New GP deployment - DNS, ping, and tracert work, but no app traffic

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

New GP deployment - DNS, ping, and tracert work, but no app traffic

L1 Bithead

I've set up a new GP config on a new PA-820 firewall. I have an old firewall I'm replacing, but I'm running them side by side. On the new 820 GP, I can connect with a GP client, and then ping internal servers. I can verify that DNS is working with nslookup using our internal DNS servers and all of the internal resources resolve and can be pinged just fine. I can also ping the GP client from any internal resource. So I believe routing is set up correctly. I can also get to the web just fine on the GP client.

 

However, everything outside of DNS, ping, and traceroute to our internal servers just times out. The PA-820 log shows everything is allowed. I have any/any policies set up for GP to LAN and vice versa and the policies are placed at the top. Application traffic appears for the most part to be ID'd correctly; I can see DNS, ping, netbios-ns, ldap, smb, etc. all listed in the application column. However, everything is either "aged-out" (most) or "tcp-rst-from-client" (a few) for the session end reason.

 

I can't for the life of me understand why I can ping both ways, but app traffic won't get through. There is no policy blocking it and routing seems to be set up. 

 

Any ideas of what to consider? I'm sure this is something dumb I'm missing.

1 accepted solution

Accepted Solutions

I solved it. The firewall config was correct. I forgot to add the correct route to the core switch. It had to be something simple.

View solution in original post

2 REPLIES 2

L4 Transporter

May be a silly question but did you add the GP zone to the outbound NAT/Security policies?

I solved it. The firewall config was correct. I forgot to add the correct route to the core switch. It had to be something simple.

  • 1 accepted solution
  • 2838 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!