<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Couldn't access link &amp;quot;www.santander.com.ar&amp;quot; from global prote in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/couldn-t-access-link-quot-www-santander-com-ar-quot-from-global/m-p/347179#M86598</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/154391"&gt;@Max.Segura&lt;/a&gt;&amp;nbsp;sure , I have updated with internal and VPN users logs for your reference&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LEDV-TCSNetwork_0-1599472568027.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27638i32CD0492DFB4F25F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="LEDV-TCSNetwork_0-1599472568027.png" alt="LEDV-TCSNetwork_0-1599472568027.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LEDV-TCSNetwork_1-1599472657001.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27639i9422E230B6846134/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="LEDV-TCSNetwork_1-1599472657001.png" alt="LEDV-TCSNetwork_1-1599472657001.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Sep 2020 09:58:37 GMT</pubDate>
    <dc:creator>LEDV-TCSNetwork</dc:creator>
    <dc:date>2020-09-07T09:58:37Z</dc:date>
    <item>
      <title>Couldn't access link "www.santander.com.ar" from global protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couldn-t-access-link-quot-www-santander-com-ar-quot-from-global/m-p/347009#M86571</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Users couldn't access the&amp;nbsp; link "&lt;A href="http://www.santander.com.ar" target="_blank"&gt;www.santander.com.ar&lt;/A&gt;" from global protect VPN, this is a normal bank related link so everyone can access though outside network, In our office structure Trust-VPN &amp;amp; Trust-Internal both sources zone are allowed to access&amp;nbsp;"&lt;A href="http://www.santander.com.ar" target="_blank"&gt;www.santander.com.ar&lt;/A&gt;" with general policies. As per policy Trust-Internal user have access the link through "PAN-INT2EXT URL FILTER" rule but Trust-VPN couldn't access the error is below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hit policy&amp;nbsp;"PAN-INT2EXT URL FILTER update" and application - incomplete and session end reason - aged out&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone please help to fix the issue&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 22:01:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couldn-t-access-link-quot-www-santander-com-ar-quot-from-global/m-p/347009#M86571</guid>
      <dc:creator>LEDV-TCSNetwork</dc:creator>
      <dc:date>2020-09-04T22:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: Couldn't access link "www.santander.com.ar" from global prote</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couldn-t-access-link-quot-www-santander-com-ar-quot-from-global/m-p/347026#M86574</link>
      <description>&lt;P&gt;It's a bit difficult to picture this, will you be able to upload a picture with your security policies? Also, what does the Detail Log View report?&lt;/P&gt;</description>
      <pubDate>Sat, 05 Sep 2020 01:33:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couldn-t-access-link-quot-www-santander-com-ar-quot-from-global/m-p/347026#M86574</guid>
      <dc:creator>Max.Segura</dc:creator>
      <dc:date>2020-09-05T01:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Couldn't access link "www.santander.com.ar" from global prote</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couldn-t-access-link-quot-www-santander-com-ar-quot-from-global/m-p/347050#M86581</link>
      <description>&lt;P&gt;I tested on my PC behind the PA i see same behaviour.&lt;/P&gt;
&lt;P&gt;Did the PCAP no drops.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did this ever worked?&lt;/P&gt;
&lt;P&gt;Only way to know the exact reason is to enable debugging on the PA.&lt;/P&gt;
&lt;P&gt;If i get time today i will do that and keep you posted.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Sep 2020 17:33:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couldn-t-access-link-quot-www-santander-com-ar-quot-from-global/m-p/347050#M86581</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-09-05T17:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: Couldn't access link "www.santander.com.ar" from global prote</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couldn-t-access-link-quot-www-santander-com-ar-quot-from-global/m-p/347114#M86588</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/151301"&gt;@LEDV-TCSNetwork&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tested again today saw this Global counter incremented&lt;/P&gt;
&lt;P&gt;tcp_drop_packet 2 1 warn tcp pktproc packets dropped because of failure in tcp reassembly&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;do you have uplink to more than one ISP?&lt;/P&gt;
&lt;P&gt;In PCAP today i saw fw was dropping syn ack from the server i think might be&amp;nbsp; because it was receiving syn ack more than 5 secs due to this config&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-----&amp;gt;Session timeout&lt;BR /&gt;TCP default timeout: 3600 secs&lt;BR /&gt;TCP session timeout before SYN-ACK received: 5 secs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my case i have single link to ISP and i did below changes to make it work only for testing purposes:&lt;/P&gt;
&lt;P&gt;In Prod I do not recommend to make those changes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;set deviceconfig setting tcp asymmetric-path bypass&lt;/P&gt;
&lt;P&gt;set deviceconfig setting session tcp-reject-non-syn no&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It was working fine then then i undo my change&amp;nbsp; via&lt;/P&gt;
&lt;P&gt;going to config mode&amp;nbsp;&lt;/P&gt;
&lt;P&gt;set deviceconfig setting tcp asymmetric-path drop&lt;/P&gt;
&lt;P&gt;set deviceconfig setting session tcp-reject-non-syn yes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since then i am able to access website fine&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Sep 2020 21:28:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couldn-t-access-link-quot-www-santander-com-ar-quot-from-global/m-p/347114#M86588</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-09-06T21:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Couldn't access link "www.santander.com.ar" from global prote</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couldn-t-access-link-quot-www-santander-com-ar-quot-from-global/m-p/347175#M86596</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp; sorry for the late!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your update, Actually that was in data center firewall and it's in production so i am not sure can i make the changes, we are using 7 gateways on that firewall for global protect VPN, and that issue is only for VPN users&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So please confirm whether can i make the changes or not,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 08:58:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couldn-t-access-link-quot-www-santander-com-ar-quot-from-global/m-p/347175#M86596</guid>
      <dc:creator>LEDV-TCSNetwork</dc:creator>
      <dc:date>2020-09-07T08:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: Couldn't access link "www.santander.com.ar" from global prote</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couldn-t-access-link-quot-www-santander-com-ar-quot-from-global/m-p/347179#M86598</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/154391"&gt;@Max.Segura&lt;/a&gt;&amp;nbsp;sure , I have updated with internal and VPN users logs for your reference&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LEDV-TCSNetwork_0-1599472568027.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27638i32CD0492DFB4F25F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="LEDV-TCSNetwork_0-1599472568027.png" alt="LEDV-TCSNetwork_0-1599472568027.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LEDV-TCSNetwork_1-1599472657001.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27639i9422E230B6846134/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="LEDV-TCSNetwork_1-1599472657001.png" alt="LEDV-TCSNetwork_1-1599472657001.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 09:58:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couldn-t-access-link-quot-www-santander-com-ar-quot-from-global/m-p/347179#M86598</guid>
      <dc:creator>LEDV-TCSNetwork</dc:creator>
      <dc:date>2020-09-07T09:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: Couldn't access link "www.santander.com.ar" from global prote</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couldn-t-access-link-quot-www-santander-com-ar-quot-from-global/m-p/347693#M86658</link>
      <description>&lt;P&gt;As PA is dropping the syn ack from the server as it is taking too long.&lt;/P&gt;
&lt;P&gt;See below link.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boBJCAY" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boBJCAY&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had to make above change to make it work.&lt;/P&gt;
&lt;P&gt;I will not recommend you above change as I do not know your environment.&lt;/P&gt;
&lt;P&gt;For now their is no other way seems to access that website behind the PA firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 21:29:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couldn-t-access-link-quot-www-santander-com-ar-quot-from-global/m-p/347693#M86658</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-09-08T21:29:28Z</dc:date>
    </item>
  </channel>
</rss>

