<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Has anyone configured and tested the new functionality within Pan OS 11.0 Web Proxy in Transparent mode? in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/has-anyone-configured-and-tested-the-new-functionality-within/m-p/650978#M5070</link>
    <description>&lt;P&gt;I have test too but follow your NAT reference, it does not, can you share me the security policy and decryptions policy too?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 24 Nov 2024 05:16:47 GMT</pubDate>
    <dc:creator>Yoekleng.Kuy</dc:creator>
    <dc:date>2024-11-24T05:16:47Z</dc:date>
    <item>
      <title>Has anyone configured and tested the new functionality within Pan OS 11.0 Web Proxy in Transparent mode?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/has-anyone-configured-and-tested-the-new-functionality-within/m-p/586465#M3183</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;
&lt;P&gt;I've set up the Web proxy in transparent mode, but I'm unsure of its functioning. Our Palo Alto device doesn't support WCCP and only allows Inline mode deployment. With only the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;admin guide&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;available for reference and study, I may be the sole individual who has done this. Particularly, I'm uncertain about the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;D-NAT aspect of transparent proxy&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;mode, as the DNS-Proxy isn't functioning. If anyone has experience with this configuration, I'd greatly appreciate assistance on how to test it effectively.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will share few logs and DNAT policy for reference&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AkashThangavel_0-1715591008571.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59634iA301DB061817F5D4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AkashThangavel_0-1715591008571.png" alt="AkashThangavel_0-1715591008571.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;FIGURE class="rte-media"&gt;
&lt;FIGCAPTION class="rte-media-caption"&gt;D-NAT for Proxy deployment&lt;/FIGCAPTION&gt;
&lt;/FIGURE&gt;
&lt;FIGURE class="rte-media"&gt;
&lt;DIV class="loaded"&gt;-------------------------------------------------------------------------------&lt;/DIV&gt;
&lt;DIV class="loaded"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AkashThangavel_1-1715591098465.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59635i61EB26C3D6492748/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AkashThangavel_1-1715591098465.png" alt="AkashThangavel_1-1715591098465.png" /&gt;&lt;/span&gt;
&lt;FIGURE class="rte-media"&gt;
&lt;FIGCAPTION class="rte-media-caption"&gt;NAT Applied, DNS port &lt;STRONG&gt;53&lt;/STRONG&gt; changed to &lt;STRONG&gt;8080&lt;/STRONG&gt; and the traffic started &lt;STRONG&gt;DROP&lt;/STRONG&gt; in the firewall itself.&lt;BR /&gt;&lt;BR /&gt;
&lt;P&gt;Furthermore, the actual traffic is being directly routed from the LAN to the WAN, bypassing the proxy entirely. What steps can be taken to ensure that traffic is routed from the LAN to the proxy and then onward to the WAN?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;
&lt;P&gt;Akash Thangavel&lt;/P&gt;
&lt;P&gt;Network Security Engineer&lt;/P&gt;
&lt;BR /&gt;&lt;BR /&gt;&lt;/FIGCAPTION&gt;
&lt;/FIGURE&gt;
&lt;/DIV&gt;
&lt;/FIGURE&gt;</description>
      <pubDate>Mon, 13 May 2024 09:06:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/has-anyone-configured-and-tested-the-new-functionality-within/m-p/586465#M3183</guid>
      <dc:creator>AkashThangavel</dc:creator>
      <dc:date>2024-05-13T09:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone configured and tested the new functionality within Pan OS 11.0 Web Proxy in Transparent mode?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/has-anyone-configured-and-tested-the-new-functionality-within/m-p/587693#M3224</link>
      <description>&lt;P&gt;TAC provided me the solution,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is for the future reference, if anyone encounter issues, when trying the web proxy in transparent mode as per the incorrect instructions in the admin guide, refer to this information.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AkashThangavel_0-1716401854625.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60001iF8F11B4290B61DC5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AkashThangavel_0-1716401854625.png" alt="AkashThangavel_0-1716401854625.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But the actually D-NAT should be like,&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AkashThangavel_2-1716401993359.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60003iB34E6246B6C10EEA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AkashThangavel_2-1716401993359.png" alt="AkashThangavel_2-1716401993359.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Traffic coming from client and going to Internet/web-server, needs to be send to Transparent proxy hence source zone would be client zone and dest zone would be Internet/web zone, not a PROXY zone. Also, For LAN to WAN, SSL traffic is routed to the PROXY zone using D-NAT, and then from PROXY to WAN, it is routed to the internet. In this process, the source and destination IPs remain the same in the traffic.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Akash Thangavel&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 18:29:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/has-anyone-configured-and-tested-the-new-functionality-within/m-p/587693#M3224</guid>
      <dc:creator>AkashThangavel</dc:creator>
      <dc:date>2024-05-22T18:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone configured and tested the new functionality within Pan OS 11.0 Web Proxy in Transparent mode?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/has-anyone-configured-and-tested-the-new-functionality-within/m-p/650978#M5070</link>
      <description>&lt;P&gt;I have test too but follow your NAT reference, it does not, can you share me the security policy and decryptions policy too?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Nov 2024 05:16:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/has-anyone-configured-and-tested-the-new-functionality-within/m-p/650978#M5070</guid>
      <dc:creator>Yoekleng.Kuy</dc:creator>
      <dc:date>2024-11-24T05:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone configured and tested the new functionality within Pan OS 11.0 Web Proxy in Transparent mode?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/has-anyone-configured-and-tested-the-new-functionality-within/m-p/680805#M5083</link>
      <description>&lt;P&gt;Please check this following reference,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Security Policy,&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AkashThangavel_0-1732601142067.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64278iB0AB6CB33B5366AE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AkashThangavel_0-1732601142067.png" alt="AkashThangavel_0-1732601142067.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Decryption policy I don't have screenshot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;LOGS&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AkashThangavel_1-1732601368093.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64279iF61152CA26BEA1EE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AkashThangavel_1-1732601368093.png" alt="AkashThangavel_1-1732601368093.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 06:09:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/has-anyone-configured-and-tested-the-new-functionality-within/m-p/680805#M5083</guid>
      <dc:creator>AkashThangavel</dc:creator>
      <dc:date>2024-11-26T06:09:42Z</dc:date>
    </item>
  </channel>
</rss>

