<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: External Web Proxy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/external-web-proxy/m-p/1227665#M124141</link>
    <description>&lt;P&gt;i am forwarding (BPF) to SkyHigh Web Gateway (on-prem),&lt;/P&gt;
&lt;P&gt;SkyHigh Web Gateway has a wonderful solution for identifying (and block) dozens of file-mimes (unlike the short list of Palo Alto file types).&lt;/P&gt;
&lt;P&gt;&lt;A href="https://success.skyhighsecurity.com/Skyhigh_Secure_Web_Gateway_(On-Prem)/Secure_Web_Gateway_Product_Guide/Media_Type_Filtering/Supported_Media_Types/Secure_Web_Gateway_(SWG)_Supported_MIME_Types" target="_blank"&gt;https://success.skyhighsecurity.com/Skyhigh_Secure_Web_Gateway_(On-Prem)/Secure_Web_Gateway_Product_Guide/Media_Type_Filtering/Supported_Media_Types/Secure_Web_Gateway_(SWG)_Supported_MIME_Types&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My plan is to to use Palo Alto (as default gateway) content inspection (TP and WF and all the protection modules), and then forward to SkyHigh (2nd hop)&lt;/P&gt;
&lt;P&gt;SkyHigh Proxy is listening on port 9090, and gets the traffic.&lt;/P&gt;
&lt;P&gt;Both PA and SkyHigh (and clients) using same SSL certificate.&lt;/P&gt;
&lt;P&gt;The issue is that the SkyHigh doesn't like the new SSL re-encryption from Palo Alto (1st hop).&lt;/P&gt;
&lt;P&gt;Seems like the SSL content inspection doesn't work when traffic comes not directly from clients (SSL is being handled by Palo Alto as MITM)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ideas?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Apr 2025 13:42:26 GMT</pubDate>
    <dc:creator>chens</dc:creator>
    <dc:date>2025-04-29T13:42:26Z</dc:date>
    <item>
      <title>External Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-web-proxy/m-p/1227517#M124127</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;
&lt;P&gt;Have someone working with next hop fwd proxy ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need post firewall solution for additional files types blocks (like Trellix)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 06:49:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-web-proxy/m-p/1227517#M124127</guid>
      <dc:creator>chens</dc:creator>
      <dc:date>2025-04-28T06:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: External Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-web-proxy/m-p/1227573#M124133</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Would you mind elaborating on your question?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 16:58:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-web-proxy/m-p/1227573#M124133</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-04-28T16:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: External Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-web-proxy/m-p/1227665#M124141</link>
      <description>&lt;P&gt;i am forwarding (BPF) to SkyHigh Web Gateway (on-prem),&lt;/P&gt;
&lt;P&gt;SkyHigh Web Gateway has a wonderful solution for identifying (and block) dozens of file-mimes (unlike the short list of Palo Alto file types).&lt;/P&gt;
&lt;P&gt;&lt;A href="https://success.skyhighsecurity.com/Skyhigh_Secure_Web_Gateway_(On-Prem)/Secure_Web_Gateway_Product_Guide/Media_Type_Filtering/Supported_Media_Types/Secure_Web_Gateway_(SWG)_Supported_MIME_Types" target="_blank"&gt;https://success.skyhighsecurity.com/Skyhigh_Secure_Web_Gateway_(On-Prem)/Secure_Web_Gateway_Product_Guide/Media_Type_Filtering/Supported_Media_Types/Secure_Web_Gateway_(SWG)_Supported_MIME_Types&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My plan is to to use Palo Alto (as default gateway) content inspection (TP and WF and all the protection modules), and then forward to SkyHigh (2nd hop)&lt;/P&gt;
&lt;P&gt;SkyHigh Proxy is listening on port 9090, and gets the traffic.&lt;/P&gt;
&lt;P&gt;Both PA and SkyHigh (and clients) using same SSL certificate.&lt;/P&gt;
&lt;P&gt;The issue is that the SkyHigh doesn't like the new SSL re-encryption from Palo Alto (1st hop).&lt;/P&gt;
&lt;P&gt;Seems like the SSL content inspection doesn't work when traffic comes not directly from clients (SSL is being handled by Palo Alto as MITM)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ideas?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 13:42:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-web-proxy/m-p/1227665#M124141</guid>
      <dc:creator>chens</dc:creator>
      <dc:date>2025-04-29T13:42:26Z</dc:date>
    </item>
  </channel>
</rss>

