<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Updates across a Site to Site VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133820#M47265</link>
    <description>&lt;P&gt;Any chance that the WSUS server is using ports seen as https and that you have decryption configured? &amp;nbsp;I've had interesting issues with Windows Updates and decrytion in the past, both internally and external. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Also if you're using applciation-default in your ruleset, make sure that the ports are matching up to whats in the app-id that it's being identified as on the Palo Alto side.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Just some thoughts...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 20 Dec 2016 20:25:58 GMT</pubDate>
    <dc:creator>mlinsemier</dc:creator>
    <dc:date>2016-12-20T20:25:58Z</dc:date>
    <item>
      <title>Windows Updates across a Site to Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133298#M47193</link>
      <description>&lt;P&gt;I have a WSUS server.&amp;nbsp; I have a Site to Site VPN from a PA-3020 at a hosting facility to a Cisco ASA on my corporate network.&amp;nbsp; The PA-3020 is running 7.1.4.&amp;nbsp; When I try to run updates from the servers in the hosting facility, it shows as ms-update in the Traffic Log.&amp;nbsp; The Session End Reason is “tcp-rst-from-server”.&amp;nbsp; I am allowing all traffic on the tunnel and can web browse at port 80 and ping the WSUS server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there something else I need to do to allow Windows Updates across the tunnel?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 15:44:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133298#M47193</guid>
      <dc:creator>kdingwall</dc:creator>
      <dc:date>2016-12-16T15:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Updates across a Site to Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133306#M47194</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Logs suggests that the server is reseting the connection. Session is created so no problem here. PCAP might help a bit. Any deny logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 16:00:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133306#M47194</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-16T16:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Updates across a Site to Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133307#M47195</link>
      <description>&lt;P&gt;I am not getting any denies.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 16:03:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133307#M47195</guid>
      <dc:creator>kdingwall</dc:creator>
      <dc:date>2016-12-16T16:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Updates across a Site to Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133308#M47196</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did it ever work? Any threat profiles applied to the policy?ms-updates &amp;nbsp;depends on ssl but as you said you allowing any traffic so that is should not be an issue. Even more sssion is created. Clearly t&lt;SPAN&gt;he server sent a TCP reset to the client but why ....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thx,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Myky&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 16:46:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133308#M47196</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-16T16:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Updates across a Site to Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133319#M47199</link>
      <description>&lt;P&gt;I'm with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;, I don't think your issue is going to be the firewall here, it would more likely be something on the actual server that is blocking the traffic. Can you verify that traffic is allowed on the WSUS server and it isn't being stopped there.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 16:35:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133319#M47199</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-16T16:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Updates across a Site to Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133342#M47201</link>
      <description>&lt;P&gt;I added a binding to the default web page for 8020.&amp;nbsp; I can browse the server locally on that port, but get the same error trying to browse from a workstation on the remote network.&amp;nbsp; I can browse the WSUS server&amp;nbsp;on port 80 from the remote network.&amp;nbsp; I can ping it as well.&amp;nbsp; I have not setup any threat profiles yet.&amp;nbsp; I am going to install wireshark on the WSUS server.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 21:18:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133342#M47201</guid>
      <dc:creator>kdingwall</dc:creator>
      <dc:date>2016-12-16T21:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Updates across a Site to Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133570#M47239</link>
      <description>&lt;P&gt;I have not installed Wireshark yet.&amp;nbsp; I did stop the default website and bind port 80 to the WSUS site.&amp;nbsp; I was able to coonect to the WSUS server on port 80 from the remote servers.&amp;nbsp; I do not know why it does not work on 8530 yet.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2016 18:57:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133570#M47239</guid>
      <dc:creator>kdingwall</dc:creator>
      <dc:date>2016-12-19T18:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Updates across a Site to Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133820#M47265</link>
      <description>&lt;P&gt;Any chance that the WSUS server is using ports seen as https and that you have decryption configured? &amp;nbsp;I've had interesting issues with Windows Updates and decrytion in the past, both internally and external. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Also if you're using applciation-default in your ruleset, make sure that the ports are matching up to whats in the app-id that it's being identified as on the Palo Alto side.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Just some thoughts...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2016 20:25:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-updates-across-a-site-to-site-vpn/m-p/133820#M47265</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2016-12-20T20:25:58Z</dc:date>
    </item>
  </channel>
</rss>

