<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is still missing or needs to be improved in PA Next Generation Firewalls ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20496#M14956</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just thought of one more - full name support in reports. Our HR department often have no idea who a user is based on their username, and so have to look it up, then write on the printed report who each username represents. To be fair, Bluecoat also fails this basic usability issue, but Websense nailed this out of the box last time I used it (about 7 years ago now right enough).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Dec 2012 14:28:05 GMT</pubDate>
    <dc:creator>broadleyn</dc:creator>
    <dc:date>2012-12-06T14:28:05Z</dc:date>
    <item>
      <title>What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20473#M14933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, will like to understand the oppinion from the PAN community about the features that are still missing or needs to be improved. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will appreciate if you can specify by functionality like :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;FIREWALL&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Must Have : A,B,C&lt;/P&gt;&lt;P&gt;Nice to Have : D,E,F&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mario&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 22:56:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20473#M14933</guid>
      <dc:creator>mario.chancay</dc:creator>
      <dc:date>2011-05-16T22:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20474#M14934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;plz, make your docs more clear! and add detailed overview for var options and settings! &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2011 14:02:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20474#M14934</guid>
      <dc:creator>stanislavm</dc:creator>
      <dc:date>2011-05-17T14:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20475#M14935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I couldn't agree more on the documentation side of things.&amp;nbsp; There is the admin guide which shows you how to configure common options and services but doesn't actually tell you what you are doing or what the not so common options are.. Then you have the CLI reference which is nothing more than a command tree of the CLI.&amp;nbsp; They are missing the part that descibes the options and the settings. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would also like to see better troubleshooting of sessions and why they were terminated.&amp;nbsp; Currently from a looking back sort of perspective it is impossible to tell why a particualr session ended which as caused a lot of issues in my deployment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oh and I would also like the bug in the 4.0.x of the PA-5000 series for packet filters to be fixed.&amp;nbsp; I currently can't do any packet level troubleshooting because filters don't work at all.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2011 17:39:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20475#M14935</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-05-17T17:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20476#M14936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;FIREWALL&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Must Have : A,B,C&lt;/P&gt;&lt;P&gt;Nice to Have : D,E,F&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A: Better QA, we have had 3 x DOA boxes&lt;/P&gt;&lt;P&gt;B: Solid state hard disks across the whole product range&lt;/P&gt;&lt;P&gt;C: When adding a device to Panorama, the ability to import the firewall configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the ACE t-shirts are cool -) So don't stop that -)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 May 2011 10:23:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20476#M14936</guid>
      <dc:creator>thesa</dc:creator>
      <dc:date>2011-05-19T10:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20477#M14937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;More DLP features.&amp;nbsp; Even a default set of predefined filters (SSN, Credit Card #, etc) would be a nice start.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 May 2011 13:32:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20477#M14937</guid>
      <dc:creator>pjswiderski</dc:creator>
      <dc:date>2011-05-19T13:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20478#M14938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ideally following would be nice, some background&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Situation:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;When ever i get malware infected client (missed by PA and most of us are SSL decrypted) the one common link i can see is that the user unwittingly (lets hope) downloaded a .EXE file from an unknown ( URL filter classification) source. Id like to be able to link the file blocking profile ( with all its derivatives)&amp;nbsp; to the URL classification profile so that if a user goes to a site which falls in the "unknown" category then they will be able to browse only .. not download .EXE and other type extensions. &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Suggestion:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;URL filtering is compliance based / not really security. Threat management (Malware engine in the instance)&amp;nbsp; on the PA (security based)&amp;nbsp; has all but stopped a handful of virus's in recent time, i need the latter two to work together linked to File blocking profile to be more effective. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The logic exists between APPID and file blocking... lets extend that to include URL filtering.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ps, im sure my regional service rep is sick of me asking for this..:-)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;( and if i understand PANOS 4 "drive by downloading" feature then this req is not really the same, i may be wrong )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 May 2011 18:18:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20478#M14938</guid>
      <dc:creator>wayne_webner</dc:creator>
      <dc:date>2011-05-20T18:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20479#M14939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Required:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Better DLP support (quite bad right now) and integration with outbound email control &amp;amp; block&lt;/LI&gt;&lt;LI&gt;SSLVPN portal for clientless connection. A client for mobile (Iphone/Android) and linux is also quite useful.&lt;/LI&gt;&lt;LI&gt;A deeper integration between rules/applications and URL filtering&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Useful in the future:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Seamless user notification when policies are violated.&lt;/LI&gt;&lt;LI&gt;Large log &amp;amp; monitoring SSD for all devices&lt;/LI&gt;&lt;LI&gt;Packet Fowing test section in order to verify rules, nat, profile group, url filtering. Cisco and Websense have a section like this and is great for troubleshooting &amp;amp; quick deployment.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA has now a great product and with other imporvements may become the real leader of network security firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep the good job!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 May 2011 15:55:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20479#M14939</guid>
      <dc:creator>zanonibs</dc:creator>
      <dc:date>2011-05-21T15:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20480#M14940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Must Have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Better integration between the wealth of documents in KnowledgePoint and the PAN-OS Administration Guide.&amp;nbsp; As an example the "&lt;A href="https://live.paloaltonetworks.com/click.jspa?searchID=157967&amp;amp;objectType=102&amp;amp;objectID=1160"&gt;How to Set Up and &lt;EM&gt;Configure&lt;/EM&gt; High Availability PANOS 3.1&lt;/A&gt;" should be referenced/hyperlinked right in the "Setting Up High Availability" section of the Administration Guide.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Ability to verify speed/duplex of an interface from the web GUI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nice to Have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- The option to execute at least some elements of the test command ("test security-policy-match", "test routing", "test nat-policy-match") against the &lt;STRONG&gt;candidate&lt;/STRONG&gt; configuration instead of the running configuration.&amp;nbsp; Would be very handy to verify behavior of a new rule/route prior to a commit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Ability to delete an old saved config from the web GUI&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 May 2011 04:27:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20480#M14940</guid>
      <dc:creator>shadowpeak</dc:creator>
      <dc:date>2011-05-22T04:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20481#M14941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Must have:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- separated reporting and logging per Device Groups/Access Domain in Panorama environment. Currently I can only choose between VSYS, nothing else and is a bit frustrating compared to FortiAnalyzer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- Better quality (and always updated) documentation on ALL available features whit a lot of case studies/real scenario (a la Juniper, for istance)&lt;/P&gt;&lt;P&gt;- Better filter group in Vulnerability Protection profile and an improved management feature related to Vuln Profile.&lt;/P&gt;&lt;P&gt;- AV, Vulnerability, AntiSpyware Exception by IP address (is totally unuseful by ID, because I can exclude a server not affected but not the entire signature and working with many profile and many rules is not a clean way)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Nice to have:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- MLPS/OSPF/BGP inspection. i.e what's inside an MPLS tunnel? Many customer are asking me this feature (not simple solution..) &lt;/P&gt;&lt;P&gt;- a series more little then 500. Many Italian customers asking for some firewall up to 100 Mbps, to better compete with Fortinet (also in terms of pricing)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 May 2011 12:51:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20481#M14941</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-05-23T12:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20482#M14942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;mario.chancay wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi, will like to understand the oppinion from the PAN community about the features that are still missing or needs to be improved. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will appreciate if you can specify by functionality like :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;FIREWALL&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Must Have : A,B,C&lt;/P&gt;&lt;P&gt;Nice to Have : D,E,F&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mario&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Documentation, Documentation, Documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without being too blunt, the documentation stinks. It needs cleared explainations, better grammar, and real-world examples instead of useless classroom types so people can sort things out without running to support. if you want examples, look at how Cisco do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Support, Support, Support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've had a discussion recently with my "suport partner" regarding the responses (or lack of them) from PA with respect to support calls (seriously, more than 6 weeks ona bug report, and three uploads of tech-support and logs to be told "it's not going to be fixed in this software series, upgrade to 4.x"? Come on!).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 May 2011 05:48:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20482#M14942</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2011-05-24T05:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20483#M14943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Must have:&lt;/P&gt;&lt;P&gt;Security policies: column with number indicating processing order.&lt;/P&gt;&lt;P&gt;And closely related: ability to sort policies on other colums.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nice to have:&lt;/P&gt;&lt;P&gt;Security profiles/groups in security policies window should be displayed by name, not logo. If you have several profiles/groups they're all the same icon.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2011 06:58:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20483#M14943</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2011-05-30T06:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20484#M14944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nice to see I'm not the only one that is complaining about:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Documentation with proper real-life scenarios/examples. Detailed explanation what different settings does and why they should be used or not.&lt;/P&gt;&lt;P&gt;-QA has been mentioned. I agree as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to see:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-The ability to block/act on ongoing attacks directly from the session browser and log (traffic/threat). IE, block offending IP for X hours.&lt;/P&gt;&lt;P&gt;-Better exceptions for Threats. I'd like to be able to create an exception for a particular threat in conjunction with a source and/or destination IP.&lt;/P&gt;&lt;P&gt;-If possible, Better reporting/logging for DDoS/Zone protection.&lt;/P&gt;&lt;P&gt;-commit timer. I'd like to be able to commit with a timer value. If a second commit hasn't been performed within the specified time, the box automaticaly reverts to the previous version.&lt;/P&gt;&lt;P&gt;-Multiple Captive Portal "profiles"&lt;/P&gt;&lt;P&gt;-Bulk set security profiles in CLI, (example: set rulebase security * from trust to untrust profile-setting profile ......) This helps making changes in large rulebases.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2011 09:10:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20484#M14944</guid>
      <dc:creator>rapoint_person</dc:creator>
      <dc:date>2011-05-30T09:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20485#M14945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Must have:&lt;/P&gt;&lt;P&gt;- Documentation Cleanup...E.g. There is an "official" Documentation (PA-4.0_Administrators_Guide.pdf) and a Lot of "How To" Guides (How to Configure HA on PANOS 3.1.2.pdf, Active Active Techz Note-2.pdf, ...). I don't like to have that many documents. Especially if they talk about the same topic and one File doesn't have all the info.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Easy Access to "show system state" information by Script (for Monitoring). E.g. accessible by SNMP or XML-API&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nice to have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Since the newest PanOS supports active/active. It would be nice to have a "active/passive"-per-VirtualSystem possibility. Its a lot easier to debug if you know, this hole V-Sys is processed by this cluster node. And there is no asymmetric routing within this setup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2011 09:45:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20485#M14945</guid>
      <dc:creator>User_333</dc:creator>
      <dc:date>2011-05-30T09:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20486#M14946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with the Documentation needs discussed thus far.&lt;/P&gt;&lt;P&gt;Must Have's:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 115%; font-family: &amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt; 1.&amp;nbsp;&amp;nbsp; Make filters applied to Logs, sticky, so that you can switch logs and then return to the same filter you applied earlier&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 115%; font-family: &amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;SPAN style="font-family: Times New Roman; font-size: 12pt;"&gt; 2. &lt;/SPAN&gt;Add ability for administrators to &lt;EM style="mso-bidi-font-style: normal;"&gt;EXCLUDE&lt;/EM&gt; users/groups/objects in a policy rule.&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: &amp;amp;quot; mso-spacerun: yes; sans-serif&amp;amp;quot: ; mso-ascii-theme-font: minor-latin; ,&amp;amp;quot: ; line-height: 115%; font-size: 11pt; mso-ansi-language: EN-US; mso-hansi-theme-font: minor-latin; Times New Roman&amp;amp;quot: ; mso-fareast-theme-font: minor-latin; font-family: &amp;amp;quot; mso-fareast-font-family: Calibri; Calibri&amp;amp;quot: ; mso-bidi-theme-font: minor-bidi; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: &amp;amp;quot; mso-spacerun: yes; sans-serif&amp;amp;quot: ; mso-ascii-theme-font: minor-latin; ,&amp;amp;quot: ; line-height: 115%; font-size: 11pt; mso-ansi-language: EN-US; mso-hansi-theme-font: minor-latin; Times New Roman&amp;amp;quot: ; mso-fareast-theme-font: minor-latin; font-family: &amp;amp;quot; mso-fareast-font-family: Calibri; Calibri&amp;amp;quot: ; mso-bidi-theme-font: minor-bidi; "&gt;Nice to Have's:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: &amp;amp;quot; mso-spacerun: yes; sans-serif&amp;amp;quot: ; mso-ascii-theme-font: minor-latin; ,&amp;amp;quot: ; line-height: 115%; font-size: 11pt; mso-ansi-language: EN-US; mso-hansi-theme-font: minor-latin; Times New Roman&amp;amp;quot: ; mso-fareast-theme-font: minor-latin; font-family: &amp;amp;quot; mso-fareast-font-family: Calibri; Calibri&amp;amp;quot: ; mso-bidi-theme-font: minor-bidi; "&gt; &lt;/SPAN&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; mso-bidi-font-family: &amp;amp;quot; mso-spacerun: yes; mso-ascii-theme-font: minor-latin; line-height: 115%; font-size: 12pt; mso-ansi-language: EN-US; mso-hansi-theme-font: minor-latin; font-family: Times New Roman; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-bidi-theme-font: minor-bidi; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoListParagraphCxSpFirst" style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l1 level1 lfo1;"&gt;&lt;SPAN&gt;&lt;SPAN style="font-family: Calibri; font-size: 12pt;"&gt;-&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt;Colored Allow/Deny entries in logs. For example, green for allowed rules and red for denied.&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;Users should be able to choose from a palette of colors to set their own colors.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraphCxSpMiddle" style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l1 level1 lfo1;"&gt;&lt;SPAN&gt;&lt;SPAN style="font-family: Calibri; font-size: 12pt;"&gt;-&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt;Faster scrolling of log traffic.&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;~1 second would be great.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraphCxSpMiddle" style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l1 level1 lfo1;"&gt;&lt;SPAN&gt;&lt;SPAN style="font-family: Calibri; font-size: 12pt;"&gt;- &lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt;Customizable columns in the logs.&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;Ability to re-arrange columns.&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;Ability to choose which columns are displayed.&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;Make these changes sticky so they stay when leaving the log page you are viewing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraphCxSpMiddle" style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l1 level1 lfo1;"&gt;&lt;SPAN&gt;&lt;SPAN style="font-family: Calibri; font-size: 12pt;"&gt;-&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt;That the “Resolve” check box only applies to the log window in which you check it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraphCxSpMiddle" style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l1 level1 lfo1;"&gt;&lt;SPAN&gt;&lt;SPAN style="font-family: Calibri; font-size: 12pt;"&gt;-&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt;Ability to perform text search within Logs, Rules, Users, Threats, etc…&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraphCxSpMiddle" style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l1 level1 lfo1;"&gt;&lt;SPAN&gt;&lt;SPAN style="font-family: Calibri; font-size: 12pt;"&gt;-&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt;Add/show the appropriate “Rule” being applied in the URL, Threat and Data Filtering logs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraphCxSpMiddle" style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l1 level1 lfo1;"&gt;&lt;SPAN&gt;&lt;SPAN style="font-family: Calibri; font-size: 12pt;"&gt;-&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt;ACC Panel: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraphCxSpMiddle" style="margin: 0in 0in 0pt 1in; text-indent: -0.25in; mso-list: l1 level2 lfo1; mso-add-space: auto;"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-list: Ignore; mso-bidi-theme-font: minor-latin; "&gt;&lt;SPAN style="font-family: Calibri;"&gt;a.&lt;/SPAN&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt;For entries of the “Insufficient Data” type, include the Protocol and port number when viewing the Application Information about it.&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;May help an administrator to define a custom or in-house application if they can see what protocols and ports are being accessed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraphCxSpMiddle" style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l1 level1 lfo1;"&gt;&lt;SPAN&gt;&lt;SPAN style="font-family: Calibri; font-size: 12pt;"&gt;-&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt;Make sticky the number of rows chosen to display in the logs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraphCxSpMiddle" style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l1 level1 lfo1;"&gt;&lt;SPAN&gt;&lt;SPAN style="font-family: Calibri; font-size: 12pt;"&gt;- &lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt;For all Logs, reference each row by row numbers and allow them to be sortable.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraphCxSpMiddle" style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l1 level1 lfo1;"&gt;&lt;SPAN&gt;&lt;SPAN style="font-family: Calibri; font-size: 12pt;"&gt;- &lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt;For all Logs, include/declare total number of rows retrieved when a filter is applied, at bottom of page.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraphCxSpMiddle" style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l1 level1 lfo1;"&gt;&lt;SPAN&gt;&lt;SPAN style="font-family: Calibri; font-size: 12pt;"&gt;- &lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt;Add the ability to be able to listen for URL headers from external clients and not just IP addresses, for internally published servers/websites.&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="margin: 0in 0in 10pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo2;"&gt;&lt;SPAN&gt;&lt;SPAN style="font-family: Calibri; font-size: 12pt;"&gt;-&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt;Sorting.&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;Throughout the user interface are many instances of Columns that should have the ability to be sorted.&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;(I.E. Objects tab&amp;gt;Name and Address columns)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraphCxSpFirst" style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1;"&gt;&lt;/P&gt;&lt;P class="MsoListParagraphCxSpFirst" style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1;"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN style=": ; mso-bidi-language: AR-SA; mso-fareast-language: EN-US; mso-bidi-font-family: &amp;amp;quot; mso-spacerun: yes; mso-ascii-theme-font: minor-latin; line-height: 115%; font-size: 3; mso-ansi-language: EN-US; mso-hansi-theme-font: minor-latin; font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-bidi-theme-font: minor-bidi; "&gt;&lt;P class="MsoListParagraphCxSpLast" style="margin: 0in 0in 10pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1;"&gt;&lt;SPAN style="line-height: 115%; font-family: &amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraphCxSpLast"&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: &amp;amp;quot; mso-spacerun: yes; sans-serif&amp;amp;quot: ; mso-ascii-theme-font: minor-latin; ,&amp;amp;quot: ; line-height: 115%; font-size: 11pt; mso-ansi-language: EN-US; mso-hansi-theme-font: minor-latin; Times New Roman&amp;amp;quot: ; mso-fareast-theme-font: minor-latin; font-family: &amp;amp;quot; mso-fareast-font-family: Calibri; Calibri&amp;amp;quot: ; mso-bidi-theme-font: minor-bidi; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2011 14:41:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20486#M14946</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-05-31T14:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20487#M14947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ability for user to authenticate to firewall and get the allow rule then sign-off when done troubleshooting an issue. I know it can be done now but in a "hack" kinda way.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2011 15:26:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20487#M14947</guid>
      <dc:creator>friento</dc:creator>
      <dc:date>2011-05-31T15:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20488#M14948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nice to Have : cisco integration with Filtering Service on Palo Alto, like websense or SurfControl&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2012 08:39:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20488#M14948</guid>
      <dc:creator>jakub_gniazdowski</dc:creator>
      <dc:date>2012-10-03T08:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20489#M14949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nice to have: Applipedia should include the information if a specific application requires an exclusion for SSL decryption in order to work. E.g. dropbox&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2012 07:24:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20489#M14949</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-12-04T07:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20490#M14950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ability to define and fold up groups of security rules.&amp;nbsp; The tags are very cool but a way to fold up groups of rules to a single line would be nice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Longer captive portal, ability to put in length of captive portal based on user/group and/or timeout and/or native client etc.&amp;nbsp; Bottom line is BYOD is here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Free copy of Panorama for small rollouts.&amp;nbsp; Why?&amp;nbsp; Word of mouth for larger installations, ability to gain experience with Panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Real world examples of implementation, rules etc.&amp;nbsp; It is a different way of thinking and honestly is difficult to get a grip on it for complex situations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Graphical interface for schedules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 05:36:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20490#M14950</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2012-12-05T05:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20491#M14951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What i really would like to see in PA device is usable DLP. A few days ago i powered up old fortigate device and damn their DLP is quite nice to work with. They even had a chance to search for keywords in mail subject or body.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 07:16:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20491#M14951</guid>
      <dc:creator>JanisM</dc:creator>
      <dc:date>2012-12-05T07:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: What is still missing or needs to be improved in PA Next Generation Firewalls ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20492#M14952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ability to import user and group information periodically, and the ability to use those imported objects to create groups on the box. Our management does not like the fact that I need to rely on our IT group for firewall ACL's. Nor do they want to create another process in which we have to monitor more group memberships/changes to AD.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 15:41:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-still-missing-or-needs-to-be-improved-in-pa-next/m-p/20492#M14952</guid>
      <dc:creator>dlopez</dc:creator>
      <dc:date>2012-12-05T15:41:59Z</dc:date>
    </item>
  </channel>
</rss>

