<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to allow RDP with specific port. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/190765#M57575</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I&amp;nbsp;tried to copy&amp;nbsp;the policy as much as possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but I have some concern.&amp;nbsp;(Sorry I am new to Palo Alto)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the picture you send&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source:&lt;/P&gt;&lt;P&gt;zone: the is no "local". I can only choose from access, external, internal, ISP2, Trust, untrust. I not sure if I can create local. and if I can i dont know how.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Destination:&lt;/P&gt;&lt;P&gt;zone: same as above I do have remote. Only the the listed choices was there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Destination/Source:&lt;/P&gt;&lt;P&gt;Address: I only want an specific IP address where the client PC can connect.&amp;nbsp; Where will I input it at Source address or Destionation address?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Service&lt;/P&gt;&lt;P&gt;I created a service. Please check if my setting is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Name: test&lt;/P&gt;&lt;P&gt;Description: blank&lt;/P&gt;&lt;P&gt;Protocol: TCP&lt;/P&gt;&lt;P&gt;Destionation Port: 12345 (sample only)&lt;/P&gt;&lt;P&gt;Source Port: blank&lt;/P&gt;&lt;P&gt;Tags: Blank&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I tested.&lt;/P&gt;&lt;P&gt;Source zone: internal&lt;/P&gt;&lt;P&gt;Destination zone: access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;address: any for both.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and i have this msg.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="x-form-item "&gt;&lt;STRONG&gt;Status: &lt;/STRONG&gt;&lt;STRONG&gt;Completed&lt;/STRONG&gt;&lt;DIV class="x-form-clear-left"&gt;&lt;STRONG&gt;Result: &lt;/STRONG&gt;&lt;STRONG&gt;Failed&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="x-form-item "&gt;&lt;DIV class="x-form-clear-left"&gt;&lt;STRONG&gt;Details&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="x-form-item "&gt;&lt;DIV class="x-form-element"&gt;&lt;DIV class=" x-form-display-field"&gt;&lt;UL&gt;&lt;LI&gt;In VSYS vsys1 from zone Internal of type vwire and to zone access of type layer3 are incompatible in security rule&amp;nbsp;Remote Desktop Protocol&lt;/LI&gt;&lt;LI&gt;Configuration is invalid&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="x-form-clear-left"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="x-form-clear-left"&gt;Thank you.&lt;/DIV&gt;&lt;DIV class="x-form-clear-left"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="x-form-clear-left"&gt;Best regards,&lt;/DIV&gt;&lt;DIV class="x-form-clear-left"&gt;Uldridge&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="x-form-item "&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/DIV&gt;</description>
    <pubDate>Fri, 08 Dec 2017 06:22:54 GMT</pubDate>
    <dc:creator>ugalarosa</dc:creator>
    <dc:date>2017-12-08T06:22:54Z</dc:date>
    <item>
      <title>How to allow RDP with specific port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/190541#M57536</link>
      <description>&lt;P&gt;Good day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am new in handling firewall. We use juniper before (i did not setup).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before we can remote access (remote desktop protocol) our network. I would like to setup that kind of connection again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before on the remote desktop connection, we just put IP Address:port number + domain account (authentication).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to setup like that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Uldridge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 02:01:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/190541#M57536</guid>
      <dc:creator>ugalarosa</dc:creator>
      <dc:date>2017-12-07T02:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow RDP with specific port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/190582#M57544</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77726"&gt;@ugalarosa&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Most likely your policy should look like this:&lt;/P&gt;
&lt;P&gt;From source zone&lt;/P&gt;
&lt;P&gt;to destination zone&lt;/P&gt;
&lt;P&gt;application ms-rdp&lt;/P&gt;
&lt;P&gt;service: a service object containing the appropriate port(s) for your rdp&lt;/P&gt;
&lt;P&gt;action allow&lt;/P&gt;
&lt;P&gt;profile: security profiles to scan your sessions for malicious content&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rdp policy.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12894i49A99C7F1F493B0C/image-size/large?v=v2&amp;amp;px=999" role="button" title="rdp policy.png" alt="rdp policy.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 09:09:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/190582#M57544</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-12-07T09:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow RDP with specific port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/190668#M57563</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77726"&gt;@ugalarosa&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Do you already have GlobalProtect configured to actually allow users to VPN into the network, or was your Juniper simply setup with NAT statements to direct traffic to the proper desktop from the outside?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Generally for something like this you would setup GlobalProtect for allowing remote access into the network, and then your RDP port would actually be left alone and everyone would simply RDP to the hostname or the IP assigned to the host of their workstation. If you are using random RDP ports on the machines, then what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;has listed would need to be done to actually allow that access since you are not using the standard ports for the ms-rdp app-id.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you were going to your Public IP address on specific ports to access your machine remotely, I would really recommend you switch to having users VPN into the network instead of opening up these ports for outside access. While the Palo Alto is perfectly capable of mimicing this configuration, if this is what you were doing, it is by no means a secure configuration at all.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 17:47:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/190668#M57563</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-12-07T17:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow RDP with specific port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/190765#M57575</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I&amp;nbsp;tried to copy&amp;nbsp;the policy as much as possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but I have some concern.&amp;nbsp;(Sorry I am new to Palo Alto)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the picture you send&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source:&lt;/P&gt;&lt;P&gt;zone: the is no "local". I can only choose from access, external, internal, ISP2, Trust, untrust. I not sure if I can create local. and if I can i dont know how.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Destination:&lt;/P&gt;&lt;P&gt;zone: same as above I do have remote. Only the the listed choices was there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Destination/Source:&lt;/P&gt;&lt;P&gt;Address: I only want an specific IP address where the client PC can connect.&amp;nbsp; Where will I input it at Source address or Destionation address?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Service&lt;/P&gt;&lt;P&gt;I created a service. Please check if my setting is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Name: test&lt;/P&gt;&lt;P&gt;Description: blank&lt;/P&gt;&lt;P&gt;Protocol: TCP&lt;/P&gt;&lt;P&gt;Destionation Port: 12345 (sample only)&lt;/P&gt;&lt;P&gt;Source Port: blank&lt;/P&gt;&lt;P&gt;Tags: Blank&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I tested.&lt;/P&gt;&lt;P&gt;Source zone: internal&lt;/P&gt;&lt;P&gt;Destination zone: access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;address: any for both.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and i have this msg.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="x-form-item "&gt;&lt;STRONG&gt;Status: &lt;/STRONG&gt;&lt;STRONG&gt;Completed&lt;/STRONG&gt;&lt;DIV class="x-form-clear-left"&gt;&lt;STRONG&gt;Result: &lt;/STRONG&gt;&lt;STRONG&gt;Failed&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="x-form-item "&gt;&lt;DIV class="x-form-clear-left"&gt;&lt;STRONG&gt;Details&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="x-form-item "&gt;&lt;DIV class="x-form-element"&gt;&lt;DIV class=" x-form-display-field"&gt;&lt;UL&gt;&lt;LI&gt;In VSYS vsys1 from zone Internal of type vwire and to zone access of type layer3 are incompatible in security rule&amp;nbsp;Remote Desktop Protocol&lt;/LI&gt;&lt;LI&gt;Configuration is invalid&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="x-form-clear-left"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="x-form-clear-left"&gt;Thank you.&lt;/DIV&gt;&lt;DIV class="x-form-clear-left"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="x-form-clear-left"&gt;Best regards,&lt;/DIV&gt;&lt;DIV class="x-form-clear-left"&gt;Uldridge&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="x-form-item "&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 08 Dec 2017 06:22:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/190765#M57575</guid>
      <dc:creator>ugalarosa</dc:creator>
      <dc:date>2017-12-08T06:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow RDP with specific port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/190766#M57576</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have read some items about globalprotect but I still dont understand how it works or how to configure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im new to this Palo Alto..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im not the one who setup the Juniper so I dont know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is you could help me to find a step by step insturction how to remote my server. It will be a big help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2017 06:33:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/190766#M57576</guid>
      <dc:creator>ugalarosa</dc:creator>
      <dc:date>2017-12-08T06:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow RDP with specific port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/190775#M57578</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77726"&gt;@ugalarosa&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;zones can be given any name you like to best reflect a topology that makes sense to you&lt;/P&gt;
&lt;P&gt;in my lab i have my internal zone and my external zone, which makes it easier to illustrate what is where but you can have very different zones (dmz, lan, wan, ...). You can configure/review your zones in Network &amp;gt; Zones&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I created the "&lt;A title="Getting Started: The Palo Alto Networks Firewall Series" href="https://live.paloaltonetworks.com/t5/Community-Blog/Getting-Started-The-Palo-Alto-Networks-Firewall-Series/ba-p/67707" target="_blank"&gt;getting started series&lt;/A&gt;" a while ago, you may want to check it out as it'll help you understand some concepts&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your service looks perfect&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the error message indicates you created a security policy that would allow sessions to flow between two incompatible interfaces&amp;nbsp;&lt;/P&gt;
&lt;P&gt;one of your zones is attached to a layer3 interface while the other is connected to a vwire, which is a "bump in the wire" directly between two interfaces&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please have a look at the &lt;A title="Getting Started: The Palo Alto Networks Firewall Series" href="https://live.paloaltonetworks.com/t5/Community-Blog/Getting-Started-The-Palo-Alto-Networks-Firewall-Series/ba-p/67707" target="_blank"&gt;getting started series&lt;/A&gt; and let me know if something is not clear yet&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2017 07:59:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/190775#M57578</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-12-08T07:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow RDP with specific port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/190906#M57595</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will check the guide you prepare. and will update this post.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your assistance is highly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Dec 2017 01:52:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/190906#M57595</guid>
      <dc:creator>ugalarosa</dc:creator>
      <dc:date>2017-12-09T01:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow RDP with specific port.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/191809#M57712</link>
      <description>&lt;P&gt;I havent solve my problem and I am coordinating with our local supplier/support but i can close this ticket and will try to post later what happen on my issue&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 01:07:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-rdp-with-specific-port/m-p/191809#M57712</guid>
      <dc:creator>ugalarosa</dc:creator>
      <dc:date>2017-12-15T01:07:45Z</dc:date>
    </item>
  </channel>
</rss>

