<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pan vs proxy??? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-vs-proxy/m-p/20425#M14893</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is what I would recommend you do first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Security rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The firewall needs to allow the LAN access to the proxy on the port they are configured to use. Most companies use port 8080 but it might be different for you. If it's the case, a rule should be in place to allow the entire LAN to communicate to the proxy's IP address only on port 8080. Remember that if an explicit proxy is configured, workstations won't even perform DNS queries, the proxy will.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another security rule needs to be in place to allow access from the proxy. The proxy will need access to the internet on ports 80, 443, and also DNS services (probably others too like NTP but that will depend on the proxy)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Address translation rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without knowing a lot on the network, it is hard for me to provide an exact answer but in most cases, this is how NAT is configured&lt;/P&gt;&lt;P&gt;- When the LAN access the proxy's IP address, no address translation is configured. This allows the proxy to see the real IP address of the workstation instead of all connections coming from the firewall&lt;/P&gt;&lt;P&gt;- When the Proxy access the internet, address translation needs to happen. In most cases a one to one rule is created (one public IP address dedicated to the proxy's internal IP)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Sep 2012 17:50:24 GMT</pubDate>
    <dc:creator>npare</dc:creator>
    <dc:date>2012-09-21T17:50:24Z</dc:date>
    <item>
      <title>Pan vs proxy???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-vs-proxy/m-p/20423#M14891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;I am newer and I meet some problems with PA 2050&lt;/P&gt;&lt;P&gt;I want use PA 2050 to monitor traffic in my network.&lt;/P&gt;&lt;P&gt;I setup PAN in Mode Layer 1 ( virtual wire)&lt;/P&gt;&lt;P&gt;I setup Polices is aler ( not block - i sure it)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a proxy, client can access internet through Proxy or not, all ok!&lt;/P&gt;&lt;P&gt;But after i put PAN, client can't not access internet through Proxy,&lt;/P&gt;&lt;P&gt;but if client doesn't user proxy, it will ok!!!&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PAN VS RPOXY.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4125_PAN VS RPOXY.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;Something wrong?&lt;/P&gt;&lt;P&gt;Pls helpme!&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2012 09:43:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-vs-proxy/m-p/20423#M14891</guid>
      <dc:creator>dat.tran</dc:creator>
      <dc:date>2012-09-21T09:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: Pan vs proxy???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-vs-proxy/m-p/20424#M14892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i just remeber.&lt;/P&gt;&lt;P&gt;Client and proxy on two diffirent subnet?&lt;/P&gt;&lt;P&gt;and not not config tag allow?&lt;/P&gt;&lt;P&gt;Maybe it is cause?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;( now i can't reconfig to check )&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2012 10:02:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-vs-proxy/m-p/20424#M14892</guid>
      <dc:creator>dat.tran</dc:creator>
      <dc:date>2012-09-21T10:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: Pan vs proxy???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-vs-proxy/m-p/20425#M14893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is what I would recommend you do first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Security rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The firewall needs to allow the LAN access to the proxy on the port they are configured to use. Most companies use port 8080 but it might be different for you. If it's the case, a rule should be in place to allow the entire LAN to communicate to the proxy's IP address only on port 8080. Remember that if an explicit proxy is configured, workstations won't even perform DNS queries, the proxy will.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another security rule needs to be in place to allow access from the proxy. The proxy will need access to the internet on ports 80, 443, and also DNS services (probably others too like NTP but that will depend on the proxy)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Address translation rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without knowing a lot on the network, it is hard for me to provide an exact answer but in most cases, this is how NAT is configured&lt;/P&gt;&lt;P&gt;- When the LAN access the proxy's IP address, no address translation is configured. This allows the proxy to see the real IP address of the workstation instead of all connections coming from the firewall&lt;/P&gt;&lt;P&gt;- When the Proxy access the internet, address translation needs to happen. In most cases a one to one rule is created (one public IP address dedicated to the proxy's internal IP)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2012 17:50:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-vs-proxy/m-p/20425#M14893</guid>
      <dc:creator>npare</dc:creator>
      <dc:date>2012-09-21T17:50:24Z</dc:date>
    </item>
  </channel>
</rss>

