This website uses cookies essential to its operation, for analytics, and for personalized content. By continuing to browse this site, you acknowledge the use of cookies.
For details on cookie usage on our site, read our
Privacy Policy
Accept
Reject
Register
·
Sign In
·
FAQs
(English) USA
(English) USA
(简体中文) China
(日本語) Japan
(한국어) Korea
(繁體中文) Taiwan
Get Started
Welcome Guide
LIVEcommunity Support Info
FAQ
News & Events
Events
Ask Me Anything (AMA) Events
Ask Me Anything (AMA) Event Discussions
Interactive Events
Social Feed
News
Discussions
Network Security
Next-Generation Firewall Discussions
VM-Series in the Public Cloud
VM-Series in the Private Cloud
CN-Series Discussions
AIOps for NGFW Discussions
Panorama Discussions
GlobalProtect Discussions
Cloud NGFW Discussions
Cloud Delivered Security Services
Threat & Vulnerability Discussions
Endpoint (Traps) Discussions
Enterprise Data Loss Prevention Discussions
Next-Generation CASB Discussions
IoT Security Discussions
Secure Access Service Edge
Prisma Access Discussions
Prisma Access Insights Discussions
Prisma Access for MSPs and Distributed Enterprises Discussions
Prisma Access Cloud Management Discussions
Prisma SD-WAN Discussions
Prisma SD-WAN CloudBlades Discussions
Prisma SD-WAN AIOps Discussions
Autonomous DEM Discussions
Cloud Native Application Protection
Prisma Cloud Discussions
Cloud Identity Engine Discussions
Security Operations
Cortex XDR Discussions
Cortex XSOAR Discussions
Cortex Xpanse Discussions
Cortex XSIAM Discussions
General Topics
Best Practice Assessment Discussions
Configuration Wizard Discussions
Custom Signatures
VirusTotal
Products
Network Security
GlobalProtect
Next-Generation Firewall
Cloud NGFW for AWS
Cloud NGFW for Azure
AIOps for NGFW
Getting Started With VM-series
Private Cloud
Oracle Cloud Infrastructure
Alibaba Cloud
AWS
GCP
Azure
CN-Series
Panorama
Threat Prevention Services
Endpoint Protection
SSL Decryption
App-ID
Content-ID
User-ID
5G
Cloud Delivered Security Services
Next-Generation CASB
IoT Security
Enterprise Data Loss Prevention
Secure Access Service Edge
Prisma Access
Prisma Access Insights
Autonomous Digital Experience Management
Prisma Access Cloud Management
Prisma Access for MSPs and Distributed Enterprises
Prisma SD-WAN
Prisma SD-WAN CloudBlades
Prisma SD-WAN AIOps
Cloud Native Application Protection
Prisma Cloud
Cloud Identity Engine
Security Operations
Cortex XDR
Cortex XSOAR
Cortex Data Lake
Cortex Xpanse
Cortex XSIAM
Hub
Tools
Integration Resources
App for QRadar
Automation / API
Ansible
PAN-OS Python
Terraform
Cloud Integration
Expedition
HTTP Log Forwarding
Maltego for AutoFocus
Best Practice Assessment
Configuration Wizard
Education Services
Certification
Instructor-Led Training
Digital Learning
Education Services Help Center
Education Services Upcoming Events
Education Services Articles
Podcasts
PANCast™
PANCast™: Episode Ideas Submission
Member Recognition
Spotlight News
Member Spotlights
Member Testimonials
Cyber Elite Program
Customer
Partner
Employee
About xuserjam
All community
Articles
xuserjam
Users
Products
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for
Show
only
|
Search instead for
Did you mean:
LIVEcommunity
About xuserjam
07-25-2021
xuserjam
since
07-25-2021
L0 Member
1
Post
0
Likes
0
Solutions
Jul 25, 2021
Last Visited
User Activity
User Profile
Latest posts by xuserjam
Subject
Views
Posted
Re: global protect remote vpn unable to reach internal network?
General Topics
4453
07-25-2021
01:51 AM
View All
User Badges
View All
Community Statistics
Member Since
07-25-2021
01:45 AM
Date Last Visited
07-25-2021
09:59 AM
Posts
1
Latest Contributions by xuserjam
Topics xuserjam has Participated In
Latest Contributions by xuserjam
Re: global protect remote vpn unable to reach internal network?
by
xuserjam
in
General Topics
07-25-2021
01:51 AM
07-25-2021
01:51 AM
Can somebody check this? admin@PA850-FW1(active)> show session id 117862 Session 117862 c2s flow: source: 10.0.1.51 [SNS_VPN] dst: 10.0.0.2 proto: 1 sport: 1 dport: 12088 state: INIT type: FLOW src user: vpn_user1 dst user: unknown s2c flow: source: 10.0.0.2 [SNS Trust] dst: 10.0.1.51 proto: 1 sport: 12088 dport: 1 state: INIT type: FLOW src user: unknown dst user: vpn_user1 pbf rule: Web Access 1 start time : Sun Jul 25 13:27:24 2021 timeout : 6 sec total byte count(c2s) : 74 total byte count(s2c) : 74 layer7 packet count(c2s) : 1 layer7 packet count(s2c) : 1 vsys : vsys1 application : ping rule : GPZone_to_SNS_Zone service timeout override(index) : False session to be logged at end : True session in session ager : False session updated by HA peer : False layer7 processing : enabled URL filtering enabled : False session via syn-cookies : False session terminated on host : False session traverses tunnel : True session terminate tunnel : False captive portal session : False ingress interface : tunnel.1 egress interface : ae1 session QoS rule : N/A (class 4) tracker stage firewall : Aged out end-reason : aged-out What I am missing here? I can ping internal (trust) PA interface IP (10.0.0.254) from VPN connected host, but any host from the 10.0.0.x network is unreachable. 10.0.0.254 is the default GW.
... View more
Contact Me
Online Status
Offline
Date Last Visited
07-25-2021
09:59 AM
Latest Tags
No tags yet