-Supported-ciphers&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Seeing that you are already using 7.1 ... are you using SSL decryption ? Have you tried disabling it for the site as a test ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Cheers.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2016 15:40:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/80036#M43268</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2016-06-08T15:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access a site, please try for me</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/80048#M43269</link>
      <description>&lt;P&gt;Obviously i defined 3 rules for my pc originating IP at the top to exit anywhere, to not decrypt, to not captive portal&lt;/P&gt;
&lt;P&gt;I have PAN OS 7.1.2&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2016 15:45:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/80048#M43269</guid>
      <dc:creator>nicolap</dc:creator>
      <dc:date>2016-06-08T15:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access a site, please try for me</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/80077#M43270</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you try to do PCAP on the Palo and client site?&lt;/P&gt;
&lt;P&gt;What error do you get on the screen when trying to access this particular site. Did you try with different a web browser?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2016 16:15:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/80077#M43270</guid>
      <dc:creator>Transporter</dc:creator>
      <dc:date>2016-06-08T16:15:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access a site, please try for me</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/80078#M43271</link>
      <description>&lt;P&gt;I'd recommend setting up a filter with your originating IP address and check the global counters for drops. &amp;nbsp;I'm guessing you will find some counters that could explain the behaviour :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Troubleshoot-Using-Counters-via-the-CLI/ta-p/57496" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Troubleshoot-Using-Counters-via-the-CLI/ta-p/57496&lt;/A&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2016 16:15:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/80078#M43271</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2016-06-08T16:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access a site, please try for me</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/80093#M43272</link>
      <description>&lt;P&gt;A strange thing&lt;/P&gt;
&lt;P&gt;I have a Policy Forwarding that for some LAN ip outbound traffic doesnt go via WAN interface but is sent to a machine connected in DMZ and that machine is connected to internet with a software firewall&lt;/P&gt;
&lt;P&gt;These routed machines can access this site normally&lt;/P&gt;
&lt;P&gt;Only machines that goes out through palo alto doesnt work&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2016 16:20:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/80093#M43272</guid>
      <dc:creator>nicolap</dc:creator>
      <dc:date>2016-06-08T16:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access a site, please try for me</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/80102#M43273</link>
      <description>&lt;P&gt;First image in log of conversation sending to machine in dmz that works&lt;/P&gt;
&lt;P&gt;Se second is using PA WAN that dont work&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4347i3B6559B601FE5003/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4348i48CE0D0A67B3CF42/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.PNG" alt="2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15933"&gt;@nicolap&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;I am unable to access this site in any way throuth my PA 3020 With Pan Os 7.1&lt;BR /&gt;Obviously is possible through&amp;nbsp;a direct connection&lt;BR /&gt;Can someone try and temm me if is the same ?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.spcconnect.com/" target="_blank"&gt;https://www.spcconnect.com/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2016 16:32:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/80102#M43273</guid>
      <dc:creator>nicolap</dc:creator>
      <dc:date>2016-06-08T16:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access a site, please try for me</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/81014#M43283</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The application in the non-working scenario is 'incomplete'.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-search-match-lithium"&gt;Incomplete&lt;/SPAN&gt; means that either the three-way TCP handshake did &lt;STRONG&gt;not&lt;/STRONG&gt; complete or the three-way TCP handshake did complete but there was no data after the handshake to identify the &lt;SPAN class="lia-search-match-lithium"&gt;application&lt;/SPAN&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example, if a client sends a server a syn and the Palo Alto Networks device creates a session for that syn, but the server never sends a SYN ACK back to the client, then that session is &lt;SPAN class="lia-search-match-lithium"&gt;incomplete&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd recommend to take PCAPs to confirm traffic is leaving the firewall on the correct egress interface and also take PCAPs on the destination server to verify if the packet reaches it and is&amp;nbsp;returned correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2016 07:03:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/81014#M43283</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2016-06-09T07:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access a site, please try for me</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/81262#M43293</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also try to run just simple ping from Palo&amp;nbsp;to the client and the web-site. Also source ping from the appropriate egress interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2016 10:14:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/81262#M43293</guid>
      <dc:creator>Transporter</dc:creator>
      <dc:date>2016-06-09T10:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access a site, please try for me</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/85951#M43397</link>
      <description>&lt;P&gt;It was very difficuolt to solve&lt;BR /&gt;I changed WAN IP of my PA and it works, i suppose that the website have banned my source ip, at now i am asking why&lt;/P&gt;
&lt;P&gt;thx&lt;/P&gt;
&lt;P&gt;Nicola&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 14:41:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-access-a-site-please-try-for-me/m-p/85951#M43397</guid>
      <dc:creator>nicolap</dc:creator>
      <dc:date>2016-06-14T14:41:46Z</dc:date>
    </item>
  </channel>
</rss>

