Traffic from Subnets Not Coming to Firewall - GlobalProtect Gateway

Traffic from Subnets Not Coming to Firewall - GlobalProtect Gateway

26007
Created On 09/25/18 19:49 PM - Last Modified 06/09/23 05:54 AM


Symptom


Symptoms

  • The Palo Alto Networks firewall can reach all internal subnets.
  • When GlobalProtect users access those internal subnets, for a few subnets, traffic is not coming to the Palo Alto Networks firewall.
  • All other subnets are working fine -- the problem occurs for only one subnet, access route 0.0.0.0/0.

Diagnosis

A more specific route in the LAN takes precedence over access route 0.0.0.0/0.



Resolution


For (full-tunneling), enter 0.0.0.0/0 as the access route.  The benefit of this configuration is that you have visibility into all client traffic and you can ensure that clients are secured according to your policy even when they are not physically connected to the LAN. 

 

In this configuration, traffic destined for the local subnet goes through the physical adapter, rather than being tunneled to the gateway.

 

Even through you have  mentioned access route 0.0.0.0/0, it may happen that certain subnets do not reach the Palo Alto Networks firewall, because these routes have a more precise match in their local routing table.

 

  • Either use more specific route for split-tunneling 
  • Or use a feature introduced in PAN OS 7.0.x and later

 

The feature in PAN OS 7.0x is  to check No direct access to local network under Gateway configurations. Doing so prevents users from sending traffic to proxies or local resources, such as a home printer.

 

When the tunnel is established, all traffic is then routed through the tunnel where it's subject to policy enforcement by the firewall. All traffic comes through the tunnel and the local routing table is ignored.

 

 

gp.PNG

 

 
 Thank you.
 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleNCAS&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language