<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Troubleshooting GlobalProtect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217397#M62894</link>
    <description>&lt;P&gt;It's showing on the correct port (443 and 8443 is what I was looking at) and being IDd as SSL traffic.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Jun 2018 18:35:55 GMT</pubDate>
    <dc:creator>Nathan.S</dc:creator>
    <dc:date>2018-06-11T18:35:55Z</dc:date>
    <item>
      <title>Troubleshooting GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217369#M62885</link>
      <description>&lt;P&gt;PA220, 8.1.1, GPClient 4.1.1, GP license activated.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Connecting to the GPportal/gateway works fine. Traffic routes as expected.&amp;nbsp;&lt;BR /&gt;We're still testing, so access is severly limited and policies wide open once connected. Literally, everything is allowed for GP users.&amp;nbsp;&lt;BR /&gt;However, when i attempt to access an internal SSL-protected site, the traffic is denied.&amp;nbsp;&lt;BR /&gt;I can even change the rule to expressly allow SSL &amp;amp; web-browsing to that device and it still hits the DenyAll rule at the bottom.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What am I missing in my setup?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 15:36:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217369#M62885</guid>
      <dc:creator>Nathan.S</dc:creator>
      <dc:date>2018-06-11T15:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217376#M62886</link>
      <description>&lt;P&gt;Can you share screenshot of permit rule and denied log entry.&lt;/P&gt;&lt;P&gt;Most likely zone or user/group mismatch.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 15:38:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217376#M62886</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-06-11T15:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217390#M62890</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/13668"&gt;@Nathan.S&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Aside from what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;already mentioned I would also look at the logs and verify that it's being seen on a default port and that the application is getting identified. There's a lot of little gotcha's here that can get in the way of this working properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 18:18:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217390#M62890</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-11T18:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217396#M62893</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rule" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15453i28768D68630C5683/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="userVPNITSRule.JPG" alt="Rule" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Rule&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UnifiedLog" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15454iA8CD86E8421BD249/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="userVPNITSDeny.JPG" alt="UnifiedLog" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;UnifiedLog&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 18:35:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217396#M62893</guid>
      <dc:creator>Nathan.S</dc:creator>
      <dc:date>2018-06-11T18:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217397#M62894</link>
      <description>&lt;P&gt;It's showing on the correct port (443 and 8443 is what I was looking at) and being IDd as SSL traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 18:35:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217397#M62894</guid>
      <dc:creator>Nathan.S</dc:creator>
      <dc:date>2018-06-11T18:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217399#M62896</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/13668"&gt;@Nathan.S&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Looking at your screenshot it looks like the log in question is being identified as looking for dst port 7443 right? Regardless the application-default port for SSL identified traffic is only 443; so if you want to allow it on 8443/7443 or whatever you need to actually specify that. As your current security policy is written this traffic&amp;nbsp;&lt;EM&gt;doesn't&lt;/EM&gt; match your policy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 18:51:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217399#M62896</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-11T18:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217406#M62897</link>
      <description>&lt;P&gt;Even though I have the apps set to 'any'?&lt;BR /&gt;huh.&amp;nbsp;&lt;BR /&gt;Let me look at the logs again, I'm pretty sure 443 traffic was failing too&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 18:53:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217406#M62897</guid>
      <dc:creator>Nathan.S</dc:creator>
      <dc:date>2018-06-11T18:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217407#M62898</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/13668"&gt;@Nathan.S&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Yes; this is due to specifying the service as application-default. Since the app-id is being identified as 'ssl' the only default service that is going to be allowed is 443.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 18:55:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217407#M62898</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-11T18:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217408#M62899</link>
      <description>&lt;P&gt;Hmm, okay. I'll test further and will update.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you for your help!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 18:56:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-globalprotect/m-p/217408#M62899</guid>
      <dc:creator>Nathan.S</dc:creator>
      <dc:date>2018-06-11T18:56:42Z</dc:date>
    </item>
  </channel>
</rss>

