PA time out accessing web

Reply
L4 Transporter

Re: PA time out accessing web

Yes, but if i try http://metromadrid.es in Firefox is working fine. After that i go to chrome, i go to metromadrid.es and its working too. Quite weird.....

 

Here screenshots and policy.

 

fo.JPGfo2.JPGfo3.JPG

L4 Transporter

Re: PA time out accessing web

using http://metromadrid.es, there is a redirect to https and its working but only in firefox and explorer.

 

working.JPG

L6 Presenter

Re: PA time out accessing web

This is very weird. Ok let's try something else.  Lets see if PA itself can get 3-way handshake using its external (NAT IP) address;

 

> ssh port 443 source 188.x.x.x host 185.89.60.64

 

PCAP filter:

 

filter.PNG

 

capture all stages: firewall, drop, receive and transmit. 

 

L4 Transporter

Re: PA time out accessing web

I think

 

Log detailed:

 

final1.JPG

 

Drop pcap:

 

drop1.JPG

 

Firewall pcap:

 

Firewall1.JPG

 

Transmit pcap:

 

transmi1.JPG

 

receive pcap:

 

receive1.JPG

 

 

L6 Presenter

Re: PA time out accessing web

This issue just breaks my mind :D l also have no ideas now.  Just for test allow only application https (SSL) and on its default port 443 "application-default", otherwise l am giving up, sorry. It is more like a guess now. Cannot understand why we don't see SYN, ACK from PA PCAPs, when you were testing from the client PC with HTTPS requests.

Highlighted
L4 Transporter

Re: PA time out accessing web

Yes, its a x-files haha. I dont know whu we are getting this RST.....

We will downgrade to version 7.1.x or/and open a case with TAC. 

 

Thanks a lot for your suppot

L6 Presenter

Re: PA time out accessing web

Please post the outcome/TAC findings :D

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!