Can’t access a website with The connection with the server was reset

Situation: The user tries to download a form from BNA bank. She gets this message: The connection with the server was reset.

Troubleshooting: From Paloalto Firewall monitor, we can see the Application is incomplete.

  1. make sure the IP address is nor foreigner IP addresses.
  2. We find the executable file and PE are blocked by Firewall.

Please refer to this post:

How to create policy to allow executable file in Paloalto Firewall

Paloalto Firewall policy blocks downloading a executable file.

Situation: The client has Paloalto Firewall. When they access BNC bank to download a form, they get a error message saying the policy block downloading a executable file.

Resolution: Create a policy to allow download executable file. Please refer to this post:

How to create policy to allow executable file in Paloalto Firewall

Can’t install DVMax client because unable to save file in Windows\downlaod installation

Situation: The Animal Hospital uses DVMax. When upgrading DVMax from v8.5 to 8.7, they can’t install DVMax client because unable to save file in Windows\download installation.

Troubleshooting: In most cases, if you can’t read files or folders, it is permissions issue. There are two resolutions.

  1. Run the installation as admin.
  2. Assign full permission to the user who installs the software.

Upgraded DVMax gets read only message and can’t continue

Situation: The Animal Hospital uses DVMax. When upgrading DVMax from v8.5 to 8.7, they can’t continue with data read only message.

Troubleshooting: We have seen many cases like this one. There are two fixes.

  1. The best way is copy the data before doing upgrade. Now we can copy it back. This is faster way to do.
  2. Restore from the backup. This may take long time. Be patience.

Can’t access FTP server randomly

Situation: The client has FTP for clients to uploading or downloading files. Sometimes some users can’t access it.

Troubleshooting: 1. If the transfer settings is default, change it to Active.

2. If it uses only passive mode, make sure port 1024-65335 open on firewall.

3. If you open ports 1024-65535 for passive mode, make sure FTP server also use the same port rang. In syncplify.me, the default port range are 1-65335.

4. For security reason, you may want to create application for example FTP instead opening port rang.

What does incomplete under Application means in Paloalto Firewall?

Q: We see many incomplete status under Application in our Paloalto Firewall. Is this application issue or Firewall issue?

A: Based on our experience, this is Application issue. It could be the user enter incorrect credentials. Or firewall blocks the connection, for example firewall may opens a port 21 for FTP, but FTP passive mode uses port rang from 1024 to 65535.

Outside RDP users loss connection

Situation: The client has two remote servers for users to access. Internal users don’t have a problem to access the RD servers. Sometimes, outside users loss the connection after login.

Troubleshooting: 1. From Paloalto firewall Monitor, we do see some RDP connections are imcomplete.

2. We find the client has 3 Internet providers: AT&T, Comcast and WiFi. The WiFi is very slow and it was configured as backup. We temporary disable it.

3. We also created a Application override policy and put it on top of other policy. Please refer to this post:

How to create Application Override Policy in Paloalto Firewall