<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic New GP deployment - DNS, ping, and tracert work, but no app traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/new-gp-deployment-dns-ping-and-tracert-work-but-no-app-traffic/m-p/257039#M72917</link>
    <description>&lt;P&gt;I've set up a new GP config on a new PA-820 firewall. I have an old firewall I'm replacing, but I'm running them side by side. On the new 820 GP, I can connect with a GP client, and then ping internal servers. I can verify that DNS is working with nslookup using our internal DNS servers and all of the internal resources resolve and can be pinged just fine. I can also ping the GP client from any internal resource. So I believe routing is set up correctly. I can also get to the web just fine on the GP client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, everything outside of DNS, ping, and traceroute to our internal servers just times out. The PA-820 log shows everything is allowed. I have any/any policies set up for GP to LAN and vice versa and the policies are placed at the top. Application traffic appears for the most part to be ID'd correctly; I can see DNS, ping, netbios-ns, ldap, smb, etc. all listed in the application column. However, everything is either "aged-out" (most) or "tcp-rst-from-client" (a few) for the session end reason.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't for the life of me understand why I can ping both ways, but app traffic won't get through. There is no policy blocking it and routing seems to be set up.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas of what to consider? I'm sure this is something dumb I'm missing.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Apr 2019 18:18:30 GMT</pubDate>
    <dc:creator>DigitalAffinity</dc:creator>
    <dc:date>2019-04-10T18:18:30Z</dc:date>
    <item>
      <title>New GP deployment - DNS, ping, and tracert work, but no app traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-gp-deployment-dns-ping-and-tracert-work-but-no-app-traffic/m-p/257039#M72917</link>
      <description>&lt;P&gt;I've set up a new GP config on a new PA-820 firewall. I have an old firewall I'm replacing, but I'm running them side by side. On the new 820 GP, I can connect with a GP client, and then ping internal servers. I can verify that DNS is working with nslookup using our internal DNS servers and all of the internal resources resolve and can be pinged just fine. I can also ping the GP client from any internal resource. So I believe routing is set up correctly. I can also get to the web just fine on the GP client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, everything outside of DNS, ping, and traceroute to our internal servers just times out. The PA-820 log shows everything is allowed. I have any/any policies set up for GP to LAN and vice versa and the policies are placed at the top. Application traffic appears for the most part to be ID'd correctly; I can see DNS, ping, netbios-ns, ldap, smb, etc. all listed in the application column. However, everything is either "aged-out" (most) or "tcp-rst-from-client" (a few) for the session end reason.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't for the life of me understand why I can ping both ways, but app traffic won't get through. There is no policy blocking it and routing seems to be set up.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas of what to consider? I'm sure this is something dumb I'm missing.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 18:18:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-gp-deployment-dns-ping-and-tracert-work-but-no-app-traffic/m-p/257039#M72917</guid>
      <dc:creator>DigitalAffinity</dc:creator>
      <dc:date>2019-04-10T18:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: New GP deployment - DNS, ping, and tracert work, but no app traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-gp-deployment-dns-ping-and-tracert-work-but-no-app-traffic/m-p/257082#M72930</link>
      <description>&lt;P&gt;May be a silly question but did you add the GP zone to the outbound NAT/Security policies?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 20:58:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-gp-deployment-dns-ping-and-tracert-work-but-no-app-traffic/m-p/257082#M72930</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2019-04-10T20:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: New GP deployment - DNS, ping, and tracert work, but no app traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-gp-deployment-dns-ping-and-tracert-work-but-no-app-traffic/m-p/257108#M72938</link>
      <description>&lt;P&gt;I solved it. The firewall config was correct. I forgot to add the correct route to the core switch. It had to be something simple.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 23:58:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-gp-deployment-dns-ping-and-tracert-work-but-no-app-traffic/m-p/257108#M72938</guid>
      <dc:creator>DigitalAffinity</dc:creator>
      <dc:date>2019-04-10T23:58:08Z</dc:date>
    </item>
  </channel>
</rss>

