<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Traffic from GlobalProtect stop working after upgrade from 8.1.11 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-globalprotect-stop-working-after-upgrade-from-8-1/m-p/335478#M84544</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have two PaloAlto 3020 in an active-passive cluster. PanOS 8.1.11 is nstalled on both. Everything works correctly, internal traffic, traffic from GP Client, vpn tunnels. GP clinets connect, sends HIPs, Palo recieves this HIPs, traffic is passing trough according to rules.&lt;/P&gt;&lt;P&gt;The problem is that when I updated one cluster node from version 8.1.11 to 8.1.12 (but checked 8.1.13, add 9.0.8 also) and switch active node to this, using newer software, traffic from the GP client is not passing trough.&lt;BR /&gt;The GP client connects, sends HIPs, Palo recieves this HIPs, but GP traffic does not pass. And there are no traffic logs from GP clients.&lt;/P&gt;&lt;P&gt;The update passed without errors and internal traffic works correctly. Everything except GP traffic.&lt;BR /&gt;Does enybody have suggestions what coud be a problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Greetings&lt;BR /&gt;Jacek&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jun 2020 05:31:47 GMT</pubDate>
    <dc:creator>Jacek_Loszewski</dc:creator>
    <dc:date>2020-06-26T05:31:47Z</dc:date>
    <item>
      <title>Traffic from GlobalProtect stop working after upgrade from 8.1.11</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-globalprotect-stop-working-after-upgrade-from-8-1/m-p/335478#M84544</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have two PaloAlto 3020 in an active-passive cluster. PanOS 8.1.11 is nstalled on both. Everything works correctly, internal traffic, traffic from GP Client, vpn tunnels. GP clinets connect, sends HIPs, Palo recieves this HIPs, traffic is passing trough according to rules.&lt;/P&gt;&lt;P&gt;The problem is that when I updated one cluster node from version 8.1.11 to 8.1.12 (but checked 8.1.13, add 9.0.8 also) and switch active node to this, using newer software, traffic from the GP client is not passing trough.&lt;BR /&gt;The GP client connects, sends HIPs, Palo recieves this HIPs, but GP traffic does not pass. And there are no traffic logs from GP clients.&lt;/P&gt;&lt;P&gt;The update passed without errors and internal traffic works correctly. Everything except GP traffic.&lt;BR /&gt;Does enybody have suggestions what coud be a problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Greetings&lt;BR /&gt;Jacek&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 05:31:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-globalprotect-stop-working-after-upgrade-from-8-1/m-p/335478#M84544</guid>
      <dc:creator>Jacek_Loszewski</dc:creator>
      <dc:date>2020-06-26T05:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from GlobalProtect stop working after upgrade from 8.1.11</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-globalprotect-stop-working-after-upgrade-from-8-1/m-p/335503#M84547</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139199"&gt;@Jacek_Loszewski&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check for the user names listed in the logs (compare it with the ones from the working PAN). If the user name (format) is not different, then you need to adjust the authentication profile.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 10:50:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-globalprotect-stop-working-after-upgrade-from-8-1/m-p/335503#M84547</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2020-06-26T10:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from GlobalProtect stop working after upgrade from 8.1.11</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-globalprotect-stop-working-after-upgrade-from-8-1/m-p/335779#M84636</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83320"&gt;@JoergSchuetter&lt;/a&gt;- thank you for your reply. You were right. There is a problem with format of the user names.&lt;BR /&gt;domain: acme.local - UPN: user@acme.local&lt;/P&gt;&lt;P&gt;domain name (pre-win200) is: &lt;EM&gt;Dom&lt;/EM&gt; so&amp;nbsp;&lt;SPAN class="st"&gt;sAMAccountName&lt;/SPAN&gt; format is: Dom\user&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="st"&gt;When active node is the one with older software, in HIP log, we have user name in sAMAccountName format- everything working fine.&lt;BR /&gt;When we switch the active node (to the one with newer software) and make a GP connection we have something like this: acme.local\user&lt;BR /&gt;And thats why traffic in not passing trough the policy rules. So, as you say, we need adjust authentication profile.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="st"&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;I don't know how yet, but I hope it will work soon &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="st"&gt;&lt;SPAN class="tlid-translation translation"&gt;Greetings&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="st"&gt;&lt;SPAN class="tlid-translation translation"&gt;Jacek&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 07:54:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-globalprotect-stop-working-after-upgrade-from-8-1/m-p/335779#M84636</guid>
      <dc:creator>Jacek_Loszewski</dc:creator>
      <dc:date>2020-06-29T07:54:47Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from GlobalProtect stop working after upgrade from 8.1.11</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-globalprotect-stop-working-after-upgrade-from-8-1/m-p/335791#M84639</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139199"&gt;@Jacek_Loszewski&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have set the following on my authentication profile (Kerberos):&lt;/P&gt;&lt;P&gt;Realm: ACME.LOCAL (all in capital letters)&lt;/P&gt;&lt;P&gt;User Dmonain: dom (we have all in lower case, not sure if Dom would also work)&lt;/P&gt;&lt;P&gt;Username Modifier: &lt;A href="mailto:%USERINPUT%@ACME.LOCAL" target="_blank"&gt;%USERINPUT%@ACME.LOCAL&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Joerg&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 09:49:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-globalprotect-stop-working-after-upgrade-from-8-1/m-p/335791#M84639</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2020-06-29T09:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from GlobalProtect stop working after upgrade from 8.1.11</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-globalprotect-stop-working-after-upgrade-from-8-1/m-p/338597#M85120</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem solved.&lt;/P&gt;&lt;P data-unlink="true"&gt;I had to change two things. First, as described in this article &lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/user-id/map-users-to-groups.html," target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/user-id/map-users-to-groups.html,&lt;/A&gt; I had to add Alternate Username 1: &lt;SPAN class="ph systemoutput"&gt;userPrincipalName&lt;/SPAN&gt;&amp;nbsp; (in my old settings this field was empty).&lt;/P&gt;&lt;P data-unlink="true"&gt;And secondly, I needed to change Authentication Profile.&lt;/P&gt;&lt;P data-unlink="true"&gt;Type: LDAP&lt;/P&gt;&lt;P data-unlink="true"&gt;Login Attribute: userPrincipalName&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;User domain: dom (lower case, pre-win 2000 format)&amp;nbsp;&amp;nbsp;&amp;nbsp; (was domain.local)&lt;/P&gt;&lt;P data-unlink="true"&gt;Username Modifier: %USERINPUT%&amp;nbsp;&amp;nbsp; (was &lt;A href="mailto:%USERINPUT%@%USERDOMAIN%" target="_blank"&gt;%USERINPUT%@%USERDOMAIN%&lt;/A&gt;&amp;nbsp;)&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Thank you for your help.&lt;/P&gt;&lt;P data-unlink="true"&gt;Greetings&lt;/P&gt;&lt;P data-unlink="true"&gt;Jacek&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 08:11:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-from-globalprotect-stop-working-after-upgrade-from-8-1/m-p/338597#M85120</guid>
      <dc:creator>Jacek_Loszewski</dc:creator>
      <dc:date>2020-07-15T08:11:37Z</dc:date>
    </item>
  </channel>
</rss>

