<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Lost Newbie - TAP Interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/lost-newbie-tap-interface/m-p/13763#M10098</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We bought a PA-500 just to start kicking the tires. I was ready to see a Juniper style GUI but was quickly lost in the PA Interface. Here is what I am looking to do, maybe someone can give me a quick list of configuration steps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All we want to do is to see the traffic for now. It would be nice if we could do the LDAP Integration to see who is doing what.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to use a TAP Interface. I already have a mirrored interface of a firewall that I would like to use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want 1 interface to manage the Box, I'm assuming I can just use the MGMT Interface for this. (duh)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I may in the future want an interface to inject TCP-Resets for traffic we dont like.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do I need to set up? Do I need to setup new zones, virtual routers, etc ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Justin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Jun 2010 20:16:45 GMT</pubDate>
    <dc:creator>jickfoo</dc:creator>
    <dc:date>2010-06-10T20:16:45Z</dc:date>
    <item>
      <title>Lost Newbie - TAP Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lost-newbie-tap-interface/m-p/13763#M10098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We bought a PA-500 just to start kicking the tires. I was ready to see a Juniper style GUI but was quickly lost in the PA Interface. Here is what I am looking to do, maybe someone can give me a quick list of configuration steps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All we want to do is to see the traffic for now. It would be nice if we could do the LDAP Integration to see who is doing what.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to use a TAP Interface. I already have a mirrored interface of a firewall that I would like to use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want 1 interface to manage the Box, I'm assuming I can just use the MGMT Interface for this. (duh)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I may in the future want an interface to inject TCP-Resets for traffic we dont like.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do I need to set up? Do I need to setup new zones, virtual routers, etc ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Justin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jun 2010 20:16:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lost-newbie-tap-interface/m-p/13763#M10098</guid>
      <dc:creator>jickfoo</dc:creator>
      <dc:date>2010-06-10T20:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: Lost Newbie - TAP Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lost-newbie-tap-interface/m-p/13764#M10099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Doc to get you started&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1445-"&gt;https://live.paloaltonetworks.com/docs/DOC-1445-&lt;/A&gt;&lt;SPAN&gt; For LDAP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You use the dedicated mgt interface for OOB. In order to send TCP resets, you will have to deploy in either vwire/l2/l3 mode&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jun 2010 20:59:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lost-newbie-tap-interface/m-p/13764#M10099</guid>
      <dc:creator>jpa</dc:creator>
      <dc:date>2010-06-10T20:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: Lost Newbie - TAP Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lost-newbie-tap-interface/m-p/13765#M10100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;EM&gt;I want to use a TAP Interface. I already have a mirrored interface of&amp;nbsp; a firewall that I would like to use.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;This part is easy.&amp;nbsp; Under the Device Tab, click on one of the interfaces and another window will pop up allowing you to define what type of interface it is.&amp;nbsp; In the first drop down box select "Tap" and then at the bottom select a zone.&amp;nbsp; I recommend clicking the "New" link and creating a new zone called "Tapzone."&amp;nbsp; Hit OK on that page and you're set for the zone, OK on the prior page and you've created your tap port.&amp;nbsp; Now hit Commit in the top right corner to make your changes active.&amp;nbsp; Also, you may want to make a security policy (Policies Tab).&amp;nbsp; Just create a new policy from Tapzone to Tapzone allowing all.&amp;nbsp; You can create profiles here to alert on all URL's, vulnerabilities, viruses so you can generate more log entries and see more logs there, too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;gt; &lt;EM&gt;I want 1 interface to manage the Box, I'm assuming I can just use the&amp;nbsp; MGMT Interface for this. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;Yes, that's it.&amp;nbsp; By default the IP address of the device is 192.168.1.1, but to change this, you can console in, type "configure" at the first prompt and you will be in configuration mode.&amp;nbsp; Use the following CLI command to make your changes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;gt; set deviceconfig system ip-address 192.168.1.150 netmask 255.255.255.0 default-gateway 192.168.1.1 dns-primary 4.2.2.1 ntp-server-1 1.2.3.4&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;gt; commit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;I'll defer to others on the LDAP nd TCP reset stuff (I think someone already replied), but if not, check out the admin guide on that, there's some good info there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;SP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jun 2010 16:34:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lost-newbie-tap-interface/m-p/13765#M10100</guid>
      <dc:creator>spolo</dc:creator>
      <dc:date>2010-06-11T16:34:57Z</dc:date>
    </item>
  </channel>
</rss>

