GlobalProtect Port 80 ,443 Incomplete

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

GlobalProtect Port 80 ,443 Incomplete

L1 Bithead


Hi

I'm Trying to set an enviorment to my mobile users (Laptops of Salesman), I used the Globalprotect to provide a secure tunnel to the office Firewall and

then gave the users access to terminal server, and it worked fine.

last week we installed a new SharePoint Server, I need to give the users with laptops direct access to my SharePoint Server

I used the same method to access the Server , meening

I opened Port 80 to the server through GlobalProtect access, with no luck - the monitor shows incomplete in the application section.

whan i open ping to the server, i recive an answer, the same issue happens with https.

now, I do have web servers in the DMZ that works fine, the only exception is that they are wide open to the world

and in this senario I'm tring to give access only through VPN.

This is a panos 5.0.4 version with GlobalProtect 1.2.2

any sugestions?

1 accepted solution

Accepted Solutions

Tnx 4 all the help,

I have found the problem

if yor tring to "talk" to a computer in the network that has a PBF rule redirecting it to another route - it wont work.....

I excluded the servers from the ip range I used to redirect to ADSL with PBF , now everything WORK!!!

here is the rule

adsl.PNG

Thanks again,

Shay

View solution in original post

11 REPLIES 11

L6 Presenter

is this sharepoint server have both public and private ip address ?

or just ip with 20.x.x.x

its only a private network with 20.1.1.16 address , i can ping him and remote access him through GlobalProtect client

but no access with http or https, the SharePoint Windows firewall is off

You mean RDP with remote access ?

Yes RDP with remote access, i even accessed his harddrive throuth network access (ms-ds-smb 445) and was able to copy files from his share folders

if you can do RDP than this is not a session issue.There is somehting special for sharepoint server than.

And incomplete means

1- syn ack not coming (but this fails because you can make RDP)

2-  3way handshake complete but after than not any packets coming(maybe timeout)

I tried to access another server with http , same problem.

if it's a timeout issue, what can i change to make it work?panos2.PNG

Try do add an application with port 80 and timeout values big

Then write app override rule for that traffic(you attached its picture) with this app.

Let's see if something will change when disabling inspection

I disabled Policy base forwarding, and it's working......

panos3.PNG

We configured a police to push all the youtube ,facebook ,etc through ADSL line,

when disabling this police the sites work with GlobalProtect access.

Now I will try to understand what was misconfigured in the Policy base forwarding

Wauvvv I have not known you have pbf rules.

what rules of pbf you have

Tnx 4 all the help,

I have found the problem

if yor tring to "talk" to a computer in the network that has a PBF rule redirecting it to another route - it wont work.....

I excluded the servers from the ip range I used to redirect to ADSL with PBF , now everything WORK!!!

here is the rule

adsl.PNG

Thanks again,

Shay

That's fine.

I'm Glad that it is solved.

  • 1 accepted solution
  • 8385 Views
  • 11 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!