<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I'm unable to use Remote desktop from internet to PC in Trust zone in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182012#M56126</link>
    <description>&lt;P&gt;from the cli.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ping source 10.126.125.1 host 10.126.123.132&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you get replies?&lt;/P&gt;</description>
    <pubDate>Mon, 16 Oct 2017 08:30:04 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2017-10-16T08:30:04Z</dc:date>
    <item>
      <title>I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/181952#M56108</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I wanna Remote desktop&amp;nbsp;from my PC in home to PC in my company but not success&lt;/P&gt;&lt;P&gt;This is my connection diagram&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled Diagram (1).jpg" style="width: 611px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11950i767AD97107F24E7D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Untitled Diagram (1).jpg" alt="Untitled Diagram (1).jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wanna remote to PC 10.126.123.132 (belong to VLAN 123,&amp;nbsp;I use several VLANs in Core switch)&amp;nbsp;but not success,&amp;nbsp;NAT seems not to work, there's no traffic logs&lt;/P&gt;&lt;P&gt;This is my config..&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Virtual router config." style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11951iC5BB50F4CB579570/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Virtual router config." /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Virtual router config.&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Security rules" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11952i580E235AEBFBC45B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.JPG" alt="Security rules" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Security rules&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT rule" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11953i4C7228CED3E6070F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3.JPG" alt="NAT rule" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;NAT rule&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can remote from internet to a server in DMZ zone successfully but L3_Trust zone, so I think because of using&amp;nbsp;VLAN in core switch, it requires some other config.. Please help me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;P/S:&amp;nbsp;The public IP in the pictures is just an example IP&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2017 14:16:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/181952#M56108</guid>
      <dc:creator>Hongson</dc:creator>
      <dc:date>2017-10-15T14:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/181964#M56109</link>
      <description>&lt;P&gt;In your nat rule try adding source nat 10.126.125.1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;your dmz may have a default route to the internet but maybe your vlans dont.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2017 19:12:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/181964#M56109</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-15T19:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/181965#M56110</link>
      <description>&lt;P&gt;take a packet capture on the firewall and the end client.&lt;/P&gt;&lt;P&gt;If you see the syn packet on the end client this would mean the packet is getting forwarded to the client.&lt;/P&gt;&lt;P&gt;Check if you recieve a syn-ack back on the firewall from the client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that is not the case then , check the routing on the switch. For testing in the nat rule that you have created for inbound, source nat the traffic to the trustzone interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Share the output of pcaps and session if this still does not resolve&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2017 19:35:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/181965#M56110</guid>
      <dc:creator>mgarg</dc:creator>
      <dc:date>2017-10-15T19:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/181976#M56119</link>
      <description>&lt;P&gt;Thank you all for your help, I added source translation to IP of L3_Trust interface (10.126.125.1) but still not success when Remote Desktop &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 405px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11955i83109CA4EDFD3615/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 02:06:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/181976#M56119</guid>
      <dc:creator>Hongson</dc:creator>
      <dc:date>2017-10-16T02:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/181978#M56120</link>
      <description>&lt;P&gt;at this point. take a pcap on firewall and client together. Share the details.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Provide the below details&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After trying rdp connection ,in the command line type&lt;/P&gt;&lt;P&gt;1) show session all filter source&amp;lt;your_public_src_ip&amp;gt; destination 113.160.131.230 destination-port 3389&lt;/P&gt;&lt;P&gt;this command will list the running sessions and the left most column is session id. Select a session id&lt;/P&gt;&lt;P&gt;2) show session id&amp;lt;session_id&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 02:37:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/181978#M56120</guid>
      <dc:creator>mgarg</dc:creator>
      <dc:date>2017-10-16T02:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/181991#M56121</link>
      <description>&lt;P&gt;Try modifying your source translation&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;address type = translated address&lt;/P&gt;&lt;P&gt;translated address = 10.126.125.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 06:06:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/181991#M56121</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-16T06:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182008#M56123</link>
      <description>&lt;P&gt;Thank you Sir, this is the picture of recive.pcap and drop.pcap, there's nothing in transmit.pcap and firewall.pcap. I'm sorry, due to security reason, I'm not allowed to upload capture file here&lt;/P&gt;&lt;P&gt;27.67.9.246 is my public IP from internet zone&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11958i2A8EC7FACCD49834/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.JPG" alt="1.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11959iCE89766C9913E30E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.JPG" alt="2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I also run command show session all filter source&amp;lt;your_public_src_ip&amp;gt; destination 113.160.131.230 destination-port 3389 but there's no active session&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 08:20:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182008#M56123</guid>
      <dc:creator>Hongson</dc:creator>
      <dc:date>2017-10-16T08:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182010#M56124</link>
      <description>&lt;P&gt;I change the source translate to "translated address" but it still not working&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.JPG" style="width: 688px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11960i96D51AF865AFA9F7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3.JPG" alt="3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 08:19:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182010#M56124</guid>
      <dc:creator>Hongson</dc:creator>
      <dc:date>2017-10-16T08:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182012#M56126</link>
      <description>&lt;P&gt;from the cli.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ping source 10.126.125.1 host 10.126.123.132&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you get replies?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 08:30:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182012#M56126</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-16T08:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182013#M56127</link>
      <description>&lt;P&gt;Yes sir, Ping successful&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 08:34:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182013#M56127</guid>
      <dc:creator>Hongson</dc:creator>
      <dc:date>2017-10-16T08:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182016#M56130</link>
      <description>&lt;P&gt;change your security policy/action/log settings to session start.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;attempt a connection and find connection attempt in monitor/traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you can see the session start then select magnifying glass on left column and post&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 08:56:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182016#M56130</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-16T08:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182017#M56131</link>
      <description>&lt;P&gt;I've already choosen both Log at session start and end before &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 09:07:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182017#M56131</guid>
      <dc:creator>Hongson</dc:creator>
      <dc:date>2017-10-16T09:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182018#M56132</link>
      <description>&lt;P&gt;in your security policy, should the destination address be 10.126.123.132 and not 113.160.131.230&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 09:16:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182018#M56132</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-16T09:16:27Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182019#M56133</link>
      <description>&lt;P&gt;I think it must be 113.160.131.230 but anyway, I tried changing it to 10.126.123.132 or any, it's not working &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 09:24:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182019#M56133</guid>
      <dc:creator>Hongson</dc:creator>
      <dc:date>2017-10-16T09:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182022#M56134</link>
      <description>&lt;P&gt;Of cource it wouldn't work...When using destination NAT, Security policy must contain &lt;STRONG&gt;PRE-NAT addresses &lt;/STRONG&gt;and &lt;STRONG&gt;POST-NAT zones&lt;/STRONG&gt;. Which means that your original configuration configuration is actually correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my humble opinion your original configuration was correct (correct NAT and correct security policy). There was suggestion to set source NAT and I saw you have enabled source and destination - I would say this is wrong... I believe the suggestion was to configure source static nat and enable bidirectional. That way you should accomplish the same think create static NAT. But you shouldn't enable both source and destination in the same rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the capture you can see that drop capture is filling with with the SYN, so&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my suggestion:&lt;/P&gt;&lt;P&gt;1. Put everything back as you configure it originally.&lt;/P&gt;&lt;P&gt;2. I saw that you are using service group RDP, can you confirm that this service group contain TCP port 3389?&lt;/P&gt;&lt;P&gt;3. Enable log on start for the security rule&lt;BR /&gt;4. Check traffic log for log matching your source address. send screenshot for this entry (you can hide the real addresses if you like)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 09:48:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182022#M56134</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2017-10-16T09:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182023#M56135</link>
      <description>&lt;P&gt;One more think - If you don't see logs for your attempts, please check if you have enabled log for default Intra and Inter zone security policy? If traffic doesn't match any explicit rule is probably being dropped by the default zone rules, and by default they are not logging.&lt;BR /&gt;&lt;BR /&gt;another you can check is&amp;nbsp; run test security-policy-match &amp;lt;fill in the rest&amp;gt; under the CLI&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 09:55:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182023#M56135</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2017-10-16T09:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182428#M56188</link>
      <description>&lt;P&gt;the reason there is no session on the firewall because i think it dropping the packet due to security rule . You can confirm this by creating a deny alll rule at the bottom and see if your traffic hits this rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The service object rdp that you have created, make sure you just put 3389 in destination port and leave the source port as blank and the protocol is tcp.&lt;/P&gt;&lt;P&gt;If this still does not work, open the rule to allow any service. For security just mention your public ip as source.&lt;/P&gt;&lt;P&gt;Check if you are still hitting the same rule or the default deny.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 00:35:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182428#M56188</guid>
      <dc:creator>mgarg</dc:creator>
      <dc:date>2017-10-18T00:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182445#M56191</link>
      <description>&lt;P&gt;Yes, I use a "Deny all" rule, I'm sure RDP service is correct with 3389 port 'cause I'm using it to remote to a server in DMZ zone. I create rule with permit access from my PC in internet to any zone and any address in internal network. But it's still not working and there's no any log except ping or telnet (but ping and telnet is not success and destination address is not NATed)&lt;/P&gt;&lt;P&gt;It seems hard to connect directly from internet to L3_trurst zone, so I'll use Globalprotect to setup VPN client to site.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 02:55:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182445#M56191</guid>
      <dc:creator>Hongson</dc:creator>
      <dc:date>2017-10-18T02:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182447#M56193</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I am having the same issue exaclty you facing now, All the while is working fine, The issue is onli happen i update the PA to 8.0.5, Are you using the same OS version.&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
      <pubDate>Wed, 18 Oct 2017 03:06:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182447#M56193</guid>
      <dc:creator>yihhow</dc:creator>
      <dc:date>2017-10-18T03:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: I'm unable to use Remote desktop from internet to PC in Trust zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182448#M56194</link>
      <description>&lt;P&gt;I'm using 6.1.16, I think it's not relate to PAN-OS version&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 03:08:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-m-unable-to-use-remote-desktop-from-internet-to-pc-in-trust/m-p/182448#M56194</guid>
      <dc:creator>Hongson</dc:creator>
      <dc:date>2017-10-18T03:08:40Z</dc:date>
    </item>
  </channel>
</rss>

