<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does anyone have any experiences or &amp;quot;gotchas&amp;quot; they'd like to share when they've implemented Riverbed Steelhead appliances behind PA fire in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/589391#M117469</link>
    <description>&lt;P&gt;Hello solution on this please upate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jun 2024 17:40:31 GMT</pubDate>
    <dc:creator>kamalGD</dc:creator>
    <dc:date>2024-06-12T17:40:31Z</dc:date>
    <item>
      <title>Does anyone have any experiences or "gotchas" they'd like to share when they've implemented Riverbed Steelhead appliances behind PA firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/38946#M28552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see that there's a 'riverbed-rios' app listed in Applipedia, which gives me some hope.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specifically what I am concerned about is discussed here (with configuration examples for PIX/ASAs):&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.dslreports.com/faq/16494" title="http://www.dslreports.com/faq/16494"&gt;http://www.dslreports.com/faq/16494&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Riverbed appliances we have take advantage of TCP option 76 for autodiscovering other Steelhead appliances that are in-path. Has anyone configured a Palo Alto to allow this traffic? I'm not finding anything in the CLI guide that implies this advanced, granular configuration of TCP is available, but I'm hoping I'm wrong and this traffic can be permitted (or is magically already permitted by using the 'riverbed-rios' AppID - that would be awesome). &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 12:52:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/38946#M28552</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-02-08T12:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have any experiences or "gotchas" they'd like to share when they've implemented Riverbed Steelhead appliances behind PA firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/38947#M28553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to clarify on this one here's Palo Alto support's reply to this question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;&lt;SPAN style="background-color: #ecf3ea; color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.199999809265137px; line-height: 1.5em;"&gt;Hello Eric &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.199999809265137px; background-color: #ecf3ea;"&gt;I did some research on this one for you. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.199999809265137px; background-color: #ecf3ea;"&gt;PA firewalls does not alter the TCP options, whenever we send traffic through the Firewall, TCP options are no altered. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.199999809265137px; background-color: #ecf3ea;"&gt;Please let me know if you have any questions. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.199999809265137px; background-color: #ecf3ea;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.199999809265137px; background-color: #ecf3ea;"&gt;Thank you again for choosing Palo Alto Networks. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.199999809265137px; background-color: #ecf3ea;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.199999809265137px; background-color: #ecf3ea;"&gt;Sincerely, &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.199999809265137px; background-color: #ecf3ea;"&gt;Harsha Natarajan | Network Security Engineer&lt;/SPAN&gt;&lt;/P&gt;
&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2013 00:32:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/38947#M28553</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-02-19T00:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have any experiences or "gotchas" they'd like to share when they've implemented Riverbed Steelhead appliances behind PA firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/38948#M28554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Eric,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just wondering how you went with this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to implement something similar. My incredibly limited understanding of the situation is that in the scenario above for cisco the traffic passes like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LAN1-Riverbed1-Gateway1-INTERNET-Gateway2-Riverbed2-LAN2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BUT in Palo world, the traffic needs to go to the PA Firewall, THEN to the Riverbed, THEN back to the PA Firewall, THEN off to its final destination.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 01:31:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/38948#M28554</guid>
      <dc:creator>cowboy71</dc:creator>
      <dc:date>2013-07-18T01:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have any experiences or "gotchas" they'd like to share when they've implemented Riverbed Steelhead appliances behind PA firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/38949#M28555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We actually haven't implemented firewalls on both sides of Riverbed appliances yet, so unfortunately I don't have any experiences to share. We have plans in the works to implement PA, but the actual implementation is about a month out. The most I had received from support was as it is above, basically "PA won't muck with option 76 traffic." So in theory the Riverbeds should see each other and work as normal (at least in theory).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 02:21:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/38949#M28555</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-07-18T02:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have any experiences or "gotchas" they'd like to share when they've implemented Riverbed Steelhead appliances behind PA firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/38950#M28556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problems mate - thanks for the prompt reply &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll probably be implementing in the next month or so as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will be sure to share my experiences here when its done!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 02:26:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/38950#M28556</guid>
      <dc:creator>cowboy71</dc:creator>
      <dc:date>2013-07-18T02:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have any experiences or "gotchas" they'd like to share when they've implemented Riverbed Steelhead appliances behind PA firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/38951#M28557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a remote branch office VPNed back to our Datacenter via an IPSEC tunnel between two Palos ; in the DC I setup a separate interface for the branch office traffic on the Palo, the routed the traffic out of the DC steelhead to that interface, down the IPSEC tunnel &amp;amp; out the other end where the second steelhead picks it up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Works fine - Palo identifies the traffic as application riverbed-rios so there may be a gotcha in there if you want to filter by application type (since you cant tell what the original app was once its been processed by the steelhead).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 13:53:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/38951#M28557</guid>
      <dc:creator>SimmSimm</dc:creator>
      <dc:date>2013-07-18T13:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have any experiences or "gotchas" they'd like to share when they've implemented Riverbed Steelhead appliances behind PA firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/38952#M28558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Some excellent feedback there SimmSimm - thank you so much for that!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 22:13:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/38952#M28558</guid>
      <dc:creator>cowboy71</dc:creator>
      <dc:date>2013-07-18T22:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have any experiences or "gotchas" they'd like to share when they've implemented Riverbed Steelhead appliances behind PA firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/38953#M28559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to be more granular, you can plug your riverbed on palo and use PBF for routing traffic to remote site equiped with remote Riverbed Mean:&lt;/P&gt;&lt;P&gt;server - palo - riverbed - palo - Ipsec tunnel - Remote site&lt;/P&gt;&lt;P&gt;server - palo - IpSec tunnel - Remote site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and if install a ne remote Riverbed, just add subnet ini pbf rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Meke sense ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jul 2013 09:57:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/38953#M28559</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-07-19T09:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have any experiences or "gotchas" they'd like to share when they've implemented Riverbed Steelhead appliances behind PA fire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/578699#M116059</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;This thread is over 10yrs old, but currently have issues with RB Steelheads behind palos&lt;/P&gt;
&lt;P&gt;lan-rb-palo-ipsec-srx-rb-lan works fine&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;migrated out the srx with palo recently&lt;/P&gt;
&lt;P&gt;lan-rb-palo-ipsec-palo-rb-lan not working for optimization&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tried any:any on both side&lt;/P&gt;
&lt;P&gt;Tried app override for ports 7800-7850 riverbed peering&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just see resets in the packet captures.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PanOS running 10.2.7-h3&lt;/P&gt;
&lt;P&gt;Riverbed RIOS&amp;nbsp;9.14.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate any thoughts on what to try next&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 19:42:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/578699#M116059</guid>
      <dc:creator>orbcomm</dc:creator>
      <dc:date>2024-02-28T19:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have any experiences or "gotchas" they'd like to share when they've implemented Riverbed Steelhead appliances behind PA fire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/589391#M117469</link>
      <description>&lt;P&gt;Hello solution on this please upate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2024 17:40:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-anyone-have-any-experiences-or-quot-gotchas-quot-they-d/m-p/589391#M117469</guid>
      <dc:creator>kamalGD</dc:creator>
      <dc:date>2024-06-12T17:40:31Z</dc:date>
    </item>
  </channel>
</rss>

