<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Filtering - Continue Action on Terminal Server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-continue-action-on-terminal-server/m-p/14776#M10853</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds odd...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If verified this sounds like a bug to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using TSagent the TSagent will inform the PA device which user uses which srcport range on which srcip (terminalserver) and by that the PA device already knows and should be able to limit this continue to the particular user when userid is being used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If one user clicks on a continue-page this "click" should only be valid for this particular user and not the whole network or for that matter the current srcip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another case where this can occur is if the users (for some reason) already is behind a NAT before reaching the PA device.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Mar 2013 07:19:54 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-03-01T07:19:54Z</dc:date>
    <item>
      <title>URL Filtering - Continue Action on Terminal Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-continue-action-on-terminal-server/m-p/14775#M10852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a customer who has deployed a PA-2020 with 3 Terminal Server agents at this seems to be operating well with one exception.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They have configured a URL filtering policy that has a Continue action on a number of categories.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When a standard LAN user accesses these sites, the continue operation works fine. The problem is when a user on a Terminal Server accesses something from this category, they click on Continue and not only is that user allowed but all other users on the Terminal Server are allowed access without any further prompting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Presumably this behavior is by design as from what i have read and understand the continue action binds the IP address of the user (of which the Terminal server users are all the same).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to implement the Continue action such that this binds to the TS user or port range rather than the IP address of the TS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 02:32:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-continue-action-on-terminal-server/m-p/14775#M10852</guid>
      <dc:creator>scottdoorey</dc:creator>
      <dc:date>2013-03-01T02:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering - Continue Action on Terminal Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-continue-action-on-terminal-server/m-p/14776#M10853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds odd...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If verified this sounds like a bug to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using TSagent the TSagent will inform the PA device which user uses which srcport range on which srcip (terminalserver) and by that the PA device already knows and should be able to limit this continue to the particular user when userid is being used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If one user clicks on a continue-page this "click" should only be valid for this particular user and not the whole network or for that matter the current srcip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another case where this can occur is if the users (for some reason) already is behind a NAT before reaching the PA device.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 07:19:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-continue-action-on-terminal-server/m-p/14776#M10853</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-03-01T07:19:54Z</dc:date>
    </item>
  </channel>
</rss>

