<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto not loading certain valid sites, why? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211565#M61717</link>
    <description>&lt;P&gt;Thanks for the clarification.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I might not fully get it yet so bear with me.&amp;nbsp; The 3020s would these be "perimeter" firewalls, where really the next hop beyond them is an ISP or is there another set of firewalls beyond the 3020s?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the 3020s are perimeter&amp;nbsp;devices, the PA IP address of 11.11.11.4 is that your public hide / NAT address?&amp;nbsp; If so you'll want to make sure that the "object" entry for that IP is a /32.&amp;nbsp; While the 11.11.11.4 might be a part of a /26 network in order to use the .4 as your NAT it needs to be a /32 object in the firewall.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Apr 2018 17:09:07 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2018-04-24T17:09:07Z</dc:date>
    <item>
      <title>Palo Alto not loading certain valid sites, why?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211537#M61712</link>
      <description>&lt;P&gt;Having another issue with these things (ready to throw them out the window in all honesty).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems as though a couple sites simply won't load when routed through a pair of HA-3020s.&amp;nbsp; Of course Palo Alto support does a packet capture and sees no drops so immediately not their fault.&amp;nbsp; But I know it is because I can route that specific traffic out another gateway on the same public network the PAs sit on and it works without issue.&amp;nbsp; Packet captures from the client side show alot of TCP re-transmissions when the traffic is routed through the PAs, when its routed through an ASA I see 0 re-transmits.&amp;nbsp; PA wants to point the finger at the ISP but I highly doubt our ISP is having an issue routing two completely different website/IPs back to a single IP on the same /26 network.&amp;nbsp; No SSL decryption.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nothing in the logging on the Palo Alto shows any block/drop or deny.&amp;nbsp; Has anyone seen anything like this before?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 15:21:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211537#M61712</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2018-04-24T15:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto not loading certain valid sites, why?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211557#M61715</link>
      <description>&lt;P&gt;Your problem statement is a bit confusing.&amp;nbsp; Can you clarify a bit more, adding in architecture information as well as the websites in question which aren't working?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 16:43:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211557#M61715</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-04-24T16:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto not loading certain valid sites, why?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211561#M61716</link>
      <description>&lt;P&gt;Yeah sorry, just frustated with PA so more of a vent post.&amp;nbsp; Hopefully this helps:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a pair HA active/passive 3020s and users behind them are unable to access a couple sites.&amp;nbsp; If I add a static route for those sites on my core (cat6k) and make the next hop an ASA (on the same public network as my 3020s) the sites load without issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lets say the ASA has an IP of 11.11.11.3/26 and the PAs have 11.11.11.4/26&amp;nbsp;and the only thing in front of them both is an L2 DMZ switch.&amp;nbsp; When routing the traffic through the PAs I see a lot of tcp retransmissions, when I route it through the ASA I don't see any of those.&amp;nbsp; I would understand if it was an ISP issue to my entire /26 but its clearly not.&amp;nbsp; Only an issue when traffic is routed through the PAs.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the sites is cigna.com 170.48.10.90 and you can see part of the captures below, ASA on top and PA on the bottom.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="asa-cigna.GIF" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14848i066430C6E5DB036A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="asa-cigna.GIF" alt="asa-cigna.GIF" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pa-cigna.GIF" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14847i86A9C2E5699C7DAF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="pa-cigna.GIF" alt="pa-cigna.GIF" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 16:59:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211561#M61716</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2018-04-24T16:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto not loading certain valid sites, why?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211565#M61717</link>
      <description>&lt;P&gt;Thanks for the clarification.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I might not fully get it yet so bear with me.&amp;nbsp; The 3020s would these be "perimeter" firewalls, where really the next hop beyond them is an ISP or is there another set of firewalls beyond the 3020s?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the 3020s are perimeter&amp;nbsp;devices, the PA IP address of 11.11.11.4 is that your public hide / NAT address?&amp;nbsp; If so you'll want to make sure that the "object" entry for that IP is a /32.&amp;nbsp; While the 11.11.11.4 might be a part of a /26 network in order to use the .4 as your NAT it needs to be a /32 object in the firewall.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 17:09:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211565#M61717</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-04-24T17:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto not loading certain valid sites, why?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211567#M61718</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes perimeter FWs, nothing allowing or denying traffic in front of them, next hop is one of my ISPs.&amp;nbsp; And I thought I was doing many to 1 NAT&amp;nbsp;using&amp;nbsp;object 11.11.11.4/26.&amp;nbsp; &amp;nbsp;You are saying I should change that object to 11.11.11.4/32? If I do that is it going to complain about my default route being in a /26 and the outside/untrust IP being a /32?&amp;nbsp; Right now my outside/untrust ae1 and my outbound NAT statement both use the 'outside interface' object 11.11.11.4/26.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For outbound NAT I am doing:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Dynamic IP and Port
Interface Address
ae1
outside object (11.11.11.4/26)&lt;/PRE&gt;&lt;P&gt;Which appears to be right because my public IP shows a 11.11.11.4.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 17:23:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211567#M61718</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2018-04-24T17:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto not loading certain valid sites, why?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211573#M61720</link>
      <description>&lt;P&gt;In my org it's easier to do static routing on the firewall so that's what I'll describe for our deployment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Default route egressing the firewall goes to a /24 network (a .1 on said network) which is owned by our border routers.&amp;nbsp; We're utilizing a specific IP (/32 object entry) which exists in that /24 on the egress/external side of the firewall for our NAT.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is how Palo requires the object to be created in order to have traffic utilize an IP for a service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Route_1.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14849iF47ACB27930E2D12/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Route_1.PNG" alt="Route_1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT_1.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14850iF85F97F00101CE43/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NAT_1.PNG" alt="NAT_1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 17:43:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211573#M61720</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-04-24T17:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto not loading certain valid sites, why?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211588#M61722</link>
      <description>&lt;P&gt;Makes sense but are you saying the way I have it could be causing me a problem?&amp;nbsp; I ask because this isn't our only HA PA environment and they are all setup the same way&amp;nbsp;but only this pair having problems.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 19:32:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211588#M61722</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2018-04-24T19:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto not loading certain valid sites, why?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211600#M61727</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34542"&gt;@drewdown&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Makes sense but are you saying the way I have it could be causing me a problem?&amp;nbsp; I ask because this isn't our only HA PA environment and they are all setup the same way&amp;nbsp;but only this pair having problems.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, 5ish years ago when I started working on Palo I deployed the firewall with the object as /24, because it was a apart of a /24 network.&amp;nbsp; I couldn't get any Internet&amp;nbsp;browsing to work.&amp;nbsp; I opened a case with Palo TAC and was told about this /32 requirement.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That said I would contact TAC again and point them to this point and let them confirm for your environment.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 20:31:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211600#M61727</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-04-24T20:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto not loading certain valid sites, why?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211608#M61729</link>
      <description>&lt;P&gt;I will but don't think that is my issue.&amp;nbsp; Thanks though.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 21:17:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211608#M61729</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2018-04-24T21:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto not loading certain valid sites, why?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211687#M61748</link>
      <description>&lt;P&gt;Just wanted to chip in and say I had the same issue with a 220 (not in a HA config) a while back at one of my sites.&amp;nbsp; We tried everything we could think of as far as ensuring nothing on the PA was interfering with it, eventually I tried adding a rule to force it through a secondary WAN connection with PBF and the site loaded just fine.&amp;nbsp; Unfortunately I don't have the logs from that incident anymore and when I went to see if this was still the case the site now works with both ISPs there.&amp;nbsp; So in my case it likely was an issue on the ISP side (Airespring who was using Sprint's network I believe).&lt;/P&gt;</description>
      <pubDate>Wed, 25 Apr 2018 13:52:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211687#M61748</guid>
      <dc:creator>carlebert</dc:creator>
      <dc:date>2018-04-25T13:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto not loading certain valid sites, why?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211979#M61808</link>
      <description>&lt;P&gt;So more and more sites stopped loading and looking at the logs I could see 0 bytes received when I tried to browse any of them.&amp;nbsp; On a whim I changed the outside IP of the PAs (changed it to 11.11.11.15/26) and that immediately fixed the issue.&amp;nbsp; &amp;nbsp;So something upstream, ARP related, route or duplicate IP was stopping return traffic from reach the PAs.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Honestly the last thing I would think the problem would be but at this point its fixed.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 03:15:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/211979#M61808</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2018-04-27T03:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto not loading certain valid sites, why?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/212095#M61852</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34542"&gt;@drewdown&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;So more and more sites stopped loading and looking at the logs I could see 0 bytes received when I tried to browse any of them.&amp;nbsp; On a whim I changed the outside IP of the PAs (changed it to 11.11.11.15/26) and that immediately fixed the issue.&amp;nbsp; &amp;nbsp;So something upstream, ARP related, route or duplicate IP was stopping return traffic from reach the PAs.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Honestly the last thing I would think the problem would be but at this point its fixed.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Take it for what you will, but you really should reach out to TAC and ask them about using a /26 object for your NAT vice the /32.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've accidentally&amp;nbsp;gotten my site on Cox's "blacklist" because I didn't use the correct mask (ie using /26 for an object on a GP setting).&amp;nbsp; What ended up happening is my 5020 was ARPing out for all the hosts on the network I specified instead of just using the single IP I intended for the interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While the change of IP might have masked the problem, I don't believe it solved it...Just trying to let you benefit&amp;nbsp;from my past mistakes.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 16:16:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/212095#M61852</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-04-27T16:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto not loading certain valid sites, why?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/212100#M61855</link>
      <description>&lt;P&gt;I agree, changing the IP fixed the problem at hand but didn't shed any light on why it was happening.&amp;nbsp; Will ask tac about the outbound NAT configuration and see what they say.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 16:20:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-not-loading-certain-valid-sites-why/m-p/212100#M61855</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2018-04-27T16:20:14Z</dc:date>
    </item>
  </channel>
</rss>

