<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PA-500 problem with ISA Proxy Server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-500-problem-with-isa-proxy-server/m-p/21313#M15555</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: SH; font-family: Calibri; "&gt;Dear,&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: SH; font-family: Calibri; "&gt; &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN lang="SH" style="mso-ansi-language: SH;"&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: SH; font-family: Calibri; "&gt;&lt;BR /&gt;We have the question concerning using Palo Alto with Microsoft ISA Server.&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: SH; font-family: Calibri; "&gt;We have implementation of a Palo Alto in the network where Microsoft ISA Server is used as proxy (8080 port). We installed PA in network as Virtual Wire so we don't disturb their current infrastructure.&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: SH; font-family: Calibri; "&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: SH; font-family: Calibri; "&gt;In Monitor we could only se users going to the proxy as the Destination, and proxy as a Source when going outside. We couldn't use filtering by users also ( they have Microsoft's Active Directory).&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: SH; font-family: Calibri; "&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: SH; font-family: Calibri; "&gt;Is there a way we could use PA in the inviroment where ISA is used as Proxy?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Nov 2010 15:26:27 GMT</pubDate>
    <dc:creator>adeldurakovic</dc:creator>
    <dc:date>2010-11-11T15:26:27Z</dc:date>
    <item>
      <title>PA-500 problem with ISA Proxy Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-500-problem-with-isa-proxy-server/m-p/21313#M15555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: SH; font-family: Calibri; "&gt;Dear,&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: SH; font-family: Calibri; "&gt; &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN lang="SH" style="mso-ansi-language: SH;"&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: SH; font-family: Calibri; "&gt;&lt;BR /&gt;We have the question concerning using Palo Alto with Microsoft ISA Server.&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: SH; font-family: Calibri; "&gt;We have implementation of a Palo Alto in the network where Microsoft ISA Server is used as proxy (8080 port). We installed PA in network as Virtual Wire so we don't disturb their current infrastructure.&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: SH; font-family: Calibri; "&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: SH; font-family: Calibri; "&gt;In Monitor we could only se users going to the proxy as the Destination, and proxy as a Source when going outside. We couldn't use filtering by users also ( they have Microsoft's Active Directory).&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: SH; font-family: Calibri; "&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: SH; font-family: Calibri; "&gt;Is there a way we could use PA in the inviroment where ISA is used as Proxy?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Nov 2010 15:26:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-500-problem-with-isa-proxy-server/m-p/21313#M15555</guid>
      <dc:creator>adeldurakovic</dc:creator>
      <dc:date>2010-11-11T15:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: PA-500 problem with ISA Proxy Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-500-problem-with-isa-proxy-server/m-p/21314#M15556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not a big fan of this because it shows your real IP Address on the Internet but you can turn on X-Forward Header on the ISA Server and PA-500.&lt;/P&gt;&lt;P&gt;ISA does not perform this function without a plug-in from Winfrasoft or Trustlist.&lt;/P&gt;&lt;P&gt;You will need to CLI into the PA-500 and perform the following:&lt;/P&gt;&lt;P&gt;set deviceconfig setting ctd x-forwarded-for yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just make sure the ISA is sending the X-Forward in the correct format: X-Forwarded-For: client1, proxy1, proxy2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Nov 2010 15:38:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-500-problem-with-isa-proxy-server/m-p/21314#M15556</guid>
      <dc:creator>blacksan</dc:creator>
      <dc:date>2010-11-11T15:38:07Z</dc:date>
    </item>
  </channel>
</rss>

