- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-23-2026 04:08 AM
I am using PA-410. In our network, one specific website is blocked automatically by the firewall. I created a URL filtering, added URLs to the whitelist, and allow in the profile. Nevertheless, users cannot access the website. When I monitor the traffic, there is "undecided" in front of the application. End Reason is unknown. State is Active.
Could you please help me to solve this issue?
09-23-2026 04:36 AM
sounds like its getting blocked before the url even matters (else i would expect the app-id to be ssl or web-browsing.
are you able to copy (redacted) output from the log or session state here so we get a little more context ?
09-23-2026 04:50 AM - edited 09-23-2026 04:54 AM
09-24-2026 12:54 AM
ok, this session tells us the connection is being allowed, the source is being NAT'ed but the session timed out during the handshake. this could mean the remote IP is not reachable or not accepting your connections quietly (no RST or FIN but silent drop), or there could be some routing issue upstream
have you doublechecked your source NAT IP, that it is correct and 'reachable' from the internet? are other hosts able to reach that destination IP address?
09-25-2026 03:38 AM
Everything is OK with NAT. Other hosts are not able to reach that site either. But when I change the network, the site opens without any problem.
Recently, we updated licenses. Since this process, we have been experiencing issues like this. Some low-risk websites also could not open on the network. I tried disabling all restriction rules and checking them, but nothing has changed. That's why I decided to ask for help.
Is it possible to bypass the firewall for a short period?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

