- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-24-2014 10:36 AM
Hi Friends,
I have configured SSL vpn with AD integration but i am not able to ping DMZ. i have all ready configure access route. please suggests what i need to do in configuration. or where i am missing.
Regards
Satish
12-24-2014 10:37 AM
Hi Satish
Do you have policy from the zone (your tunnel interface is) to your DMZ zone ?
Also check if you have route for the GP pool on your intermediary devices after the packet leaves Palo Alto to the destination in DMZ.
12-24-2014 10:50 AM
Hi Bat Dud..,
I have already created policy for that but till is not working.
Thnx
Satish
12-24-2014 10:52 AM
Did you check traffic logs, in case it's getting dropped.
Thanks
12-24-2014 10:55 AM
Also check if you have route for the GP pool on your intermediary devices after the packet leaves Palo Alto to the destination in DMZ.
12-24-2014 10:55 AM
Hi Hulk,
How are you ?? yes i am getting drop but rule is allow pls suggest.
Regards
Satish
12-24-2014 10:57 AM
Hi Bat,
GP pool is like 172.16.1.X or DMZ 10.10.1.X. i have configure in GP access route like 0.0.0.0/0, 10.10.1.0/X
Thanks
Satish
12-24-2014 10:58 AM
Hello Satish,
I am doing well and thank you for asking. Could you please expand the traffic logs ( monitor > logs > traffic) and share a snapshot of that logs here.
Thanks
12-24-2014 11:01 AM
Hi Hulk,
Right now, i dont have access but i will share with you tomorrow.
Satish
12-24-2014 11:06 AM
Thanks for your quick reply. Could you please also check: (tomorrow )
--whetherthe traffic is leaving the firewall inright direction(from Monitor> traffic logs)
-- Try to ping the destination(DMZ),sourceas the PAN interface IP (connected towards DMZ).
Thanks
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!