New GP deployment - DNS, ping, and tracert work, but no app traffic

Reply
Highlighted
L1 Bithead

New GP deployment - DNS, ping, and tracert work, but no app traffic

I've set up a new GP config on a new PA-820 firewall. I have an old firewall I'm replacing, but I'm running them side by side. On the new 820 GP, I can connect with a GP client, and then ping internal servers. I can verify that DNS is working with nslookup using our internal DNS servers and all of the internal resources resolve and can be pinged just fine. I can also ping the GP client from any internal resource. So I believe routing is set up correctly. I can also get to the web just fine on the GP client.

 

However, everything outside of DNS, ping, and traceroute to our internal servers just times out. The PA-820 log shows everything is allowed. I have any/any policies set up for GP to LAN and vice versa and the policies are placed at the top. Application traffic appears for the most part to be ID'd correctly; I can see DNS, ping, netbios-ns, ldap, smb, etc. all listed in the application column. However, everything is either "aged-out" (most) or "tcp-rst-from-client" (a few) for the session end reason.

 

I can't for the life of me understand why I can ping both ways, but app traffic won't get through. There is no policy blocking it and routing seems to be set up. 

 

Any ideas of what to consider? I'm sure this is something dumb I'm missing.

L4 Transporter

Re: New GP deployment - DNS, ping, and tracert work, but no app traffic

May be a silly question but did you add the GP zone to the outbound NAT/Security policies?

L1 Bithead

Re: New GP deployment - DNS, ping, and tracert work, but no app traffic

I solved it. The firewall config was correct. I forgot to add the correct route to the core switch. It had to be something simple.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!