<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't get traffic to GP VPN clients in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-traffic-to-gp-vpn-clients/m-p/316624#M81411</link>
    <description>&lt;P&gt;I'm trying to figure out how to get traffic from my internal network to my GP VPN clients. At the moment I can't even ping the remote users. They can access all corporate resources without issue I just can't seem to get any traffic out to them. It seems I have this issue with any tunnel.xx interface. Is there something obvious here that I'm missing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm running an 820 with 8.1.6.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Mar 2020 15:24:18 GMT</pubDate>
    <dc:creator>s.Konowalchuk</dc:creator>
    <dc:date>2020-03-16T15:24:18Z</dc:date>
    <item>
      <title>Can't get traffic to GP VPN clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-traffic-to-gp-vpn-clients/m-p/316624#M81411</link>
      <description>&lt;P&gt;I'm trying to figure out how to get traffic from my internal network to my GP VPN clients. At the moment I can't even ping the remote users. They can access all corporate resources without issue I just can't seem to get any traffic out to them. It seems I have this issue with any tunnel.xx interface. Is there something obvious here that I'm missing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm running an 820 with 8.1.6.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 15:24:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-traffic-to-gp-vpn-clients/m-p/316624#M81411</guid>
      <dc:creator>s.Konowalchuk</dc:creator>
      <dc:date>2020-03-16T15:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get traffic to GP VPN clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-traffic-to-gp-vpn-clients/m-p/316662#M81418</link>
      <description>&lt;P&gt;You may want to confirm that the virtual pool of addresses that the GP users are getting is an UNKNOWN/un-used range from your internal network.&amp;nbsp; Too often I see customers using a subnet that is internal to the network, and then the L3 switch does not know how to get them to the users.&amp;nbsp; &amp;nbsp;So routing/subnet is one issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let us know how this works.. provide other detials.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 17:57:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-traffic-to-gp-vpn-clients/m-p/316662#M81418</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-03-16T17:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get traffic to GP VPN clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-traffic-to-gp-vpn-clients/m-p/316663#M81419</link>
      <description>&lt;P&gt;Hi Steve,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes I can confirm that the virtual pool definitely is not used anywhere else in my network. I've also got a static route setup for it same as I do my other networks that terminate on the PA.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 18:10:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-traffic-to-gp-vpn-clients/m-p/316663#M81419</guid>
      <dc:creator>s.Konowalchuk</dc:creator>
      <dc:date>2020-03-16T18:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get traffic to GP VPN clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-traffic-to-gp-vpn-clients/m-p/316671#M81421</link>
      <description>&lt;P&gt;Every setup is different but for me i just have a policy to allow all from trusted zone to vpn tunnel zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 19:35:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-traffic-to-gp-vpn-clients/m-p/316671#M81421</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-03-16T19:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get traffic to GP VPN clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-traffic-to-gp-vpn-clients/m-p/316822#M81448</link>
      <description>&lt;P&gt;I have a similar policy that basically allows my entire IT zone to access any on my Global Protect zone. I don't think its a policy issue so much as a routing issue as I can ping the tunnel gateway but not the individual clients that are remoting in.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2020 18:09:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-traffic-to-gp-vpn-clients/m-p/316822#M81448</guid>
      <dc:creator>s.Konowalchuk</dc:creator>
      <dc:date>2020-03-17T18:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get traffic to GP VPN clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-traffic-to-gp-vpn-clients/m-p/386942#M90323</link>
      <description>&lt;P&gt;I was wondering if you ever found a solution to this?&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2021 00:17:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-traffic-to-gp-vpn-clients/m-p/386942#M90323</guid>
      <dc:creator>jlittle</dc:creator>
      <dc:date>2021-02-20T00:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get traffic to GP VPN clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-traffic-to-gp-vpn-clients/m-p/386943#M90324</link>
      <description>&lt;P&gt;Howdy, there really could only be 2 potential reasons.....&amp;nbsp; security policy to allow the traffic and routing table to permit the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You MUST see traffic in your logs from your inside zone to your globalprotect zone (or whatever)&lt;/P&gt;
&lt;P&gt;If you do not see this traffic, then you are not displaying your logs properly, or you are using intrazone policy (without logging) or you are not logging the rule that it would be hitting... once you see this, then you can confirm in your logs, that you see traffic from the inside interface (whatever that would be) destined to the tunnel interface for GP (whatever that is..)&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2021 00:27:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-traffic-to-gp-vpn-clients/m-p/386943#M90324</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-02-20T00:27:11Z</dc:date>
    </item>
  </channel>
</rss>

