Kind of strange to reply to ones own post, but there is a little update: I found other articles about the SMB problematic. It seems a known "issue", that the TS-agent is unable to map all outgoing connections. Some happen at system-level, where the ts-agent cannot intervene. SMB is one of these cases: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkCCAS Still even when leaving out SMB we have the problem that the ts-agent intermittently does not work (i.e. with SSL-Connections). For a while it does the source-port-mappings as configured (i.e. src-port 20xyz) and then it stops and we get src-ports 57xyz and our policies don't work anymore. Restarting the machine or Service resolves the issue for a while, but not persistently. Any ideas what this could be? thanks, best regards Andi
... View more