- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-15-2013 09:44 AM
Hi,
I am new to looking after Palo Alto firewalls,
I have setup a small network for my client using a PA-200 as my firewall. Users on the internal network can get out to the internet via the NAT and security policies.
I have one user who works for a sister company who users Forticlient on his laptop to VPN to his own network. In Monitor I can see he is allowed out to the destination IP address for his companies network but it does not setup a VPN link. By default the PAT NAT rule is giving him a specific external IP address and I think this is where the problem is. Does anybody have any experience in Forticlient in particular or 3rd party VPN clients in general thorugh a Palo Alto firewall?
I hope to get more info from his IT department next week.
Another quick one! Is there anyway on the Palo Alto to see the bandwidth being used by the ethernet ports?
Regards,
Phil
03-15-2013 12:43 PM
Does the VPN software give you any specific errors that may lead to the problem? There is a way in the CLI to view counters for the traffic going to the destination IP and they may have some drops that would not specifically be viewed in the traffic logs. Here are some entry docs into those counters.
You can use the monitor tab->packet capture to setup a filter and filter these counters by a specific IP address.
>> Another quick one! Is there anyway on the Palo Alto to see the bandwidth being used by the ethernet ports?"
in the GUI, if you apply QOS you can look at the statistics
in the CLI,
PA> show system state browser
Shift L and select Port Stats
Hit y
hit u
There is by default a 5 second update but can be changed with "r"
Dominic
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!