<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Application issues Via VPN with Peer in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/application-issues-via-vpn-with-peer/m-p/184864#M56639</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need some help dealing with CyberAck over VPN. The problem is that I created and established a VPN with a remote peer for CyberAck traffic. Service is Any but application is default. Traffic is allowed via the firewall but I get an error (tcp-rst-from-server) on both sides or server and client. Cyberack uses TCP ports 4118, 4119, 4120 which I custom&amp;nbsp;created. This did not work so I set the service to any and application to default and still get the same error - tcp-rst-from-server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when I set the application to Any and service to Any, everything works fine. And this defeats my reason for a firewall in the first place.&amp;nbsp;Monitoring the rule in action,&amp;nbsp;I noticed that service is coming and going as 4120, 4118 etc and application is set to SSL. This is obviously not a default SSL so hence failing.&amp;nbsp;I think what happens is this - &lt;A href="https://10.10.10.25:4118" target="_blank"&gt;https://10.10.10.25:4118&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know how I can overcome this problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help will be much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Nov 2017 10:15:54 GMT</pubDate>
    <dc:creator>Light-Regions</dc:creator>
    <dc:date>2017-11-01T10:15:54Z</dc:date>
    <item>
      <title>Application issues Via VPN with Peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-issues-via-vpn-with-peer/m-p/184864#M56639</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need some help dealing with CyberAck over VPN. The problem is that I created and established a VPN with a remote peer for CyberAck traffic. Service is Any but application is default. Traffic is allowed via the firewall but I get an error (tcp-rst-from-server) on both sides or server and client. Cyberack uses TCP ports 4118, 4119, 4120 which I custom&amp;nbsp;created. This did not work so I set the service to any and application to default and still get the same error - tcp-rst-from-server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when I set the application to Any and service to Any, everything works fine. And this defeats my reason for a firewall in the first place.&amp;nbsp;Monitoring the rule in action,&amp;nbsp;I noticed that service is coming and going as 4120, 4118 etc and application is set to SSL. This is obviously not a default SSL so hence failing.&amp;nbsp;I think what happens is this - &lt;A href="https://10.10.10.25:4118" target="_blank"&gt;https://10.10.10.25:4118&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know how I can overcome this problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help will be much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2017 10:15:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-issues-via-vpn-with-peer/m-p/184864#M56639</guid>
      <dc:creator>Light-Regions</dc:creator>
      <dc:date>2017-11-01T10:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: Application issues Via VPN with Peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-issues-via-vpn-with-peer/m-p/184948#M56656</link>
      <description>&lt;P&gt;You'll need to create an application override policy to force that traffic to the application(s) you created. Here are the steps:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override/ta-p/65513" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override/ta-p/65513&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2017 16:32:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-issues-via-vpn-with-peer/m-p/184948#M56656</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-11-01T16:32:43Z</dc:date>
    </item>
  </channel>
</rss>

