<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic not able to access certain web sites from host behind PAN firewalls in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/not-able-to-access-certain-web-sites-from-host-behind-pan/m-p/380856#M89700</link>
    <description>&lt;P&gt;I am trying to access &lt;A href="http://www.brokercheck.com" target="_blank"&gt;http://www.brokercheck.com&lt;/A&gt; from behind the PAN firewall via dynamic NAT without any success.&amp;nbsp; I have other customers behind different PAN firewalls, regardless of PAN OS version, with the same issue access website &lt;A href="http://www.brokercheck.com" target="_blank"&gt;http://www.brokercheck.com.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The FW rule is wide open "any any accept log"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It works for customers NOT behind PAN firewalls.&amp;nbsp; In other words, hosts behind Cisco ASA and checkpoint firewalls can access &lt;A href="http://www.brokercheck.com" target="_blank"&gt;http://www.brokercheck.com&lt;/A&gt; without any issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a TAC case opened with PaloAlto support and waiting to hear back from them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jan 2021 19:41:34 GMT</pubDate>
    <dc:creator>dtran</dc:creator>
    <dc:date>2021-01-19T19:41:34Z</dc:date>
    <item>
      <title>not able to access certain web sites from host behind PAN firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/not-able-to-access-certain-web-sites-from-host-behind-pan/m-p/380856#M89700</link>
      <description>&lt;P&gt;I am trying to access &lt;A href="http://www.brokercheck.com" target="_blank"&gt;http://www.brokercheck.com&lt;/A&gt; from behind the PAN firewall via dynamic NAT without any success.&amp;nbsp; I have other customers behind different PAN firewalls, regardless of PAN OS version, with the same issue access website &lt;A href="http://www.brokercheck.com" target="_blank"&gt;http://www.brokercheck.com.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The FW rule is wide open "any any accept log"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It works for customers NOT behind PAN firewalls.&amp;nbsp; In other words, hosts behind Cisco ASA and checkpoint firewalls can access &lt;A href="http://www.brokercheck.com" target="_blank"&gt;http://www.brokercheck.com&lt;/A&gt; without any issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a TAC case opened with PaloAlto support and waiting to hear back from them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 19:41:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/not-able-to-access-certain-web-sites-from-host-behind-pan/m-p/380856#M89700</guid>
      <dc:creator>dtran</dc:creator>
      <dc:date>2021-01-19T19:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: not able to access certain web sites from host behind PAN firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/not-able-to-access-certain-web-sites-from-host-behind-pan/m-p/380891#M89704</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41973"&gt;@dtran&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What are you seeing under traffic logs? Traffic logs should give more clarity for this. You can also check few other points like,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.First, check if traffic for below URL is reaching the firewall. If there are any DNS issues on the source system, you won't see any traffic on the firewall.&lt;/P&gt;&lt;P&gt;2. Check if the required security policy is getting applied to below URL traffic on Palo Alto and if security policy is allowing the traffic,&lt;/P&gt;&lt;P&gt;3. Check if any other security policy profile e.g. URL filtering is blocking it.&lt;/P&gt;&lt;P&gt;4. NAT Policy &amp;amp; desired routing is happening on the firewall while accessing below URL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check these points.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 04:17:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/not-able-to-access-certain-web-sites-from-host-behind-pan/m-p/380891#M89704</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-01-20T04:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: not able to access certain web sites from host behind PAN firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/not-able-to-access-certain-web-sites-from-host-behind-pan/m-p/380982#M89714</link>
      <description>&lt;P&gt;No issue with DNS, URL filtering, NAT....&amp;nbsp; Did I mention that if I replace the PAN with Cisco or Checkpoint, I don't have this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This issue is reproducible from multiple customers that are behind the PAN firewalls, from different locations and different ISP.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 13:34:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/not-able-to-access-certain-web-sites-from-host-behind-pan/m-p/380982#M89714</guid>
      <dc:creator>dtran</dc:creator>
      <dc:date>2021-01-20T13:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: not able to access certain web sites from host behind PAN firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/not-able-to-access-certain-web-sites-from-host-behind-pan/m-p/381165#M89730</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41973"&gt;@dtran&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tested URL from my one of the test system which is behind palo alto and URL is working. It gets redirected to &lt;A href="https://brokercheck.finra.org/" target="_blank"&gt;https://brokercheck.finra.org/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 09:35:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/not-able-to-access-certain-web-sites-from-host-behind-pan/m-p/381165#M89730</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-01-21T09:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: not able to access certain web sites from host behind PAN firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/not-able-to-access-certain-web-sites-from-host-behind-pan/m-p/382211#M89821</link>
      <description>&lt;P&gt;I found the solution here:&amp;nbsp; &lt;A href="https://www.networkdefenseblog.com/post/wireshark-tcp-challenge-ack" target="_blank"&gt;https://www.networkdefenseblog.com/post/wireshark-tcp-challenge-ack&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apparently many users who are behind PAN firewalls have issues access this site.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 21:57:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/not-able-to-access-certain-web-sites-from-host-behind-pan/m-p/382211#M89821</guid>
      <dc:creator>dtran</dc:creator>
      <dc:date>2021-01-26T21:57:53Z</dc:date>
    </item>
  </channel>
</rss>

