URL citrix.rsieh.com is inaccessible through firewall

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

URL citrix.rsieh.com is inaccessible through firewall

L3 Networker

Hi Friends,

1) One of my customer is trying to access https://citrix.rsieh.com, although it initially opened, and it was soon redirected to https://sso-fe2eb653.sso.duosecurity.com/saml2/sp/sso and site is getting inaccessible through firewall

2) This are the User-Id users and they are not using authentication and decryption policy and apart from this URL, all other websites are working fine under the same security policy only this particular URL is not accessible.

3) We also tried allowing, DNS Name: *.login.duosecurity.com , *.sso.duosecurity.com but no luck

Kindly help me with the next step

Model:- PA-440
PANOS:- 11.1.6-h10

 

Regards,

Chandrashekhar

1 REPLY 1

Cyber Elite
Cyber Elite

@ChandrashekharD,

This is almost certainly that your existing policy just doesn't match for the traffic and it's getting dropped. You can validate if traffic is getting dropped by either building a targeted policy at the bottom of your rulebase, or simply enable logging on your interzone-default policy. 

 

You'll likely need to take a test user and build them out a policy that isn't locked down and ensure that you use the alert-all URL profile assigned to match what they're actually hitting. It is likely that you aren't allowing the identified application or a required domain to actually allow things to function.

  • 425 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!