<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connection Issues between servers in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/connection-issues-between-servers/m-p/275132#M75235</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Also check the logs to see where and why you are getting dropped. If you have Application set for any and Service set to Application-default, then the PAN may identify some apps over non-standard ports and block the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However as you mentioned your config, I would highly recommend that you not use any/any from untrust to trust, unless you have another firewall in between. Also there is free training online to help you along.&lt;/P&gt;&lt;P&gt;&lt;A href="https://paloaltonetworks.csod.com/" target="_blank"&gt;https://paloaltonetworks.csod.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As always you can post in here and we'll help out the best we can :).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jul 2019 17:09:59 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2019-07-05T17:09:59Z</dc:date>
    <item>
      <title>Connection Issues between servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connection-issues-between-servers/m-p/275061#M75224</link>
      <description>&lt;P&gt;I'm very new to PAN firewalls and are still learning as I go along, they've only been in a month or so and the only rule is currently set any any from the trust to untrust zones and vice versa.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've got a couple of issues around some connections that traverse our 5250's (LAN to WAN and vice versa) but from the 5250's perspective its not seeing any traffic in the logs for the addresses in question, no deny drops allows nothing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we've done a packet capture from the servers on either end of the connection it shows the traffic leaving but its never seen on the 5250's. We've checked the routing and everything else in between but we've found nothing wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zone protection profile has been disabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anything else that I can check to see if for one reason or another the 5250's are doing something they shouldn't to the traffic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be much appreciated?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 13:47:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connection-issues-between-servers/m-p/275061#M75224</guid>
      <dc:creator>JonHill</dc:creator>
      <dc:date>2019-07-05T13:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: Connection Issues between servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connection-issues-between-servers/m-p/275088#M75229</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/100050"&gt;@JonHill&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Ensure that you've actually enabled logging on the interzone-default policy and ensure you've checked interface counters for any dropped packets. Did you do a PCAP on the actual firewall yet or not? That would be my next stop if everything else checks out so you can see that it's at least hitting the firewall and being processed correctly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 14:38:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connection-issues-between-servers/m-p/275088#M75229</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-07-05T14:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: Connection Issues between servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connection-issues-between-servers/m-p/275132#M75235</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Also check the logs to see where and why you are getting dropped. If you have Application set for any and Service set to Application-default, then the PAN may identify some apps over non-standard ports and block the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However as you mentioned your config, I would highly recommend that you not use any/any from untrust to trust, unless you have another firewall in between. Also there is free training online to help you along.&lt;/P&gt;&lt;P&gt;&lt;A href="https://paloaltonetworks.csod.com/" target="_blank"&gt;https://paloaltonetworks.csod.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As always you can post in here and we'll help out the best we can :).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 17:09:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connection-issues-between-servers/m-p/275132#M75235</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-07-05T17:09:59Z</dc:date>
    </item>
  </channel>
</rss>

