<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA blocking returned traffic!!! in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-blocking-returned-traffic/m-p/12165#M8918</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try creating a new Zone Protection profile (in Network -&amp;gt; Network Profiles).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the new profile set the "Reject Non-SYN TCP" to no.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apply this zone profile to your zone - sorry can't remember if it will be the internal or external zone!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Aug 2014 13:23:43 GMT</pubDate>
    <dc:creator>ajbool</dc:creator>
    <dc:date>2014-08-14T13:23:43Z</dc:date>
    <item>
      <title>PA blocking returned traffic!!!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-blocking-returned-traffic/m-p/12164#M8917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've deployed PA-500 recently, and I'm experiencing an interesting situation.&lt;/P&gt;&lt;P&gt;PA-500 is deployed in virtual-wire, and I'm filtering only my main ISP connection (ISP 1). The connection for ISP 2 goes directly to the router.&lt;/P&gt;&lt;P&gt;We have a web server, which accepts requests from users through ISP2, and replies back but the router sends the replies through ISP1 (as it is the default connection). This returned traffic is block from PA-500, even though I applied a policy rule to allow everything from inside to outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please if you can provide a solution to this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is a diagram visualizing the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-0 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/14963_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Aug 2014 13:19:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-blocking-returned-traffic/m-p/12164#M8917</guid>
      <dc:creator>Besfort</dc:creator>
      <dc:date>2014-08-14T13:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: PA blocking returned traffic!!!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-blocking-returned-traffic/m-p/12165#M8918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try creating a new Zone Protection profile (in Network -&amp;gt; Network Profiles).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the new profile set the "Reject Non-SYN TCP" to no.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apply this zone profile to your zone - sorry can't remember if it will be the internal or external zone!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Aug 2014 13:23:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-blocking-returned-traffic/m-p/12165#M8918</guid>
      <dc:creator>ajbool</dc:creator>
      <dc:date>2014-08-14T13:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: PA blocking returned traffic!!!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-blocking-returned-traffic/m-p/12166#M8919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot ajbool, it is working &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;. I had to apply it on the internal zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-B&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Aug 2014 14:42:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-blocking-returned-traffic/m-p/12166#M8919</guid>
      <dc:creator>Besfort</dc:creator>
      <dc:date>2014-08-14T14:42:14Z</dc:date>
    </item>
  </channel>
</rss>

