Outbound Port 80 Traffic from the Terminal Server does not Use the TS-Agent Allocated Source Ports

Outbound Port 80 Traffic from the Terminal Server does not Use the TS-Agent Allocated Source Ports

17098
Created On 09/26/18 13:53 PM - Last Modified 05/31/23 20:58 PM


Resolution


Details

With the TS-agent installed, outbound web traffic on port 80 from the Terminal Server is not using the allocated source ports for that user. All other traffic appears to use the correct allocated range of source ports but whenever the destination port is 80, the source port is far below the allocated range it should use. This causes the source user to be unknown, and miss the security policy rule where source user is defined.

 

Cause

If there are any Sophos, Trend Micro or similar products installed on the Terminal Server, the proxy feature may be causing the problem.

 

Resolution

To resolve the issue, disable the Sophos, Trend Micro or similar products proxy feature, or even all services.

 

Alternatively, configure the proxy so it does not change the source port when connection coming from Terminal Server.

 

owner: jwoodburn



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClxdCAC&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language