<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic difference zone between end users and domain controller on Palo alto in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/difference-zone-between-end-users-and-domain-controller-on-palo/m-p/230846#M66309</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problem with palo alto PA-850. I configure domain controllers and end users diference zone. example: zone name: Server for domain controllers, and zone: User for end users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I setup policy to allow all traffic from Zone: Server to Zone: User and from User to Server. but end users could not authenticate with domain controllers.&amp;nbsp; I checked in traffic logs: To-Port: 135, 445, Aplication: Incomplete. Please help to advise&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Fri, 14 Sep 2018 13:08:29 GMT</pubDate>
    <dc:creator>Chivas</dc:creator>
    <dc:date>2018-09-14T13:08:29Z</dc:date>
    <item>
      <title>difference zone between end users and domain controller on Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-zone-between-end-users-and-domain-controller-on-palo/m-p/230846#M66309</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problem with palo alto PA-850. I configure domain controllers and end users diference zone. example: zone name: Server for domain controllers, and zone: User for end users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I setup policy to allow all traffic from Zone: Server to Zone: User and from User to Server. but end users could not authenticate with domain controllers.&amp;nbsp; I checked in traffic logs: To-Port: 135, 445, Aplication: Incomplete. Please help to advise&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 13:08:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-zone-between-end-users-and-domain-controller-on-palo/m-p/230846#M66309</guid>
      <dc:creator>Chivas</dc:creator>
      <dc:date>2018-09-14T13:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: difference zone between end users and domain controller on Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-zone-between-end-users-and-domain-controller-on-palo/m-p/230853#M66310</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97490"&gt;@Chivas&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try following the packet with PCAPs (is the server actually getting the packet ? Is the server returning the packet correctly ?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Not-Applicable-Incomplete-Insufficient-Data-in-the-Application/ta-p/65711" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Not-Applicable-Incomplete-Insufficient-Data-in-the-Application/ta-p/65711&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good luck !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 14 Sep 2018 13:44:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-zone-between-end-users-and-domain-controller-on-palo/m-p/230853#M66310</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2018-09-14T13:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: difference zone between end users and domain controller on Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-zone-between-end-users-and-domain-controller-on-palo/m-p/230865#M66315</link>
      <description>&lt;P&gt;hi Kiwi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked in PCAPs, the server is not getting the packet. but from client, I can ping or tracert to the server, even access network share on the server. just cannot authenticate when end users login. Please help to advise, do I need to configure any thing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the rule i setup:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;active-directory {&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;source zone: User;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; source&amp;nbsp; address: any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; user any;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; destination zone: Server;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; destination address: any;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;category any;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; application any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; service any;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; action allow;&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 14:48:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-zone-between-end-users-and-domain-controller-on-palo/m-p/230865#M66315</guid>
      <dc:creator>Chivas</dc:creator>
      <dc:date>2018-09-14T14:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: difference zone between end users and domain controller on Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-zone-between-end-users-and-domain-controller-on-palo/m-p/230869#M66317</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97490"&gt;@Chivas&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What if you actually look at the session ID in the CLI; does that give you any additional insight. Your security policy looks fine as the only thing you are really doing is analyzing the zones.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 14:55:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-zone-between-end-users-and-domain-controller-on-palo/m-p/230869#M66317</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-14T14:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: difference zone between end users and domain controller on Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-zone-between-end-users-and-domain-controller-on-palo/m-p/230877#M66319</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Application incomplete in my experience has been a routing issue. If they are on different subnets, e.g. useres and servers, make sure the routes are in place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 16:37:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-zone-between-end-users-and-domain-controller-on-palo/m-p/230877#M66319</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-09-14T16:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: difference zone between end users and domain controller on Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-zone-between-end-users-and-domain-controller-on-palo/m-p/231178#M66381</link>
      <description>&lt;P&gt;Thank Klier, I fixed my problem.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 02:42:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-zone-between-end-users-and-domain-controller-on-palo/m-p/231178#M66381</guid>
      <dc:creator>Chivas</dc:creator>
      <dc:date>2018-09-18T02:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: difference zone between end users and domain controller on Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-zone-between-end-users-and-domain-controller-on-palo/m-p/429172#M94842</link>
      <description>&lt;P&gt;What was the fix?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 16:12:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-zone-between-end-users-and-domain-controller-on-palo/m-p/429172#M94842</guid>
      <dc:creator>Networking2017</dc:creator>
      <dc:date>2021-08-25T16:12:22Z</dc:date>
    </item>
  </channel>
</rss>

