<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue With GlobalProtect VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/103259#M44613</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone please point me at the right direction?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2 PA-500 devices are in active-passive configuration.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;When connected via global connect, getting IP address in the correct range but&amp;nbsp;cannot reach any internal address and trace route does not proceed beyond the first hop of&amp;nbsp;the gateway on the Firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, from a PC behind the firewall on the network, we can ping the GlobalProtect PC connected over the internet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Farzana&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Aug 2016 05:08:09 GMT</pubDate>
    <dc:creator>Farzana</dc:creator>
    <dc:date>2016-08-16T05:08:09Z</dc:date>
    <item>
      <title>Issue With GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/103259#M44613</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone please point me at the right direction?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2 PA-500 devices are in active-passive configuration.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;When connected via global connect, getting IP address in the correct range but&amp;nbsp;cannot reach any internal address and trace route does not proceed beyond the first hop of&amp;nbsp;the gateway on the Firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, from a PC behind the firewall on the network, we can ping the GlobalProtect PC connected over the internet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Farzana&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 05:08:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/103259#M44613</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2016-08-16T05:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/103376#M44615</link>
      <description>&lt;P&gt;Hi Farzana&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;are you seeing any packets being blocked in the traffic log? Did you make sure to create a security policy that will allow sessions from the GP gateway zone (the zone attached to the interface the GP clients connect to) to the trusted zone?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in the GP gateway settings, did you happen to set an access route? if so, can you verify the subnet is accurate ?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 09:37:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/103376#M44615</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-08-16T09:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/103685#M44645</link>
      <description>&lt;P&gt;Hello Reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for taking your time out and replying.&lt;/P&gt;&lt;P&gt;In the traffic log, I can see packets sent=packets received...only season end reason showing aged-out.&lt;/P&gt;&lt;P&gt;Security policy is allowed from LAN (interface tunnel1) to LAN (interface Eth1/4).&lt;/P&gt;&lt;P&gt;GP gateway settings has access route setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Configs | User/User group | OS | IP pool | &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Access Route&lt;/P&gt;&lt;P&gt;-------- &amp;nbsp; &amp;nbsp;------------------- &amp;nbsp; &amp;nbsp;--- &amp;nbsp; &amp;nbsp;-------- &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;----------------&lt;/P&gt;&lt;P&gt;Default &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Any &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Any &amp;nbsp;10.20.30.0/24 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.1.0/24&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.2.0/24&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.10.0/24&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.100.0/24&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.101.0/24&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 00:03:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/103685#M44645</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2016-08-17T00:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/103794#M44649</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="routingtable.jpg" style="width: 711px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5209iFA698179B26FDFDC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="routingtable.jpg" alt="routingtable.jpg" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="forwardingtable.jpg" style="width: 711px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5210iE4B1A2DAAB4AF0E4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="forwardingtable.jpg" alt="forwardingtable.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 04:00:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/103794#M44649</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2016-08-17T04:00:00Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/103876#M44654</link>
      <description>&lt;P&gt;Hi Farzana&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;session end reason aged-out means the session came to a natural end, which means it went as expected&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you create a security policy from LAN to LAN zone ? (i would recommend changing the zone of the GP tunnel interface so you have more control over what goes in and out of the tunnel)&lt;/P&gt;
&lt;P&gt;Due to both interfaces being in the same zone, you may be missing some logs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you make sure the GP Client Network settings contain the appropriate access routes to reach all of your subnets (or is left empty for a 0.0.0.0/0 default route into the tunnel)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2016-08-17_11-27-50.jpg"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/5DE745A4213343D2E26844B0146B285E/responsive_peak/images/image_not_found.png" alt="2016-08-17_11-27-50.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 09:29:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/103876#M44654</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-08-17T09:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/103893#M44656</link>
      <description>&lt;P&gt;Hi Reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i don't think aged-out is the naturall way of seeion end,&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Aged out&lt;/STRONG&gt; - Occurs when a session closes due to aging out&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I'm sorry if i'm worng,&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 12:50:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/103893#M44656</guid>
      <dc:creator>KotreshaMC</dc:creator>
      <dc:date>2016-08-17T12:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/103919#M44658</link>
      <description>&lt;P&gt;hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you are right! i wanted to argue that the session end would be 'unknown' but aged-out works just as well for a half open session&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so please disregard that comment until you have verified the bytes sent and bytes received&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if both are populated with plenty of bytes, the aged-out simply means both sides stopped sending packets without forcibly terminating the session by FIN or RST, if you see bytes sent but none received, there is likely a problem with returning packets (routing, NAT, ...)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;sorry for the confusion&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 13:21:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/103919#M44658</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-08-17T13:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/105914#M44772</link>
      <description>&lt;P&gt;Was going to say something similar. Does your internal network have a route for&amp;nbsp;&lt;SPAN&gt;10.20.30.0/24 for the returning packets?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2016 08:12:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/105914#M44772</guid>
      <dc:creator>aceandy79</dc:creator>
      <dc:date>2016-08-23T08:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/106288#M44794</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for taking your time out and replying. I had to log a support call for this and TAC engineer solved the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the Traffic monitor logs, we ran show session id. It showed the session was using pbf rule: No_PBF_rule which had 'Enforce Symmetric Return' ticked. Once it was disabled, issue was fixed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Farzana&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2016 23:13:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/106288#M44794</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2016-08-23T23:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/107984#M44925</link>
      <description>&lt;P&gt;This is a fine temporary solution. &amp;nbsp;But this solution is showing you that the previous comments about asymmetrical routing in your network here are correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The best permanent solution is to identify how to get the return traffic from these internal hosts to use the same path that the outbound traffic from the vpn hosts are using to reach those hosts. &amp;nbsp;As noted above this is likely a missing route somewhere.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or it could be the need to create a routed link into the internal zone instead of connecting multiple routers to the same subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA firewalls can best protect against threats only when they see the full flow of the traffic both inbound and outbound in a symetrical routing setup. &amp;nbsp;This is why the default behavior is the block asymmetrical flows to help you see that this path is not optimal and can allow some threats to go undetected.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Aug 2016 12:22:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-globalprotect-vpn/m-p/107984#M44925</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-08-27T12:22:57Z</dc:date>
    </item>
  </channel>
</rss>

