<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ssh problem on mac os x in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139587#M48145</link>
    <description>&lt;P&gt;Agreed same time control&amp;nbsp;plane will get refreshed wich is also a good thing :0&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jan 2017 15:10:07 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-01-26T15:10:07Z</dc:date>
    <item>
      <title>ssh problem on mac os x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139484#M48121</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have such a weird problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A user has to connect to a samba server. He does it on his mac with cyberduck, Port 999 and ssh.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in the monitor, the application is "incomplete", the action is "allow", and session end reason is "aged-out".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently, the concerning firewall policy to this public server is any app and any service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the connection doesn't work. It can't connect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's the deal here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: It worked yesterday! So I think there is something wrong with the firewall (PA 3020).&lt;/P&gt;&lt;P&gt;I also restored the backup from yesterday, however, it doesn't work!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What can I do? Restart dataplane? Restart the whole device?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 07:44:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139484#M48121</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-01-26T07:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: ssh problem on mac os x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139491#M48122</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you ping a server from PA? Looks like TCP handshake is not complete. Any NAT in place? Check detailed traffic log reason and bytes received/sent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 07:41:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139491#M48122</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-01-26T07:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: ssh problem on mac os x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139493#M48123</link>
      <description>&lt;P&gt;Yes I can ping the public ip of the server. as source interface I used the gateway which the mac uses.&lt;/P&gt;&lt;P&gt;Yes, there is NAT in place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;detailed log view:&lt;/P&gt;&lt;P&gt;Bytes send: 640&lt;/P&gt;&lt;P&gt;Bytes received: 0&lt;/P&gt;&lt;P&gt;Repeat Count: 1&lt;/P&gt;&lt;P&gt;Packets: 8&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 07:50:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139493#M48123</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-01-26T07:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: ssh problem on mac os x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139495#M48124</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like you stealing an information:) Just post snip of your detailed session and NAT rule for the client (wipe sensitive info from logs). &amp;nbsp;What version&amp;nbsp;of PAN-OS you running?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 08:06:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139495#M48124</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-01-26T08:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: ssh problem on mac os x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139501#M48125</link>
      <description>&lt;P&gt;Hey Myky,&lt;/P&gt;&lt;P&gt;sorry.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA1.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7412i8BB89410F70BB054/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA1.JPG" alt="PA1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Security Rule:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA2.JPG" style="width: 532px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7414i75F9F7B33079A417/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA2.JPG" alt="PA2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT Rule is just a dynamic-ip-and-port Source Translation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN OS: 7.0.7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The weird thing is, this worked yesterday.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 08:17:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139501#M48125</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-01-26T08:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: ssh problem on mac os x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139514#M48126</link>
      <description>&lt;P&gt;Looks to me that the server is not responding to the ssh request&amp;nbsp;on port 999.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you try from the&amp;nbsp;cli&amp;nbsp;on Palo and do PCAP put the filter to the&amp;nbsp;server ip addrtess :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; ssh port 999 source (external ip) host (server ip)&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 08:52:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139514#M48126</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-01-26T08:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: ssh problem on mac os x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139523#M48128</link>
      <description>&lt;P&gt;Hi MPI-AE,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;does the&amp;nbsp;server listening to port 999 or is it 22 which is often used for ssh. As it worked before did you do nat as well ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Klaus&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 09:59:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139523#M48128</guid>
      <dc:creator>kdd</dc:creator>
      <dc:date>2017-01-26T09:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: ssh problem on mac os x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139548#M48133</link>
      <description>&lt;P&gt;You were right, our public NAT IP was blocked in the server's internal firewall.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: What effect does "Restart Dataplane" under Device -&amp;gt; Operations have?&lt;/P&gt;&lt;P&gt;When do I use it?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 11:02:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139548#M48133</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-01-26T11:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: ssh problem on mac os x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139553#M48135</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good point actually. As it was a silent drop (no RST or reject received by PA). Dataplane&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;should have an answer. l never use that option&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 12:41:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139553#M48135</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-01-26T12:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: ssh problem on mac os x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139570#M48137</link>
      <description>&lt;P&gt;The dataplane is what actually processes all of your traffic.&amp;nbsp;Restarting it would essentially temporarly stop traffic from being processed while the dataplane comes back up. You really only use it if you suspect that one of the processes isn't functioning correctly and need to restart it without actually restarting the box. It's quite a bit faster than restarting the whole thing as you only have to wait for 'half' the box to come back up. This graph might help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Palo-Alto-FW-Architecture.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7426i54B65DE042F5A019/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Palo-Alto-FW-Architecture.png" alt="Palo-Alto-FW-Architecture.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 13:59:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139570#M48137</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-01-26T13:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: ssh problem on mac os x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139574#M48140</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Pretty&amp;nbsp;good explanation l would say. I did play with management plane process restart where the&amp;nbsp;issues seen more often&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 14:06:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139574#M48140</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-01-26T14:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: ssh problem on mac os x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139578#M48144</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;&amp;nbsp;I would say that the majority of issues that people run into can be attributed to a management process and not a dataplane process. Really since restarting the dataplane is going to have an impact anyways most of the time if we do run into an issue that could be fixed with a dataplane restart we just restart the whole thing.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 14:18:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139578#M48144</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-01-26T14:18:24Z</dc:date>
    </item>
    <item>
      <title>Re: ssh problem on mac os x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139587#M48145</link>
      <description>&lt;P&gt;Agreed same time control&amp;nbsp;plane will get refreshed wich is also a good thing :0&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 15:10:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-problem-on-mac-os-x/m-p/139587#M48145</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-01-26T15:10:07Z</dc:date>
    </item>
  </channel>
</rss>

