<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Telegram website is not accessible in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134634#M47369</link>
    <description>&lt;P&gt;Hi TranceforLife,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You're correct! The firewall doesn't receive a SYN ACK packets when I checked the pcaps taken from firewall. Still its a weird issue cause its happening for only one website!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="telegram diagram.jpg" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7025iB2FE004661E672FE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="telegram diagram.jpg" alt="telegram diagram.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I performed fib lookup I got the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;btcuser@HO-PALOALTO-FW1(active)&amp;gt; test routing fib-lookup ip 149.154.167.99 virtual-router "Perimeter VR"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;runtime route lookup&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;virtual-router:&amp;nbsp;&amp;nbsp; Perimeter VR&lt;/P&gt;&lt;P&gt;destination:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 149.154.167.99 (Telegram website)&lt;/P&gt;&lt;P&gt;result:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;via 37.216.237.xx1 interface ethernet1/1, source 37.216.237.xx2, metric 10&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the internal gateway (Cisco router) IP address is 37.216.237.xx1&lt;/P&gt;&lt;P&gt;When we connect directly the gateway of the test PC will be Cisco router IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sharief&lt;/P&gt;</description>
    <pubDate>Tue, 27 Dec 2016 07:45:46 GMT</pubDate>
    <dc:creator>MohamedSharief</dc:creator>
    <dc:date>2016-12-27T07:45:46Z</dc:date>
    <item>
      <title>Telegram website is not accessible</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134522#M47353</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've one client that cannot access &lt;A href="https://telegram.org" target="_blank"&gt;https://telegram.org&lt;/A&gt; but he can access all other https website.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We tried to use a security rule with one source address and any any allow but still the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the traffic monitor we can observe the session end reason is aged-out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are not using any ssl decryption rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA telegramTraffic log.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7021i279925EA017B935E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PA telegramTraffic log.png" alt="PA telegramTraffic log.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA telegramTraffic log2.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7024i4234232422FA7780/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PA telegramTraffic log2.png" alt="PA telegramTraffic log2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sharief&lt;/P&gt;</description>
      <pubDate>Sun, 25 Dec 2016 14:03:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134522#M47353</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2016-12-25T14:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: Telegram website is not accessible</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134544#M47356</link>
      <description>&lt;P&gt;A session that is "incomplete" along with "aged-out" typically indicates a fundamental network routing problem between your client and the site in question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Not-Applicable-Incomplete-Insufficient-Data-in-the-Application/ta-p/65711" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Not-Applicable-Incomplete-Insufficient-Data-in-the-Application/ta-p/65711&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the most common issues with this would be asymmetrical routing for the path. &amp;nbsp;But basically the 3 way handshake is not completing or there is no data transmited through the PA after the handshake at all.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Dec 2016 13:42:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134544#M47356</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-12-25T13:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Telegram website is not accessible</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134545#M47357</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You are not getting anything back from the website or even not reaching it as 0 bytes received. Are you able to ping a website from the&amp;nbsp;firewall external (NAT IP 37....)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Sun, 25 Dec 2016 13:46:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134545#M47357</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-25T13:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: Telegram website is not accessible</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134546#M47358</link>
      <description>&lt;P&gt;Hi pulukas,&lt;/P&gt;&lt;P&gt;If I bypassed the firewall I can connect normally to &lt;A href="https://telegram.org" target="_blank"&gt;https://telegram.org&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The question is why the firewall is not able to complete the 3 way handshake?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi MyKy,&lt;/P&gt;&lt;P&gt;Tried that also but no echo reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sharief&lt;/P&gt;</description>
      <pubDate>Sun, 25 Dec 2016 14:00:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134546#M47358</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2016-12-25T14:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: Telegram website is not accessible</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134549#M47359</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't&amp;nbsp;think it is a firewall issue, as the firewall sends the packets but not receiving anything back. You could run a PCAP on the firewall to get more details and if you are actually getting SYN-ACK packets back:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Using-Packet-Filtering-through-the-WebGUI/ta-p/56363" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Using-Packet-Filtering-through-the-WebGUI/ta-p/56363&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do you get to that website&amp;nbsp;from the firewall (your routing l mean). When you bypassing the firewall what is you default gateway, same as on the PA box. Funny that this happens only for one destination.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Dec 2016 15:51:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134549#M47359</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-25T15:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: Telegram website is not accessible</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134634#M47369</link>
      <description>&lt;P&gt;Hi TranceforLife,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You're correct! The firewall doesn't receive a SYN ACK packets when I checked the pcaps taken from firewall. Still its a weird issue cause its happening for only one website!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="telegram diagram.jpg" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7025iB2FE004661E672FE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="telegram diagram.jpg" alt="telegram diagram.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I performed fib lookup I got the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;btcuser@HO-PALOALTO-FW1(active)&amp;gt; test routing fib-lookup ip 149.154.167.99 virtual-router "Perimeter VR"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;runtime route lookup&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;virtual-router:&amp;nbsp;&amp;nbsp; Perimeter VR&lt;/P&gt;&lt;P&gt;destination:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 149.154.167.99 (Telegram website)&lt;/P&gt;&lt;P&gt;result:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;via 37.216.237.xx1 interface ethernet1/1, source 37.216.237.xx2, metric 10&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the internal gateway (Cisco router) IP address is 37.216.237.xx1&lt;/P&gt;&lt;P&gt;When we connect directly the gateway of the test PC will be Cisco router IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sharief&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2016 07:45:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134634#M47369</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2016-12-27T07:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Telegram website is not accessible</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134636#M47370</link>
      <description>&lt;P&gt;When you bypass FW you have different source IP address? The telegraph.org server has your PA IP address on block list?&lt;/P&gt;&lt;P&gt;Sometimes a paranoid server or some other security device can block anIP if there are too many connections coming from it which would be the case with default NAT address.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2016 07:56:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134636#M47370</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-12-27T07:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: Telegram website is not accessible</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134641#M47372</link>
      <description>&lt;P&gt;Hi santonic,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really interesting point you have here mate. Let me check on this also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sharief&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2016 09:10:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134641#M47372</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2016-12-27T09:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: Telegram website is not accessible</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134649#M47375</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The client updates me that Telegram website is working now, without any changes in the configurations and that indicates the issue is not from firewall, maybe the router or ISP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyways, if the issue arises in the future we will do the following:&lt;/P&gt;&lt;P&gt;We will add an unused public IP address on outside interface and NAT the test machine with it and try accessing Telegram website to see if its working or not. This way we can find if it was really block by telegram or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sharief&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2016 13:14:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/telegram-website-is-not-accessible/m-p/134649#M47375</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2016-12-27T13:14:56Z</dc:date>
    </item>
  </channel>
</rss>

