<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Website issue. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/235323#M67474</link>
    <description>&lt;P&gt;Hi to everyone!&lt;/P&gt;&lt;P&gt;We have one site - halqa.az, which I can't give access to.&lt;/P&gt;&lt;P&gt;I have permitted everything on policies, permitted everything on decryption, still no success.&lt;/P&gt;&lt;P&gt;What should be else permitted? Maybe some of you will be able to help me.&lt;/P&gt;&lt;P&gt;Maybe there is any timeout issue or anything else.&lt;/P&gt;</description>
    <pubDate>Mon, 15 Oct 2018 06:07:36 GMT</pubDate>
    <dc:creator>AzerbaijanSupermarkets</dc:creator>
    <dc:date>2018-10-15T06:07:36Z</dc:date>
    <item>
      <title>Website issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/235323#M67474</link>
      <description>&lt;P&gt;Hi to everyone!&lt;/P&gt;&lt;P&gt;We have one site - halqa.az, which I can't give access to.&lt;/P&gt;&lt;P&gt;I have permitted everything on policies, permitted everything on decryption, still no success.&lt;/P&gt;&lt;P&gt;What should be else permitted? Maybe some of you will be able to help me.&lt;/P&gt;&lt;P&gt;Maybe there is any timeout issue or anything else.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 06:07:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/235323#M67474</guid>
      <dc:creator>AzerbaijanSupermarkets</dc:creator>
      <dc:date>2018-10-15T06:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Website issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/235405#M67496</link>
      <description>&lt;P&gt;PAN-DB categorizes&amp;nbsp;&lt;SPAN&gt;halqa.az as Insufficient Content&amp;nbsp; (&lt;A href="https://urlfiltering.paloaltonetworks.com" target="_blank"&gt;https://urlfiltering.paloaltonetworks.com&lt;/A&gt;) - which you may be blocking. Can you check for any blocks in the URL Filtering Log?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 16:26:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/235405#M67496</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-10-15T16:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: Website issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/235459#M67514</link>
      <description>&lt;P&gt;Good day!&lt;/P&gt;&lt;P&gt;There are no logs. Only timeouts. This site is some kind of test page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logs.jpg" style="width: 687px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17162i224DED4490E92F3E/image-dimensions/687x285/is-moderation-mode/true?v=v2" width="687" height="285" role="button" title="logs.jpg" alt="logs.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="halqa.az.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17161iDC428D80FCA2A3E5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="halqa.az.jpg" alt="halqa.az.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 09:01:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/235459#M67514</guid>
      <dc:creator>AzerbaijanSupermarkets</dc:creator>
      <dc:date>2018-10-16T09:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Website issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/235465#M67515</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also there are such kind of logs - incomplete and aged-out.&lt;/P&gt;&lt;P&gt;this public ip is an ip of this server(halqa.az).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="incomplete.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17164i0A1232947326AAE6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="incomplete.jpg" alt="incomplete.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 11:05:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/235465#M67515</guid>
      <dc:creator>AzerbaijanSupermarkets</dc:creator>
      <dc:date>2018-10-16T11:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: Website issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/235554#M67531</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Edit the columns to include 'Log Subtype'. I have see that sometimes this will be deny and the action is allow. To adjust the columns view, hover the mouse above one of the title fileds and click the down arrow. Then you can select the one you want.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 16:14:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/235554#M67531</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-10-16T16:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: Website issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/243481#M69614</link>
      <description>&lt;P&gt;Hello ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I faced a similar issue where the the website was not accessible when the traffic goes via Paloalto device. But the website is accessible from other network without PA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This may be due to the packets from the web Server not having the window-scale information inside TCP packets. Paloalto will by default drop such TCP packets even though traffic is allowed in security policy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For this you can check the TCP settings in Device--&amp;gt; Setup--&amp;gt; Session--&amp;gt; TCP Settings, change the Asymmetric path to bypass ( By default it will be drop )&lt;/P&gt;&lt;P&gt;It worked for me..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will be the mis configuration in Web Server. If the Window-Scale details are not seen in TCP packets from Server reply, paloalto considers it as a asymmetric reply and will drop.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we can configure the Zone protection profile as well on the Untrust zone as well under ZoneProtection profile --&amp;gt; add --&amp;gt; Packet based Attack Protection -- TCP Drop --&amp;gt; Asymmetric Drop --&amp;gt; Bypass. And call this profile in Zone&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But as a security best practice this is not recommended as it&amp;nbsp;might&amp;nbsp;give chance to attacks like&amp;nbsp;&lt;SPAN&gt;IP spoofing and sequence number prediction.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We cannot have IP based or URL based bypass for this kind of issue.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sandeep&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 13:11:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/243481#M69614</guid>
      <dc:creator>Sandeep_R</dc:creator>
      <dc:date>2018-12-17T13:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Website issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/243501#M69618</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/94380"&gt;@Sandeep_R&lt;/a&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Are you sure that window-scale information missing is solved by bypassing Assymmetric path? Because asymmetric routing should just be the fact that path from client to server isn't mirrored for the path from server to client (for example traffic from client to server does go through the firewall, but for server to client it doesn't)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76179"&gt;@AzerbaijanSupermarkets&lt;/a&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When you click in the traffic log on the traffic from your client to the server, do you&amp;nbsp;only see packets received or also sent?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And possibly stupid question, but are you sure your traffic from your public ip isn't being dropped on their end?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 15:04:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/243501#M69618</guid>
      <dc:creator>Rikkert_Kooy</dc:creator>
      <dc:date>2018-12-17T15:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: Website issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/243523#M69619</link>
      <description>&lt;P&gt;halqa.az resolves to&amp;nbsp;85.132.12.14&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Monitor &amp;gt; Packet Capture &amp;gt; Manage Filters&lt;BR /&gt;Add 2 filters.&lt;BR /&gt;One where 85.132.12.14 is source.&lt;BR /&gt;One where 85.132.12.14 is destination.&lt;BR /&gt;Turn filtering on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Go to cli.&lt;BR /&gt;&amp;gt; show counter global filter delta yes packet-filter yes&lt;/P&gt;&lt;P&gt;Now try to access website.&lt;BR /&gt;And then run same command again.&lt;/P&gt;&lt;P&gt;&amp;gt; show counter global filter delta yes packet-filter yes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other option is to see if anything was dropped with severity drop.&lt;BR /&gt;&amp;gt; show counter global filter delta yes packet-filter yes severity drop&lt;/P&gt;&lt;P&gt;Switch off filter and remove 2 filters added before.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 16:26:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-issue/m-p/243523#M69619</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-12-17T16:26:25Z</dc:date>
    </item>
  </channel>
</rss>

