- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-24-2025 11:02 AM
Hi Friends,
1) One of my customer is trying to access https://citrix.rsieh.com, although it initially opened, and it was soon redirected to https://sso-fe2eb653.sso.duosecurity.com/saml2/sp/sso and site is getting inaccessible through firewall
2) This are the User-Id users and they are not using authentication and decryption policy and apart from this URL, all other websites are working fine under the same security policy only this particular URL is not accessible.
3) We also tried allowing, DNS Name: *.login.duosecurity.com , *.sso.duosecurity.com but no luck
Kindly help me with the next step
Model:- PA-440
PANOS:- 11.1.6-h10
Regards,
Chandrashekhar
10-24-2025 11:12 AM
This is almost certainly that your existing policy just doesn't match for the traffic and it's getting dropped. You can validate if traffic is getting dropped by either building a targeted policy at the bottom of your rulebase, or simply enable logging on your interzone-default policy.
You'll likely need to take a test user and build them out a policy that isn't locked down and ensure that you use the alert-all URL profile assigned to match what they're actually hitting. It is likely that you aren't allowing the identified application or a required domain to actually allow things to function.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

