<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Access Route for a public website? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-access-route-for-a-public-website/m-p/219555#M63397</link>
    <description>&lt;P&gt;You were right.&amp;nbsp; I did not think to go add the VPN zone to the security rule to Untrust and Dynamic IP and Port NAT rule.&lt;/P&gt;&lt;P&gt;Resolved.&amp;nbsp; Thanks again!&lt;/P&gt;</description>
    <pubDate>Wed, 27 Jun 2018 21:54:59 GMT</pubDate>
    <dc:creator>OMatlock</dc:creator>
    <dc:date>2018-06-27T21:54:59Z</dc:date>
    <item>
      <title>GlobalProtect Access Route for a public website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-access-route-for-a-public-website/m-p/219431#M63372</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using a PA 3020 PANOS 7.1.14.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have entered all public IP addresses for Okta in our Global Protect Gateway Client Access route settings.&lt;/P&gt;&lt;P&gt;Our intention is for Okta to only see&amp;nbsp;client IP requests come from our one corporate public IP (instead of the client's ISP).&lt;/P&gt;&lt;P&gt;We want split tunnelling except for when accessing &amp;lt;name&amp;gt;.okta.com.&lt;/P&gt;&lt;P&gt;We have our internal DNS server IP added for the GlobalProtect clients to use (forwarding configured to public DNS).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, when connected to GlobalProtect &amp;lt;name&amp;gt;.okta.com will not resolve, "this site can't be reached", times out.&lt;/P&gt;&lt;P&gt;I've confirmed with a ping -a that the public IP it resolves to is in the list for access routes.&lt;/P&gt;&lt;P&gt;I've also tried adding adding an internal DNS zone for &amp;lt;name&amp;gt;.okta.com, but has not helped.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wondering if anyone has any tips?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 11:53:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-access-route-for-a-public-website/m-p/219431#M63372</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2018-06-27T11:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Access Route for a public website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-access-route-for-a-public-website/m-p/219439#M63373</link>
      <description>&lt;P&gt;Are you positive there is a nat rule for this outbound traffic?&lt;/P&gt;&lt;P&gt;Scurity policy to allow it?&lt;/P&gt;&lt;P&gt;Do you see this traffic in the logs?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 12:16:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-access-route-for-a-public-website/m-p/219439#M63373</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-06-27T12:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Access Route for a public website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-access-route-for-a-public-website/m-p/219475#M63376</link>
      <description>&lt;P&gt;Yea, I think your are right, thank you.&amp;nbsp; We do not have a security rule in place from VPN zone to Untrust zone.&amp;nbsp; I assume because it was not necessary.&lt;/P&gt;&lt;P&gt;I just tried it, but still not working.&amp;nbsp; I believe I need to add all the IPs in there, since I am now getting a page not found error (instead of time out).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Traffic to the Okta public IP is not even registering the traffic log at the moment, have not packet captured yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure if the internal DNS zone I created for &amp;lt;name&amp;gt;.okta.com is needed or not, will try to find out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still testing, will update.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 14:05:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-access-route-for-a-public-website/m-p/219475#M63376</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2018-06-27T14:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Access Route for a public website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-access-route-for-a-public-website/m-p/219492#M63378</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Just another though might be to not decypt the traffic to Okta, if you are decrypticing traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 15:04:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-access-route-for-a-public-website/m-p/219492#M63378</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-06-27T15:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Access Route for a public website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-access-route-for-a-public-website/m-p/219496#M63380</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56398"&gt;@OMatlock&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Just to ensure that you are actually getting all of the logs you might want to override the interzone default policy to log the traffic, as if you don't have a security policy allow it the denied traffic won't be logged by default.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 15:19:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-access-route-for-a-public-website/m-p/219496#M63380</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-27T15:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Access Route for a public website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-access-route-for-a-public-website/m-p/219555#M63397</link>
      <description>&lt;P&gt;You were right.&amp;nbsp; I did not think to go add the VPN zone to the security rule to Untrust and Dynamic IP and Port NAT rule.&lt;/P&gt;&lt;P&gt;Resolved.&amp;nbsp; Thanks again!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 21:54:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-access-route-for-a-public-website/m-p/219555#M63397</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2018-06-27T21:54:59Z</dc:date>
    </item>
  </channel>
</rss>

