- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-15-2023 07:45 AM
Hi, I have a web application hosted by OCI, from on Prem I and my users can access the application without any problems. However when connecting to our PA setup through global protect we cant access the application.
We have a very similar setup for some AWS hosted web applications and these work without any issues.
Any ideas as I am stumped by this one. I am fairly new to PA so please be gentle with your replys!! Thanks
08-16-2023 12:16 AM
Hi @paul-b ,
Welcome to LiveCommunity! Thanks for reaching out.
How are you currently routing your GP traffic? Is all traffic being routed through GP or are you using a split tunnel for external connections?
If you are routing all traffic through GP, do you currently have security policies in place to allow traffic from your GP zone to Untrust zone with the required Apps/Services? If so, in the monitor tab, what do the traffic logs look like? Are you able to see the GP IPs as the source and external APP in OCI as the destination?
08-16-2023 06:29 AM
I'm gonna echo a lot of what @JayGolf already mentioned and add one of my own.
09-29-2023 08:10 AM
I use Global Protect for home workers to connect to th ecorp network.
Now, I have a tunnel setup for AWS, which all works fine, from within the office and when using global protect from home.
However the OCI connection only works from within the office, as soon as i try from global protect it does not respond.
So there is something in the way that the AWS ipsec tunnel is working than the OCI tunnel is working. I cant see any difference but clearly I am missing something could it be routing or policy, I am completely stumped.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!