<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clientless VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/clientless-vpn/m-p/183626#M56417</link>
    <description>&lt;P&gt;Have you tasted that on PAN-OS 8.0.5?&lt;/P&gt;</description>
    <pubDate>Wed, 25 Oct 2017 13:02:28 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2017-10-25T13:02:28Z</dc:date>
    <item>
      <title>Clientless VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clientless-vpn/m-p/171634#M54250</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can someone provide configuration example for Clientless VPN access through GP portal...&lt;BR /&gt;I was already used configuration steps explained on this &lt;A href="https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-clientless-vpn/configure-clientless-vpn" target="_self"&gt;page&lt;/A&gt;, but seem that it not helped in my case. I'm able to authenticate and open portal landing page with published app, but there is no response of it. I'm pretty sure that all steps of configuration is by the book, but I'm not sure about step 10 where have to create security rules... With my opinion it is a bit grayed and confused, how exactly policies has to be created.&lt;BR /&gt;If someone have this operational, it could be very appriciated to share configuration with us...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S. I used troubleshooting procedure provided &lt;A href="https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-clientless-vpn/troubleshoot-clientless-vpn" target="_self"&gt;here&lt;/A&gt; and after generated logs and pcap's, only strange I can find is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cannot de-NAT v4 packet, no port match&lt;/P&gt;&lt;P&gt;== 2017-08-15 10:49:11.393 +0200 ==&lt;BR /&gt;Packet received at ingress stage, tag 262143, type ORDERED&lt;BR /&gt;Packet info: len 91 port 16 interface 256 vsys 1&lt;BR /&gt;wqe index 229186 packet 0x0x800000041da465c2, HA: 0&lt;BR /&gt;Packet decoded dump:&lt;BR /&gt;L2: 00:1b:17:4c:8f:10-&amp;gt;00:70:76:69:66:00, type 0x0800&lt;BR /&gt;IP: 89.x.x.x (portal public IP)-&amp;gt;10.x.x.x(dns internal) , protocol 17&lt;BR /&gt;version 4, ihl 5, tos 0x00, len 73,&lt;BR /&gt;id 44114, frag_off 0x4000, ttl 64, checksum 63738(0xf8fa)&lt;BR /&gt;UDP: sport 54788, dport 53,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like that portal ask internal dns (DNS proxy) for resolution of published url app, but has this "de-NAT port not match" issue. Seem that packet flow after establishing initial vpn connection to portal, enforce NAT policy stage.... &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PANOS 8.0.4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 12:30:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clientless-vpn/m-p/171634#M54250</guid>
      <dc:creator>Tician</dc:creator>
      <dc:date>2017-08-15T12:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: Clientless VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clientless-vpn/m-p/183626#M56417</link>
      <description>&lt;P&gt;Have you tasted that on PAN-OS 8.0.5?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2017 13:02:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clientless-vpn/m-p/183626#M56417</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2017-10-25T13:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: Clientless VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clientless-vpn/m-p/183647#M56427</link>
      <description>&lt;P&gt;no, but I'll try this days and post results...&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2017 14:22:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clientless-vpn/m-p/183647#M56427</guid>
      <dc:creator>Tician</dc:creator>
      <dc:date>2017-10-25T14:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: Clientless VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clientless-vpn/m-p/203348#M59914</link>
      <description>&lt;P&gt;I agree.&amp;nbsp; Step 10 is confusing.&amp;nbsp; I want to create a seperate zone for clientless VPN, but what interface do I assign it to?&amp;nbsp; Doesn't seem possible to use a tunnel interface.&amp;nbsp; &amp;nbsp;Do I not assign the zone to an interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I use the untrust/outside zone then the policy doesn't really make sense.&amp;nbsp; Do I allow access from the "internet" to my internal resources?&amp;nbsp; How about DNS proxy?&amp;nbsp; The documentation around this piece is poor at best.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 19:32:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clientless-vpn/m-p/203348#M59914</guid>
      <dc:creator>ice-quake</dc:creator>
      <dc:date>2018-03-02T19:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: Clientless VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clientless-vpn/m-p/229633#M66032</link>
      <description>&lt;P&gt;did you guys get what you where looking for?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 02:42:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clientless-vpn/m-p/229633#M66032</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2018-09-06T02:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Clientless VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clientless-vpn/m-p/229634#M66033</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10387"&gt;@Tician&lt;/a&gt;&amp;nbsp;did you get this working?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 02:44:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clientless-vpn/m-p/229634#M66033</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2018-09-06T02:44:42Z</dc:date>
    </item>
  </channel>
</rss>

