<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN-OS 11.0 Explicit proxy with no authentication in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/549239#M112083</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/302880"&gt;@itsnoc&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You need to specify an authentication service type and have an assigned authentication profile to have a valid configuration. If you don't want to set that up you'd have to utilize a transparent proxy instead of an explicit proxy.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Jul 2023 13:34:17 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2023-07-13T13:34:17Z</dc:date>
    <item>
      <title>PAN-OS 11.0 Explicit proxy with no authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/549109#M112062</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;may it be possible to use explicit proxy feature in PAN-OS 11.0 with no authentication and allow access for all users?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The documentation is very limited in this area and describes SAML or Kerberos&amp;nbsp;authentication only.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lumir&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 13:17:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/549109#M112062</guid>
      <dc:creator>itsnoc</dc:creator>
      <dc:date>2023-07-12T13:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 11.0 Explicit proxy with no authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/549158#M112071</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Here are a few articles that may help out.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-networking-admin/dns/configure-a-web-proxy/configure-explicit-proxy" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-networking-admin/dns/configure-a-web-proxy/configure-explicit-proxy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-networking-admin/dns/configure-a-web-proxy/configure-authentication-for-explicit-web-proxy" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-networking-admin/dns/configure-a-web-proxy/configure-authentication-for-explicit-web-proxy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 21:30:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/549158#M112071</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-07-12T21:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 11.0 Explicit proxy with no authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/549239#M112083</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/302880"&gt;@itsnoc&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You need to specify an authentication service type and have an assigned authentication profile to have a valid configuration. If you don't want to set that up you'd have to utilize a transparent proxy instead of an explicit proxy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 13:34:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/549239#M112083</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-07-13T13:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 11.0 Explicit proxy with no authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/550339#M112199</link>
      <description>&lt;P&gt;Better question is why you want explicit/transperant proxy at all &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/302880"&gt;@itsnoc&lt;/a&gt; ? Even before 11.0 Palo Alto can be an SSL forward proxy as mentioned in &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/decryption-concepts/ssl-forward-proxy" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/decryption-concepts/ssl-forward-proxy&lt;/A&gt; and if you do not configure authentication policy and portal redirection, it will decrypt the traffic and inspect it without authentication. You can use &lt;SPAN&gt;Policy based routing (&lt;EM&gt;PBR&lt;/EM&gt;)&lt;/SPAN&gt; routing from a router and switch to send the web traffic to the Firewall if it is not in path of the traffic as usually this is why explicit proxy is configured when it is not between the users and Internet. Palo Alto also has DNS Proxy mode if you want it to be your DNS point for the users &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFcCAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFcCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Outside of that the Kerberos authentication for users that are in the AD is seamless without affecting the users so it is another option &lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-networking-admin/dns/configure-a-web-proxy/configure-authentication-for-explicit-web-proxy" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-networking-admin/dns/configure-a-web-proxy/configure-authentication-for-explicit-web-proxy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also SAML maybe to Azure AD can utilize SSL Client cert and this will again make the authentication expiriance seemless:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-certificate-based-authentication" target="_blank"&gt;https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-certificate-based-authentication&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also if you have proxy before the Palo Alto that authenticates the users then the Explicit proxy can use the &lt;SPAN class="ph cmd"&gt;XAU header&lt;/SPAN&gt; to auto authenticate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 07:18:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/550339#M112199</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-07-21T07:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 11.0 Explicit proxy with no authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/550641#M112233</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your comments, the documentation is very limited, same as the proxy functionality. Also it does not functional without issues - ssl handshake is sometime broken and clients have to reload web page in their browsers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Lumir&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 13:28:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/550641#M112233</guid>
      <dc:creator>itsnoc</dc:creator>
      <dc:date>2023-07-24T13:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 11.0 Explicit proxy with no authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/550666#M112237</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153031"&gt;@nikoolayy1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your summary, the main goal of using explicit proxy is to avoid default route and other hacks in the network. I built solution using the Fortigate explicit proxy which can keep original source IP, route traffic over the PA box which then recognize source user based on User-ID mapping.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kerberos authentication works fine for desktop OS (Win, MAC) but does not work for Apple IOS devices - even with the Apple extension delivered by MDM.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;
&lt;P&gt;Lumir&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 15:04:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/550666#M112237</guid>
      <dc:creator>itsnoc</dc:creator>
      <dc:date>2023-07-24T15:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 11.0 Explicit proxy with no authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/572188#M115147</link>
      <description>&lt;P&gt;Now there seems to be bypass support in 11.1 &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/302880"&gt;@itsnoc&lt;/a&gt;&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-networking-admin/dns/configure-a-web-proxy/configure-exemptions-for-explicit-proxy-authentication" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-networking-admin/dns/configure-a-web-proxy/configure-exemptions-for-explicit-proxy-authentication&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 22:42:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/572188#M115147</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2024-01-08T22:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 11.0 Explicit proxy with no authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/572488#M115197</link>
      <description>&lt;P&gt;Good point&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153031"&gt;@nikoolayy1&lt;/a&gt;&amp;nbsp;- works as expected. Thanks for you comment&lt;/P&gt;
&lt;P&gt;Lumir&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 05:49:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-0-explicit-proxy-with-no-authentication/m-p/572488#M115197</guid>
      <dc:creator>lumirs</dc:creator>
      <dc:date>2024-01-10T05:49:23Z</dc:date>
    </item>
  </channel>
</rss>

