<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't browse web pages in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380968#M89712</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp; i will keep testing and TS, as you mentioned it's a DNS issue.&lt;/P&gt;&lt;P&gt;I will back to you&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jan 2021 13:23:09 GMT</pubDate>
    <dc:creator>wzahri</dc:creator>
    <dc:date>2021-01-20T13:23:09Z</dc:date>
    <item>
      <title>Can't browse web pages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380469#M89671</link>
      <description>&lt;P&gt;Hello all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm new in Paloalto firewalls, i'm doing a migration from Fortigate to PA220. i configured all interfaces, router... but I'm struggling with Policies&lt;/P&gt;&lt;P&gt;attached the basic policy i created to allow my LAN users to access internet:&lt;/P&gt;&lt;P&gt;After testing the PA:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;users can only ping to internet eg: 8.8.8.8&lt;/LI&gt;&lt;LI&gt;users can access website using IP address not with the URL&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;PS: we have an internal DNS, Activedirectory, but in the PA220 i configured the DNS using 8.8.8.8 "Attached config"&lt;/P&gt;&lt;P&gt;PS: NAT configured "Attached config"&lt;/P&gt;&lt;P&gt;can you please advice if i'm missing something.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dns config.PNG" style="width: 496px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29578i705AD9DA901792EB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="dns config.PNG" alt="dns config.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT config.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29580i5F12ECB05D879C3F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NAT config.PNG" alt="NAT config.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="policy.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29579i9F1409CCE92266BF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="policy.PNG" alt="policy.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 10:51:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380469#M89671</guid>
      <dc:creator>wzahri</dc:creator>
      <dc:date>2021-01-18T10:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can't browse web pages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380541#M89676</link>
      <description>&lt;P&gt;the 8.8.8.8 you show in the screenshot is only used by the management interface of the firewall itself. you do have a security policy that would allow dns coming from your network to go out to the internet&lt;/P&gt;&lt;P&gt;did you add dns servers to your dhcp options so clients are issued with dns servers (your AD)? (and if the AD is being assigned, did you verify the AD has access to the internet?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 14:56:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380541#M89676</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-01-18T14:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: Can't browse web pages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380544#M89677</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;for your reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't configure a policy that would allow dns coming from DMZ" AD+DNS" to ==&amp;gt; Internet, i will configure it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for your second point: the active directory is acting also as an DHCP so i configured a DHCP relay in the PaloAlto.&lt;/P&gt;&lt;P&gt;i have to verify if the AD have access to internet also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the policies to go out to internet are correct or maybe i have to change something ?&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dhcp rely.PNG" style="width: 561px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29583iEF9708851A599A24/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="dhcp rely.PNG" alt="dhcp rely.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 15:12:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380544#M89677</guid>
      <dc:creator>wzahri</dc:creator>
      <dc:date>2021-01-18T15:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: Can't browse web pages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380559#M89678</link>
      <description>&lt;P&gt;Ah ha &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/164482"&gt;@wzahri&lt;/a&gt;&amp;nbsp;! With 3 interfaces things get a little more complex &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You'll want the dhcp relay on the LAN interface pointing to the AD&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rules&lt;/P&gt;&lt;P&gt;From lan to dmz "all AD services (dns, smb, netbios, ....)" Allow&lt;/P&gt;&lt;P&gt;From dmz to untrust dns/ntp/ms-updates allow&lt;/P&gt;&lt;P&gt;From lan to untrust "web apps" allow&lt;/P&gt;&lt;P&gt;From lan+dmz to untrust block log&lt;/P&gt;&lt;P&gt;From lan+dmz interzone block log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 16:19:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380559#M89678</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-01-18T16:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can't browse web pages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380563#M89679</link>
      <description>&lt;P&gt;Great thanks for your reply.&lt;/P&gt;&lt;P&gt;I will configure those policies, perform a test and back to you tomorrow.&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 16:26:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380563#M89679</guid>
      <dc:creator>wzahri</dc:creator>
      <dc:date>2021-01-18T16:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can't browse web pages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380925#M89706</link>
      <description>&lt;P&gt;hi&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately the same issue &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i tried to open all services&amp;nbsp; on Any Any to test&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rules&lt;/P&gt;&lt;P&gt;From lan to dmz "all AD services (dns, smb, netbios, ....)" ==&amp;gt; Allow Any Any&lt;/P&gt;&lt;P&gt;From dmz to untrust dns/ntp/ms-updates allow==&amp;gt; Any Any&lt;/P&gt;&lt;P&gt;From lan to untrust "web apps" allow==&amp;gt; Any Any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do i have to configure something in "service routing" ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 08:56:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380925#M89706</guid>
      <dc:creator>wzahri</dc:creator>
      <dc:date>2021-01-20T08:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Can't browse web pages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380960#M89708</link>
      <description>&lt;P&gt;the service route is only used by the management interface of the firewall, it is used when the physical mgmt interface is located in an oob network that has no internet access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you have&amp;nbsp; any any open in all directions and you can only reach IP addresses, there must be something wrong with how DNS is resolved&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you check which DNS server is on your clients&lt;/P&gt;&lt;P&gt;what if you replace that with 1.1.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in case your clients do dns lookups on your AD, can you see those connections in the firewall sessions and is there packets sent AND received ?&lt;/P&gt;&lt;P&gt;set up wireshark on client and AD to see if both see all packets&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then, do the same with AD and it's upstream DNS: do you see dns queries leave and come back? what if you set the upstream ('Forwarders') to 1.1.1.1&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 10:19:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380960#M89708</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-01-20T10:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: Can't browse web pages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380968#M89712</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp; i will keep testing and TS, as you mentioned it's a DNS issue.&lt;/P&gt;&lt;P&gt;I will back to you&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 13:23:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/380968#M89712</guid>
      <dc:creator>wzahri</dc:creator>
      <dc:date>2021-01-20T13:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Can't browse web pages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/382124#M89799</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes it was a DNS Issue. i changed the DNS config in the AD. it's works fine now.&lt;/P&gt;&lt;P&gt;Thank you for your help.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 10:51:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-browse-web-pages/m-p/382124#M89799</guid>
      <dc:creator>wzahri</dc:creator>
      <dc:date>2021-01-26T10:51:38Z</dc:date>
    </item>
  </channel>
</rss>

