<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Airwatch issue Session Browser Query in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/airwatch-issue-session-browser-query/m-p/272939#M74982</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/109121"&gt;@a.jones&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Your troubleshooting so far is sound and logical. Something is causing the traffic to be dropped silently, that could be intentional or it could be misconfigured routes.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jun 2019 17:58:17 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-06-25T17:58:17Z</dc:date>
    <item>
      <title>Airwatch issue Session Browser Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/airwatch-issue-session-browser-query/m-p/272918#M74977</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a sanity check question to ensure my config and thinking okay.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having issues with VMWare Airwatch traffic to a cloud server for a customer that migrated across to our network. They don't seem to be able to connect to the server for deployments. Traceroute to the server blackholes within VMWare environment. Test from other sources we can connect to the server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My rule allows traffic from the client network out to the server IP on the required port using application airwatch, service as application default. This is patted out to the firewall interface with all other traffic. Logs show rule is being hit but application incomplete indicating the TCP handshake is not completing thereby matching the traceroute issue - no server connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I look at the session browser I get this:&lt;/P&gt;&lt;P&gt;show session id 2700153&lt;/P&gt;&lt;P&gt;Session 2700153&lt;/P&gt;&lt;P&gt;c2s flow:&lt;BR /&gt;source: 10.119.77.16 [Public_99_Inside]&lt;BR /&gt;dst: 169.50.196.24&lt;BR /&gt;proto: 6&lt;BR /&gt;sport: 42319 dport: 443&lt;BR /&gt;state: INIT type: FLOW&lt;BR /&gt;src user: unknown&lt;BR /&gt;dst user: unknown&lt;/P&gt;&lt;P&gt;s2c flow:&lt;BR /&gt;source: 169.50.196.24 [Public_118_Outside]&lt;BR /&gt;dst: 185.111.131.198&lt;BR /&gt;proto: 6&lt;BR /&gt;sport: 443 dport: 49058&lt;BR /&gt;state: INIT type: FLOW&lt;BR /&gt;src user: unknown&lt;BR /&gt;dst user: unknown&lt;/P&gt;&lt;P&gt;Slot : 1&lt;BR /&gt;DP : 0&lt;BR /&gt;index(local): : 2700153&lt;BR /&gt;start time : Tue Jun 25 15:43:12 2019&lt;BR /&gt;timeout : 5 sec&lt;BR /&gt;total byte count(c2s) : 78&lt;BR /&gt;total byte count(s2c) : 0&lt;BR /&gt;layer7 packet count(c2s) : 1&lt;BR /&gt;layer7 packet count(s2c) : 0&lt;BR /&gt;vsys : vsys6&lt;BR /&gt;application : incomplete&lt;BR /&gt;rule : MKC Wifi-2&lt;BR /&gt;service timeout override(index) : False&lt;BR /&gt;session to be logged at end : True&lt;BR /&gt;session in session ager : False&lt;BR /&gt;session updated by HA peer : False&lt;BR /&gt;address/port translation : source&lt;BR /&gt;nat-rule : Internet Nat-1(vsys6)&lt;BR /&gt;layer7 processing : enabled&lt;BR /&gt;URL filtering enabled : False&lt;BR /&gt;session via syn-cookies : False&lt;BR /&gt;session terminated on host : False&lt;BR /&gt;session traverses tunnel : False&lt;BR /&gt;captive portal session : False&lt;BR /&gt;ingress interface : ae2.1530&lt;BR /&gt;egress interface : ae1.1521&lt;BR /&gt;session QoS rule : N/A (class 4)&lt;BR /&gt;tracker stage firewall : Aged out&lt;BR /&gt;end-reason : aged-out&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the fact that there is an s2c flow indicate there is traffic coming back from the server or just effectively timeout traffic? It remains in State INIT and type FLOW - for me it's just due to it aging out and nothing to do with server connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anything else that can be considered that I may have missed? I tried a 1-1 NAT and get the same results. In all cases we can only traceroute so far into VMWare to the server indicating they are blackholing our traffic for some reason. If I traceroute from my desktop, different network I can get to the server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts or advice?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adrian&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 14:55:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/airwatch-issue-session-browser-query/m-p/272918#M74977</guid>
      <dc:creator>a.jones</dc:creator>
      <dc:date>2019-06-25T14:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: Airwatch issue Session Browser Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/airwatch-issue-session-browser-query/m-p/272939#M74982</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/109121"&gt;@a.jones&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Your troubleshooting so far is sound and logical. Something is causing the traffic to be dropped silently, that could be intentional or it could be misconfigured routes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 17:58:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/airwatch-issue-session-browser-query/m-p/272939#M74982</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-06-25T17:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: Airwatch issue Session Browser Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/airwatch-issue-session-browser-query/m-p/273393#M75031</link>
      <description>&lt;P&gt;Thanks. We are chasing the remote end to get them to check the routing through their network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just wanted to ensure my thoughts were correct and I hadn't missed anything obvious.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adrian&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 07:22:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/airwatch-issue-session-browser-query/m-p/273393#M75031</guid>
      <dc:creator>a.jones</dc:creator>
      <dc:date>2019-06-27T07:22:14Z</dc:date>
    </item>
  </channel>
</rss>

