Many government sites are not opening on paloalto networks. Same is opening on outside network

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Many government sites are not opening on paloalto networks. Same is opening on outside network

L1 Bithead

Many government sites are not opening on paloalto networks. Same is opening on outside network. Please suggest

6 REPLIES 6

Community Team Member

Hi @SankalpS ,

 

You're not giving us much to work with.

 

What do you see exactly ? Is there a time-out or other error message ? Is your policy allowing it ? Do you see the connection attempt in the traffic logs ? Are you using decryption ? If so, is it being decrypted properly ? Do you see any drops in global counters when trying to access the websites ? Which platform and PAN-OS version are you using ?

 

Kind regards,

-Kiwi.

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Don't forget to hit that Like button if a post is helpful to you!

Getting site cant reached message when we try to open indian government sites link morth.nic.in. Also we try to by removing ILL cable from firewall and directly connecting to laptop then sites works.

 

Our many customers are facing this issue for last two days. 

L0 Member

We also faced same issues. Example of Govt Site

Software Version 10.1.5-h2
Deployment: Vwire Mode
Once we removed palo-alto firewall from network, start opening the site. Log saying "Aged-out"
Appliance Model 850.

Cyber Elite
Cyber Elite

Hello,

If you are using SSL decryption, set the government and military URL filter to bypass decryption. Many of these sites dont like to be decrypted since it looks like a man in the middle attack. While it is man in the middle, its not an attack.

 

Hope this makes sense.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!