<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic google home page not loading when remove &amp;quot;service-https&amp;quot; and leave ssl application in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/google-home-page-not-loading-when-remove-quot-service-https-quot/m-p/425684#M94394</link>
    <description>&lt;P&gt;so i have this dual personality thing going on with the PA firewall and am learning, so this might be an easy one. I kind of dont like the requirement to create "application" based rules and then back them up with "service-based" rules. I had this security policy in place and was playing with it:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;RULEBASE1 (old working rulebase):&lt;/P&gt;&lt;P&gt;user2internet&amp;nbsp; allow&amp;nbsp;service-https &amp;amp;&amp;nbsp;service-http&amp;nbsp; &amp;nbsp; (service-based rule)&lt;/P&gt;&lt;P&gt;user2internet&amp;nbsp; allow ftp, ntp, ping&amp;nbsp; &amp;nbsp;(application-based rule)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;RULEBASE2 (new rulebase, trying to migrate to all application base):&lt;/P&gt;&lt;P&gt;user2internet&amp;nbsp; allow&amp;nbsp; &amp;nbsp;service-http&amp;nbsp; &amp;nbsp; (service-based rule)&lt;/P&gt;&lt;P&gt;user2internet&amp;nbsp; allow ftp, ntp, ssl, ping&amp;nbsp; &amp;nbsp;(application-based rule)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my thinking is any https website should use SSL, right? So if i go to a secure site with rulebase1, im using line 1; with rulebase2, i use line 2. Both rules work fine most of the time. in fact rulebase1 is the months-old config so its a fine rule. rulebase2 - not so much!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;under rulebase2, many ssl-enabled websites load, but funny thing: &lt;A href="https://www.google.com" target="_blank"&gt;https://www.google.com&lt;/A&gt;&amp;nbsp;doesnt load.&amp;nbsp; I get some sort of connection reset message - i think from the PA firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what's up here? Why is google special? What other sites wont work under rulebase2? how do I work around this? NOTE: I'm not going to get nickel &amp;amp; dimed by configuring every SSL application under the sun, that a normal use may want to use on the internet. So things like google-base (SSL) will remain unconfigured, but I suspect this has something to do with the problem. maybe big companies, which are special, have their own defined pre-canned PA applications and for some reason, if the PA sees this riding on top of SSL, it still denies the connection - unless that sub-type application (under SSL), is also configured?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Aug 2021 05:21:54 GMT</pubDate>
    <dc:creator>anon4all</dc:creator>
    <dc:date>2021-08-10T05:21:54Z</dc:date>
    <item>
      <title>google home page not loading when remove "service-https" and leave ssl application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-home-page-not-loading-when-remove-quot-service-https-quot/m-p/425684#M94394</link>
      <description>&lt;P&gt;so i have this dual personality thing going on with the PA firewall and am learning, so this might be an easy one. I kind of dont like the requirement to create "application" based rules and then back them up with "service-based" rules. I had this security policy in place and was playing with it:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;RULEBASE1 (old working rulebase):&lt;/P&gt;&lt;P&gt;user2internet&amp;nbsp; allow&amp;nbsp;service-https &amp;amp;&amp;nbsp;service-http&amp;nbsp; &amp;nbsp; (service-based rule)&lt;/P&gt;&lt;P&gt;user2internet&amp;nbsp; allow ftp, ntp, ping&amp;nbsp; &amp;nbsp;(application-based rule)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;RULEBASE2 (new rulebase, trying to migrate to all application base):&lt;/P&gt;&lt;P&gt;user2internet&amp;nbsp; allow&amp;nbsp; &amp;nbsp;service-http&amp;nbsp; &amp;nbsp; (service-based rule)&lt;/P&gt;&lt;P&gt;user2internet&amp;nbsp; allow ftp, ntp, ssl, ping&amp;nbsp; &amp;nbsp;(application-based rule)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my thinking is any https website should use SSL, right? So if i go to a secure site with rulebase1, im using line 1; with rulebase2, i use line 2. Both rules work fine most of the time. in fact rulebase1 is the months-old config so its a fine rule. rulebase2 - not so much!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;under rulebase2, many ssl-enabled websites load, but funny thing: &lt;A href="https://www.google.com" target="_blank"&gt;https://www.google.com&lt;/A&gt;&amp;nbsp;doesnt load.&amp;nbsp; I get some sort of connection reset message - i think from the PA firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what's up here? Why is google special? What other sites wont work under rulebase2? how do I work around this? NOTE: I'm not going to get nickel &amp;amp; dimed by configuring every SSL application under the sun, that a normal use may want to use on the internet. So things like google-base (SSL) will remain unconfigured, but I suspect this has something to do with the problem. maybe big companies, which are special, have their own defined pre-canned PA applications and for some reason, if the PA sees this riding on top of SSL, it still denies the connection - unless that sub-type application (under SSL), is also configured?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 05:21:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-home-page-not-loading-when-remove-quot-service-https-quot/m-p/425684#M94394</guid>
      <dc:creator>anon4all</dc:creator>
      <dc:date>2021-08-10T05:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: google home page not loading when remove "service-https" and leave ssl application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-home-page-not-loading-when-remove-quot-service-https-quot/m-p/425689#M94395</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/180129"&gt;@anon4all&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Normally whenever you see some issues for the traffic passing from PA, traffic logs gives much clarity on traffic being allowed and dropped &lt;EM&gt;(additionally you should have logging enabled on the security policy)&amp;nbsp;&lt;/EM&gt;and with this, you can see why traffic is not working. Now in your case, I would recommend you to check access by adding&amp;nbsp;&lt;EM&gt;google-base&amp;nbsp;&lt;/EM&gt;app-id in the security policy.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 06:06:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-home-page-not-loading-when-remove-quot-service-https-quot/m-p/425689#M94395</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-08-10T06:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: google home page not loading when remove "service-https" and leave ssl application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-home-page-not-loading-when-remove-quot-service-https-quot/m-p/425871#M94410</link>
      <description>&lt;P&gt;hi, thx fro quick reply. by adding google-base app ID in security policy, do you mean: edit the rule in question, go to the application tab, and add google base under the applications? If so, that is tedious and leads me down the application rabbit hole. then for each thing that should be working with SSL, but has some sort of custom application, i have to had that one - and then another one, and another, etc. pretty soon have 10's or more of these pre-made applications, just running over SSL. I just want to allow anything running on ssl. And that doesn't seem to work.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 18:44:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-home-page-not-loading-when-remove-quot-service-https-quot/m-p/425871#M94410</guid>
      <dc:creator>anon4all</dc:creator>
      <dc:date>2021-08-10T18:44:01Z</dc:date>
    </item>
  </channel>
</rss>

