<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect, use custom port for portal, followed the tutorial on paloaltonetwork in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-use-custom-port-for-portal-followed-the-tutorial/m-p/232323#M66653</link>
    <description>&lt;P&gt;Just to add some new information.&lt;/P&gt;&lt;P&gt;After applying the NAT rules, I see on the other router ARP message like this: Broadcast ARP Gratuitous&amp;nbsp; request for 172.16.0.254 ( duplicate use of 172.16.0.254 detected).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;172.16.0.254 == my second router IP and the configured nextHop on the palo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The network diagram is the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;palo with ip internal 192.168.200.1 and ip external 172.16.0.200 connected to a router with ip 172.16.0.254.&lt;/P&gt;&lt;P&gt;I'm wondering why adding the nat rules make this message appears.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After doing packet capture on the palo, I can see in the DROP pcap, SYN from 172.16.0.144 (ip where i connect to the portal on port 30043) on port 443, on RECV pcap, I can see SYN on port 30043 from ip 172.16.0.144.&lt;/P&gt;&lt;P&gt;Question is why traffic is dropped on 443 ? I have rules like in the tutorial for it.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Sep 2018 19:44:43 GMT</pubDate>
    <dc:creator>Jborgeaud</dc:creator>
    <dc:date>2018-09-25T19:44:43Z</dc:date>
    <item>
      <title>Global Protect, use custom port for portal, followed the tutorial on paloaltonetwork</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-use-custom-port-for-portal-followed-the-tutorial/m-p/231802#M66552</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I followed the tutorial :&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-GlobalProtect-Portal-Page-to-be-Accessed-on-any/ta-p/53460" target="_blank"&gt;How to Configure GlobalProtect Portal Page to be Accessed on any Port&lt;/A&gt;&amp;nbsp;but it's not working.&lt;/P&gt;&lt;P&gt;When I connect using browser I get an error. I see in monitor that the port is accessed and I see the rules for the nat as well, but in the application it's written "incomplete". How can I debug it further ?&lt;/P&gt;&lt;P&gt;Thanks for help.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 19:10:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-use-custom-port-for-portal-followed-the-tutorial/m-p/231802#M66552</guid>
      <dc:creator>Jborgeaud</dc:creator>
      <dc:date>2018-09-21T19:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect, use custom port for portal, followed the tutorial on paloaltonetwork</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-use-custom-port-for-portal-followed-the-tutorial/m-p/231811#M66554</link>
      <description>&lt;P&gt;HEllo,&lt;/P&gt;&lt;P&gt;I would start by looking at the logs to see if/where the traffic is getting blocked. My guess is that its probably a typo somewhere and its causing a block?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 19:26:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-use-custom-port-for-portal-followed-the-tutorial/m-p/231811#M66554</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-09-21T19:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect, use custom port for portal, followed the tutorial on paloaltonetwork</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-use-custom-port-for-portal-followed-the-tutorial/m-p/231899#M66582</link>
      <description>&lt;P&gt;There is no typo.&lt;/P&gt;&lt;P&gt;Here is the screenshot of the monitor:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2018-09-22-18-19-12.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16720iB2B92A0E0A9B5A1C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2018-09-22-18-19-12.png" alt="2018-09-22-18-19-12.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Sep 2018 16:22:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-use-custom-port-for-portal-followed-the-tutorial/m-p/231899#M66582</guid>
      <dc:creator>Jborgeaud</dc:creator>
      <dc:date>2018-09-22T16:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect, use custom port for portal, followed the tutorial on paloaltonetwork</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-use-custom-port-for-portal-followed-the-tutorial/m-p/231903#M66583</link>
      <description>&lt;P&gt;pics of loopback:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2018-09-22-18-23-29.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16721i9AEE577056D1A33B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2018-09-22-18-23-29.png" alt="2018-09-22-18-23-29.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;screen of nat:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2018-09-22-18-25-20.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16722i6AF1587072EA3C11/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2018-09-22-18-25-20.png" alt="2018-09-22-18-25-20.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;security rules:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2018-09-22-18-26-25.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16723i092CBBF6A313827E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2018-09-22-18-26-25.png" alt="2018-09-22-18-26-25.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We see that all rules has count, means they are triggered...&lt;/P&gt;&lt;P&gt;And inside the monitr they are no block, I even override intra/interzone to show inside the logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Sep 2018 16:28:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-use-custom-port-for-portal-followed-the-tutorial/m-p/231903#M66583</guid>
      <dc:creator>Jborgeaud</dc:creator>
      <dc:date>2018-09-22T16:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect, use custom port for portal, followed the tutorial on paloaltonetwork</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-use-custom-port-for-portal-followed-the-tutorial/m-p/231913#M66585</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98103"&gt;@Jborgeaud&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I would take a look at your routing with that NAT statement in place. Your logs don't seem to show it due to where you cut them off, but are you showing any received traffic at all or just sent?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Sep 2018 19:12:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-use-custom-port-for-portal-followed-the-tutorial/m-p/231913#M66585</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-22T19:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect, use custom port for portal, followed the tutorial on paloaltonetwork</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-use-custom-port-for-portal-followed-the-tutorial/m-p/231914#M66586</link>
      <description>Sorry but I didnt understand what you mean.&lt;BR /&gt;there is no routing, only default route 0.0.0.0/0 on the next hope, and if I remove loopback, nat and loopback ip on the portal/ge, the portal is working from outside using port 443.</description>
      <pubDate>Sat, 22 Sep 2018 19:19:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-use-custom-port-for-portal-followed-the-tutorial/m-p/231914#M66586</guid>
      <dc:creator>Jborgeaud</dc:creator>
      <dc:date>2018-09-22T19:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect, use custom port for portal, followed the tutorial on paloaltonetwork</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-use-custom-port-for-portal-followed-the-tutorial/m-p/232323#M66653</link>
      <description>&lt;P&gt;Just to add some new information.&lt;/P&gt;&lt;P&gt;After applying the NAT rules, I see on the other router ARP message like this: Broadcast ARP Gratuitous&amp;nbsp; request for 172.16.0.254 ( duplicate use of 172.16.0.254 detected).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;172.16.0.254 == my second router IP and the configured nextHop on the palo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The network diagram is the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;palo with ip internal 192.168.200.1 and ip external 172.16.0.200 connected to a router with ip 172.16.0.254.&lt;/P&gt;&lt;P&gt;I'm wondering why adding the nat rules make this message appears.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After doing packet capture on the palo, I can see in the DROP pcap, SYN from 172.16.0.144 (ip where i connect to the portal on port 30043) on port 443, on RECV pcap, I can see SYN on port 30043 from ip 172.16.0.144.&lt;/P&gt;&lt;P&gt;Question is why traffic is dropped on 443 ? I have rules like in the tutorial for it.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 19:44:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-use-custom-port-for-portal-followed-the-tutorial/m-p/232323#M66653</guid>
      <dc:creator>Jborgeaud</dc:creator>
      <dc:date>2018-09-25T19:44:43Z</dc:date>
    </item>
  </channel>
</rss>

