Client VPN query

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Client VPN query

Not applicable

Hi,

I am new to looking after Palo Alto firewalls,

I have setup a small network for my client using a PA-200 as my firewall.  Users on the internal network can get out to the internet via the NAT and security policies.

I have one user who works for a sister company who users Forticlient on his laptop to VPN to his own network.  In Monitor I can see he is allowed out to the destination IP address for his companies network but it does not setup a VPN link.  By default the PAT NAT rule is giving him a specific external IP address and I think this is where the problem is.  Does anybody have any experience in Forticlient in particular or 3rd party VPN clients in general thorugh a Palo Alto firewall?

I hope to get more info from his IT department next week.

Another quick one!  Is there anyway on the Palo Alto to see the bandwidth being used by the ethernet ports?

Regards,

Phil

1 REPLY 1

L4 Transporter

Does the VPN software give you any specific errors that may lead to the problem? There is a way in the CLI to view counters for the traffic going to the destination IP and they may have some drops that would not specifically be viewed in the traffic logs. Here are some entry docs into those counters.

You can use the monitor tab->packet capture to setup a filter and filter these counters by a specific IP address.

>> Another quick one!  Is there anyway on the Palo Alto to see the bandwidth being used by the ethernet ports?"

in the GUI, if you apply QOS you can look at the statistics

in the CLI,

PA> show system state browser

Shift L and select Port Stats

Hit y

hit u

There is by default a 5 second update but can be changed with "r"

Dominic

  • 2181 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!