<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot access HTTPS sites using non standard ports in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190577#M57542</link>
    <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45418"&gt;@Farzana&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your outbound packets are being passed along so my guess would be there is an upstream issue&lt;/P&gt;
&lt;P&gt;Since you're not applying NAT on the Palo Alto, is your upstream NAT device perhaps configured to NAT default ports (80+443) and not 'high' ports?&lt;/P&gt;</description>
    <pubDate>Thu, 07 Dec 2017 07:44:49 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-12-07T07:44:49Z</dc:date>
    <item>
      <title>Cannot access HTTPS sites using non standard ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190235#M57469</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we switch the connection to a 4G connection, was able to connect to the URL without any issues:&lt;/P&gt;&lt;P&gt;wget &lt;A href="https://www2.medicareaustralia.gov.au:5447/" target="_blank"&gt;https://www2.medicareaustralia.gov.au:5447/&lt;/A&gt; --no-check-certificate&lt;/P&gt;&lt;P&gt;--2017-12-06 10:39:16--&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www2.medicareaustralia.gov.au:5447/" target="_blank"&gt;https://www2.medicareaustralia.gov.au:5447/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Resolving www2.medicareaustralia.gov.au... 203.80.58.18&lt;/P&gt;&lt;P&gt;Connecting to www2.medicareaustralia.gov.au|203.80.58.18|:5447...&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;connected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Through PA, we are getting below:&lt;/P&gt;&lt;P&gt;wget &lt;A href="https://www2.medicareaustralia.gov.au:5447/" target="_blank"&gt;https://www2.medicareaustralia.gov.au:5447/&lt;/A&gt; --no-check-certificate&lt;/P&gt;&lt;P&gt;--2017-12-06 10:21:30--&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www2.medicareaustralia.gov.au:5447/" target="_blank"&gt;https://www2.medicareaustralia.gov.au:5447/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Resolving www2.medicareaustralia.gov.au... 203.80.58.18&lt;/P&gt;&lt;P&gt;Connecting to www2.medicareaustralia.gov.au|203.80.58.18|:5447...&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;failed: Connection timed out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tried using a simple test rule from Inside to Outside, Application any, Service/URL Category any, without any profile.&lt;/P&gt;&lt;P&gt;No NAT in use.&amp;nbsp;&lt;/P&gt;&lt;P&gt;No-decrypt rule is in use for URL category: *.gov.au&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ND.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12844i3E8B540C82B62406/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ND.jpg" alt="ND.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12843i915E7EE96523D14B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 03:40:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190235#M57469</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-12-06T03:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access HTTPS sites using non standard ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190264#M57472</link>
      <description>&lt;P&gt;Can we see the Security policy Rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;are you using app default or a specific service (serivice-http, service-https)&lt;/P&gt;&lt;P&gt;is it being identified in the traffic log as SSL&lt;/P&gt;&lt;P&gt;or something else&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 08:02:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190264#M57472</guid>
      <dc:creator>DarinSutton</dc:creator>
      <dc:date>2017-12-06T08:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access HTTPS sites using non standard ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190290#M57476</link>
      <description>&lt;P&gt;your log states the app is incomplete and there's only 1 packet sent, none received&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you may want to do some more basic troubleshooting like a ping or traceroute to verify if your routing is letting you get to the server, and then perform more tests to see why you are not receiving a reply packet (is the conenction being NATed, is the port allowed to pass through the upstream router, is the destination server blocking your ip,...)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 10:12:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190290#M57476</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-12-06T10:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access HTTPS sites using non standard ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190452#M57517</link>
      <description>&lt;P&gt;Have you modified these to use your custom port:&amp;nbsp; service-http, service-https? If not, then you are blocking the traffic.&amp;nbsp; Those two default to port 80 and port 443.&amp;nbsp; You need to create a custom service and set the port in there, then assign that service to your Security Policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you check the Monitor tab, you'll see your traffic listed with "action = deny", with the ports listed in there.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 20:49:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190452#M57517</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2017-12-06T20:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access HTTPS sites using non standard ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190455#M57519</link>
      <description>&lt;P&gt;Hello Farzana,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Agree with another comment here: your log shows that the flow is seen as incomplete with no ingress packets. I would assume a network architecture problem like assymetry or a NAT problem: you tell that there is no NAT policy configured... Even an outbound one ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 21:30:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190455#M57519</guid>
      <dc:creator>khuynh</dc:creator>
      <dc:date>2017-12-06T21:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access HTTPS sites using non standard ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190531#M57534</link>
      <description>&lt;P&gt;&lt;SPAN&gt;This issue only occurs when using a non-standard port 5447.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Security policy is a simple one with application and service set to Any.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As mentioned earlier, no NATTing is there.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If I go to URL &lt;A href="https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww2.medicareaustralia.gov.au%2F&amp;amp;data=02%7C01%7Csupport-anz%40arrow.com%7C57fb5b72b04440aca67708d53d0dce17%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C636482051863897725&amp;amp;sdata=3Y7caADXPLaEKgwSGEpNFlNuP8l2AQIGctj6rcgCwes%3D&amp;amp;reserved=0" target="_blank"&gt;https://www2.medicareaustralia.gov.au/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I do get a response back from the Server, as shown below:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TrafficLog.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12892i83C47A1F196754CA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="TrafficLog.jpg" alt="TrafficLog.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 01:21:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190531#M57534</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-12-07T01:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access HTTPS sites using non standard ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190577#M57542</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45418"&gt;@Farzana&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your outbound packets are being passed along so my guess would be there is an upstream issue&lt;/P&gt;
&lt;P&gt;Since you're not applying NAT on the Palo Alto, is your upstream NAT device perhaps configured to NAT default ports (80+443) and not 'high' ports?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 07:44:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190577#M57542</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-12-07T07:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access HTTPS sites using non standard ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190653#M57557</link>
      <description>&lt;P&gt;Can you show your "Pinterest Allow" Security Policy?&amp;nbsp; That's the one that's matching the traffic, as shown by the log entries.&amp;nbsp; And show the Security Policy that you think it's supposed to be matching.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 16:37:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190653#M57557</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2017-12-07T16:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access HTTPS sites using non standard ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190658#M57558</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45418"&gt;@Farzana&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The current traffic is being allowed through the "Pinterest Allow" security policy, and prior traffic was being allowed through your test rule. Since your only test of this actually working is through a 4G connection, was that done through your Palo Alto or on a mobile device.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;is right, this looks like it's an issue upstream from your Palo Alto. With the information provided I would start testing to see if you can access the site through the ISP connection if you bypass the PA all together, my initial guess would be that this test will fail. Once you've verified it's an ISP issue, then you can start the process of troubleshooting with the ISP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 17:30:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/190658#M57558</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-12-07T17:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access HTTPS sites using non standard ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/191446#M57664</link>
      <description>&lt;P&gt;Thank you all for the suggestions. Really helpful.&lt;/P&gt;&lt;P&gt;Client found out there was another set of firewall by the Upstream provider that caused the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 00:40:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-access-https-sites-using-non-standard-ports/m-p/191446#M57664</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-12-13T00:40:34Z</dc:date>
    </item>
  </channel>
</rss>

