- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
04-25-2016 07:41 AM
I have and external website that I need to access on port 10443: https://<public IP>:10443. The connection never completes and times out.
If I pull the PA FW out and throw in an ASA, works just fine. The logs on PA don't even show port 10443 being accessed or logged.
No matter what log I check, I find nothing.
Any idea?
Thx
04-25-2016 07:54 AM
Hello,
Have you tried running a packet capture & global counters to check for any drops/reasons for drops? Is there any asymmetric routing in your network?
How to run a capture -
https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Run-a-Packet-Capture/ta-p/62390
Global counters -
hope this helps!
Ben
04-25-2016 11:57 PM
Also make sure that your only drop rule isn't the implicit one: interzone-default. That rule doesn't log. I always make a default drop rule which logs above implicit rules.
04-26-2016 05:07 AM
Good idea on the drop rule. It's a very basic setup, and all rules log start and end of session. Capture logs show retransmissions, and traffic is getting to device.
Additionally another app that uses SSL over a non stanard port also did not work. Swapped PA with an ASA and both apps worked.....definatley something on the PA.
INFO:
PA-VM-100
Pan-OS: 7.1.1
All other software up to date.
Thx
04-26-2016 05:43 AM
So did you find this traffic in logs? If all rules are set to logging then you must see it. If you still don't see it then it's dropped by implicit rule.
04-26-2016 09:54 AM
Good call santonic on the deny rule.....it was getting caught in the implict rule. Adjusted regular rule and all is good.
Thx guys....
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!