<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Terminal Services Agent allocates ports outside the defined port range in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/344781#M86238</link>
    <description>&lt;P&gt;Hi Chacko42,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;unfortunately, setting the mentioned option does not change the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But thank you for your comment!!&lt;/P&gt;&lt;P&gt;Maybe there are additional options to check?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Marc&lt;/P&gt;</description>
    <pubDate>Thu, 20 Aug 2020 13:03:41 GMT</pubDate>
    <dc:creator>Marc.Luecke</dc:creator>
    <dc:date>2020-08-20T13:03:41Z</dc:date>
    <item>
      <title>Terminal Services Agent allocates ports outside the defined port range</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/343901#M86062</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the problem, that the Terminal Services Agent sometimes allocates ports to users that are out of their port range.&lt;/P&gt;&lt;P&gt;That leads to the usage of wrong security polices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example for one user I configured&amp;nbsp;&lt;SPAN&gt;22800-22999 as the port range.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That user is not allowed to download certain files.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now sometimes the user gets port 58729 allocated and so the session is not matched to that user, a wrong policy gets to work and the download is possible although it should be denied.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The TSA debug log is almost just filled with this error message:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[Error 966]: GetDriverLog3: Device control get drvier log3 fails: 57!!!!&lt;BR /&gt;[Error 966]: GetDriverLog3: Device control get drvier log3 fails: 57!!!!&lt;BR /&gt;[Error 966]: GetDriverLog3: Device control get drvier log3 fails: 57!!!!&lt;BR /&gt;[Error 966]: GetDriverLog3: Device control get drvier log3 fails: 57!!!!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There is no other application in use that could disturb the TSA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Maybe someone encountered this error message and can provide some help?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Would be very much appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Marc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 13:58:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/343901#M86062</guid>
      <dc:creator>Marc.Luecke</dc:creator>
      <dc:date>2020-08-14T13:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal Services Agent allocates ports outside the defined port range</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/343919#M86065</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/123063"&gt;@Marc.Luecke&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What OS version do you have and what TSA version do you use? At the time when this happens, did you check the allocated ports for this user? Did he maybe reach the 200 ports? How many users are connected to that server? Did you verify if the connection on this port really is from that user that tries to download something he should not be allowed?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 16:30:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/343919#M86065</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-08-14T16:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal Services Agent allocates ports outside the defined port range</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/344326#M86153</link>
      <description>&lt;P&gt;Hi Vsys_remo:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will try to answer your questions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What OS version do you have and what TSA version do you use?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- The Terminal Server Agent is running on a Windows Server 2016 in Version 8.1.13-5.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;At the time when this happens, did you check the allocated ports for this user?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- No port allocations Error are shown in the TSA Debug log, so I guess that is not the problem&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Did he maybe reach the 200 ports?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Does not seem like that&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How many users are connected to that server?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;8 - 10 Users&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Did you verify if the connection on this port really is from that user that tries to download something he should not be allowed?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Yes, it's verified through the logs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I hope you can maybe help with that problem?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Marc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 09:15:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/344326#M86153</guid>
      <dc:creator>Marc.Luecke</dc:creator>
      <dc:date>2020-08-18T09:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal Services Agent allocates ports outside the defined port range</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/344374#M86170</link>
      <description>&lt;P&gt;If you don't want the users to fail to a high-port out of range, when the pool is used up, you can enable the check box "fail port binding when available ports are used up"&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 16:25:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/344374#M86170</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2020-08-18T16:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal Services Agent allocates ports outside the defined port range</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/344781#M86238</link>
      <description>&lt;P&gt;Hi Chacko42,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;unfortunately, setting the mentioned option does not change the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But thank you for your comment!!&lt;/P&gt;&lt;P&gt;Maybe there are additional options to check?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Marc&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 13:03:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/344781#M86238</guid>
      <dc:creator>Marc.Luecke</dc:creator>
      <dc:date>2020-08-20T13:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal Services Agent allocates ports outside the defined port range</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/428363#M94712</link>
      <description>&lt;P&gt;Hi Marc.Luecke,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you had this issue resolved. I am experiencing the same issue through Windows Virtual Desktop in Azure. The TS Agent is intermittently allocating out of range ports to users. Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Tanny&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 05:00:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/428363#M94712</guid>
      <dc:creator>WAN-Support</dc:creator>
      <dc:date>2021-08-23T05:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal Services Agent allocates ports outside the defined port range</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/428924#M94809</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/123063"&gt;@Marc.Luecke&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does this problem happen often/constantly?&lt;/P&gt;&lt;P&gt;Even if your TSA version is still supported&amp;nbsp; I would try it with one of the current version (directly version 10.1).&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 20:07:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/428924#M94809</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-08-24T20:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal Services Agent allocates ports outside the defined port range</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/432546#M95756</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/35071"&gt;@WAN-Support&lt;/a&gt;&amp;nbsp; and everyone&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I have the same problem on azure AVDs. Have you been able to resolve it?&lt;/P&gt;&lt;P&gt;For some connections the TSA sets the correct source ports (i.e. 20001) but for many it does not (i.e. 57024). So the mapping fails.&lt;/P&gt;&lt;P&gt;Interestingly it seems like HTTP-connections work and SMB ones don't.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use TSA version 10.0.3&lt;BR /&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;BR /&gt;Andi&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2021 09:16:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/432546#M95756</guid>
      <dc:creator>AndreasTrautmann</dc:creator>
      <dc:date>2021-09-08T09:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal Services Agent allocates ports outside the defined port range</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/435231#M96052</link>
      <description>&lt;P&gt;Kind of strange to reply to ones own post, but there is a little update:&lt;/P&gt;&lt;P&gt;I found other articles about the SMB problematic. It seems a known "issue", that the TS-agent is unable to map all outgoing connections. Some happen at system-level, where the ts-agent cannot intervene. SMB is one of these cases:&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkCCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkCCAS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still even when leaving out SMB we have the problem that the ts-agent intermittently does not work (i.e. with SSL-Connections). For a while it does the source-port-mappings as configured (i.e. src-port 20xyz) and then it stops and we get src-ports 57xyz and our policies don't work anymore.&lt;BR /&gt;Restarting the machine or Service resolves the issue for a while, but not persistently.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas what this could be?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks, best regards&lt;/P&gt;&lt;P&gt;Andi&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 14:19:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/435231#M96052</guid>
      <dc:creator>AndreasTrautmann</dc:creator>
      <dc:date>2021-09-20T14:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal Services Agent allocates ports outside the defined port range</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/582148#M116450</link>
      <description>&lt;P&gt;Was this ever resolved in later versions of the TS Client or PanOS?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2024 14:56:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/582148#M116450</guid>
      <dc:creator>robert.holmes</dc:creator>
      <dc:date>2024-03-29T14:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal Services Agent allocates ports outside the defined port range</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/617233#M121997</link>
      <description>&lt;P&gt;I too am noticing this problem...&amp;nbsp; latest TS agent, 11.0.1.104&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 18:34:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-allocates-ports-outside-the-defined-port/m-p/617233#M121997</guid>
      <dc:creator>cenders</dc:creator>
      <dc:date>2024-11-12T18:34:20Z</dc:date>
    </item>
  </channel>
</rss>

