<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Website getting blocked in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/website-getting-blocked/m-p/279563#M75724</link>
    <description>&lt;P&gt;Hi Reaper&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If no syn-ack is received from the webserver, the problem will be on the outside of the firewall or on the webserver itself&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Answer : For your information, I can able to reach the same website from the external network (outside network). Through the palo alto firewall only I couldn't access the website.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Need to check with ISP side aslo and let you know.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mohammed Asik&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jul 2019 11:20:13 GMT</pubDate>
    <dc:creator>MohammedAsik</dc:creator>
    <dc:date>2019-07-26T11:20:13Z</dc:date>
    <item>
      <title>Website getting blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-getting-blocked/m-p/279508#M75714</link>
      <description>&lt;P&gt;Hi Team&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have PA 220 firewall with 8.1.5 PAN os version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have tried to reach one particular website but its not reachable. When we checked the traffic logs that application was shown as "incomplete" and the end session reason was aged-out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note : Same website can be reached by external network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For testing purpose, we have created one security policy on the top as below&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sec policy.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20790i96CE8D0B501E063E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Sec policy.PNG" alt="Sec policy.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After that also particular&amp;nbsp; we are getting the same error "application incomplete" in the traffic logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have took the packet capture and its received only RX and Firewall files. No drops and tranmit packet we are not found&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per the packet capture logs, Its send syn packets only. No SYN-ACK packets we are not received.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to fix the issue? Please help us&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mohammed Asik&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2019 05:33:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-getting-blocked/m-p/279508#M75714</guid>
      <dc:creator>MohammedAsik</dc:creator>
      <dc:date>2019-07-26T05:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: Website getting blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-getting-blocked/m-p/279515#M75716</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/106720"&gt;@MohammedAsik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If no syn-ack is received from the webserver, the problem will be on the outside of the firewall or on the webserver itself&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;one thing you can check is to verify that outbound NAT is being applied properly, so the server has the right IP to reply to&lt;/P&gt;
&lt;P&gt;next, you could try traceroute to see if you are able to get to the server IP (there could be a routing or peering issue at the ISP level, or your IP could have been blacklisted on the server)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2019 06:43:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-getting-blocked/m-p/279515#M75716</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-07-26T06:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: Website getting blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-getting-blocked/m-p/279563#M75724</link>
      <description>&lt;P&gt;Hi Reaper&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If no syn-ack is received from the webserver, the problem will be on the outside of the firewall or on the webserver itself&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Answer : For your information, I can able to reach the same website from the external network (outside network). Through the palo alto firewall only I couldn't access the website.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Need to check with ISP side aslo and let you know.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mohammed Asik&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2019 11:20:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-getting-blocked/m-p/279563#M75724</guid>
      <dc:creator>MohammedAsik</dc:creator>
      <dc:date>2019-07-26T11:20:13Z</dc:date>
    </item>
    <item>
      <title>Re: Website getting blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-getting-blocked/m-p/279753#M75759</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/106720"&gt;@MohammedAsik&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi Reaper&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If no syn-ack is received from the webserver, the problem will be on the outside of the firewall or on the webserver itself&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Answer : For your information, I can able to reach the same website from the external network (outside network). Through the palo alto firewall only I couldn't access the website.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Need to check with ISP side aslo and let you know.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mohammed Asik&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;edit&amp;gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp; already came up with all my cool ideas.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 14:21:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-getting-blocked/m-p/279753#M75759</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-07-29T14:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: Website getting blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-getting-blocked/m-p/279839#M75778</link>
      <description>But wait, theres more: when you set up packet filters for packet capture, make sure you set filters in both directions and both pre- and post nat. See if the sequence numbers pan out, and verify the server isnt requesting some weird parameters the firewall wont support. For example: is there a smaller MTU somewhere? You may need to enable TCP MSS to circumvent that (if so, check if the server gets the message and is not  ignoring it)
Double check if outbound NAT is alright, check if the IP can independently traced to your firewall from the outside (potential arp issues on outside)</description>
      <pubDate>Mon, 29 Jul 2019 19:49:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-getting-blocked/m-p/279839#M75778</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-07-29T19:49:03Z</dc:date>
    </item>
  </channel>
</rss>

