<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VNC Access through Global protect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/202021#M59643</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70049"&gt;@Radmin_85&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is the firewall with GP Gateway the only firewall in between? If yes, is this subnet of that server directly vonnected to this firewall?&lt;/LI&gt;&lt;LI&gt;From where in the internal network is it working? From the same subnet or also from other subnets?&lt;/LI&gt;&lt;LI&gt;Did you check the local firewall on that server?&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Fri, 23 Feb 2018 15:57:44 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-02-23T15:57:44Z</dc:date>
    <item>
      <title>VNC Access through Global protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201306#M59513</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;We have internal server that must be accessed through VNC and HTTP.&lt;/P&gt;&lt;P&gt;Internally it works well but when we try to connect from outside through Global Protect it is blocked&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Access&amp;nbsp; Policies&amp;nbsp; from GP to Internal allowed. But&amp;nbsp; not&amp;nbsp; working.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 11:52:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201306#M59513</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-02-20T11:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: VNC Access through Global protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201334#M59518</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70049"&gt;@Radmin_85&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Can you post the actual security policy that you have to allow the traffic, along with verifying that your Gateway settings under&amp;nbsp;&lt;STRONG&gt;Agent &amp;gt; Client Settings&lt;/STRONG&gt; include an access route if you are utilizing split tunnel.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd also recommend looking at the traffic logs and seeing what they tell you, as it will give you a better insight into where the problem actually is. Do you see the traffic&amp;nbsp;&lt;STRONG&gt;from&lt;/STRONG&gt; your GlobalProtect client hitting the firewall? Can you see traffic&amp;nbsp;&lt;STRONG&gt;from&lt;/STRONG&gt; the server attempting to hit your GlobalProtect clients? It might be worth taking a packet capture directly on the server as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 14:10:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201334#M59518</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-02-20T14:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: VNC Access through Global protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201533#M59563</link>
      <description>&lt;P&gt;Thanks i will check&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 07:55:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201533#M59563</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-02-21T07:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: VNC Access through Global protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201554#M59565</link>
      <description>&lt;P&gt;What i have learned is:&lt;/P&gt;&lt;P&gt;The outside users can connect any other server inside with GP.But there is one spesific server inside which is Siemens Simantic server to which users cannot connect from outside with HTTP.&lt;/P&gt;&lt;P&gt;They wanted to use VNC as alternative but no way.That is the logs.The security rule is allowing any any from GP zone to Trust zone.Everything works fine except this server with Siemens web server&lt;/P&gt;&lt;P&gt;May be someone meet such case.Is there any specification about it?Can it be because of HTML version or something else?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_4.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13885iC50A4095D02D1034/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot_4.png" alt="Screenshot_4.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_5.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13886iF087A98033C400FF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot_5.png" alt="Screenshot_5.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 09:05:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201554#M59565</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-02-21T09:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: VNC Access through Global protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201601#M59572</link>
      <description>&lt;P&gt;you stated any,any, does that include application and service...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it may be best if you post the actual security policy as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;suggested.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 14:45:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201601#M59572</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-02-21T14:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: VNC Access through Global protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201775#M59599</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image002.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13912iA6BE073BB4791DA0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image002.png" alt="image002.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please &amp;nbsp;the information provided&amp;nbsp; bellow;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;DELL Precision T1650&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;STRONG&gt;RACKMOUNT&lt;/STRONG&gt;&lt;BR /&gt;Intel Xeon E3-1240 v2 (3.40GHz, 8MB, QC)&lt;BR /&gt;1 GB NVIDIA Quadro 600&lt;BR /&gt;&lt;STRONG&gt;1x500GB&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;3.5inch Serial ATA (7.200 Rpm) Hard Drive&lt;BR /&gt;8GB (2x4GB) 1600MHz DDR3 Non-ECC&lt;BR /&gt;&lt;STRONG&gt;Windows 7 SP1&amp;nbsp; Ultimate (English) 64 Bit&lt;/STRONG&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;USB&lt;/STRONG&gt;&amp;nbsp;TR Q professional keyboard, Optical&amp;nbsp;&lt;STRONG&gt;USB&lt;/STRONG&gt;&amp;nbsp;Mouse&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;HD 1920 x 1080 @60 Hz i Destekleyecek 1xDP çıkışlı Ekran Kartı Takılmalı&lt;/STRONG&gt;DELL&lt;BR /&gt;Web Server&amp;nbsp;&amp;nbsp;&amp;nbsp; IIS VERSION 7.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://ip1.i.lithium.com/a5431649ef5b225db906cc0de8785522fa7f3e93/68747470733a2f2f737570706f72742e74696765722d6f70746963732e72752f696e6465782e706c3f416374696f6e3d4167656e745469636b65744174746163686d656e743b537562616374696f6e3d48544d4c566965773b41727469636c6549443d343138343b46696c6549443d34" border="0" alt="image001.png@01D3AB13.1EF753D0" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2018 15:18:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201775#M59599</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-02-22T15:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: VNC Access through Global protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201789#M59602</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70049"&gt;@Radmin_85&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In such cases it may help if you check the column "Bytes received" in your logs. It there is a 0, the problem could also be a local firewall or accesslist on the server.&lt;/P&gt;&lt;P&gt;And what filter did you use ond the screenshot? Did you filter on the source and destination IP or the rulename or something completely different?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2018 16:33:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201789#M59602</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-02-22T16:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: VNC Access through Global protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201897#M59618</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13920iA5F80DFDE0E8E566/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_3.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13921iC4622CDC8886E5DE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot_3.png" alt="Screenshot_3.png" /&gt;&lt;/span&gt;First is logs.And as you see the server 172.17.79.2 get incomplete and some bytes are recieved&lt;/P&gt;&lt;P&gt;and the second is actual security rule.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 06:20:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201897#M59618</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-02-23T06:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: VNC Access through Global protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201902#M59619</link>
      <description>&lt;P&gt;We also cannot access to this server via http&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 06:22:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201902#M59619</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-02-23T06:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: VNC Access through Global protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201939#M59620</link>
      <description>&lt;P&gt;Actually in this screenshot there is only the "bytes" column, but not "Bytes received"&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 07:12:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201939#M59620</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-02-23T07:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: VNC Access through Global protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201960#M59624</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_5.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13950iD9462607EE43D76A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot_5.png" alt="Screenshot_5.png" /&gt;&lt;/span&gt;As you see there is no received bytes&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 10:11:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/201960#M59624</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-02-23T10:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: VNC Access through Global protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/202021#M59643</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70049"&gt;@Radmin_85&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is the firewall with GP Gateway the only firewall in between? If yes, is this subnet of that server directly vonnected to this firewall?&lt;/LI&gt;&lt;LI&gt;From where in the internal network is it working? From the same subnet or also from other subnets?&lt;/LI&gt;&lt;LI&gt;Did you check the local firewall on that server?&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 23 Feb 2018 15:57:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vnc-access-through-global-protect/m-p/202021#M59643</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-02-23T15:57:44Z</dc:date>
    </item>
  </channel>
</rss>

