<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allowing a subnet complete internet access but logging their traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-a-subnet-complete-internet-access-but-logging-their/m-p/23162#M16888</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This can easily be done be doing one or both of the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. create a policy that allows all applications and services specifically for those users (make sure and I identify either their names if you are using user identification or list their ips)&lt;/P&gt;&lt;P&gt;...you want to do this so that this allow all rule that you create does not apply to all of the other users..&lt;/P&gt;&lt;P&gt;On this allow all rule, make sure that you select log at session end or both log at session end and session start under the "options" section of the policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Create a url filtering profile (I suggest this because I assume you want to track/log the categorgization of the sites that they are browsing to). In that url filtering profile select ALL category actions as "alert". When you do this you are telling the paloalto device to log all of the user browsing and the site categorizations and allow them..........If you select "allow" you will only allow the sessions and not log them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you,&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Jun 2010 22:43:42 GMT</pubDate>
    <dc:creator>swhyte</dc:creator>
    <dc:date>2010-06-16T22:43:42Z</dc:date>
    <item>
      <title>Allowing a subnet complete internet access but logging their traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-a-subnet-complete-internet-access-but-logging-their/m-p/23161#M16887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ya'll,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline; "&gt;Background:&lt;/STRONG&gt;&amp;nbsp; We have a seperate Vlan that we call "Raw Internet" with no filtering.&amp;nbsp; This is used by our helpdesk staff.&amp;nbsp; Which means they have open access to Internet and nothing is being blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Currently &lt;/STRONG&gt;we purchased Palo Alto and I was wondering what would be the best way to do this.&amp;nbsp; Meaning, giving them full access to internet yet &lt;STRONG&gt;log their traffic&lt;/STRONG&gt; on Palo Alto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Furthermore, any configuration examples would be helpful &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jun 2010 18:49:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-a-subnet-complete-internet-access-but-logging-their/m-p/23161#M16887</guid>
      <dc:creator>casdc1pa</dc:creator>
      <dc:date>2010-06-15T18:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing a subnet complete internet access but logging their traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-a-subnet-complete-internet-access-but-logging-their/m-p/23162#M16888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This can easily be done be doing one or both of the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. create a policy that allows all applications and services specifically for those users (make sure and I identify either their names if you are using user identification or list their ips)&lt;/P&gt;&lt;P&gt;...you want to do this so that this allow all rule that you create does not apply to all of the other users..&lt;/P&gt;&lt;P&gt;On this allow all rule, make sure that you select log at session end or both log at session end and session start under the "options" section of the policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Create a url filtering profile (I suggest this because I assume you want to track/log the categorgization of the sites that they are browsing to). In that url filtering profile select ALL category actions as "alert". When you do this you are telling the paloalto device to log all of the user browsing and the site categorizations and allow them..........If you select "allow" you will only allow the sessions and not log them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you,&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jun 2010 22:43:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-a-subnet-complete-internet-access-but-logging-their/m-p/23162#M16888</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-06-16T22:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing a subnet complete internet access but logging their traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allowing-a-subnet-complete-internet-access-but-logging-their/m-p/23163#M16889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you so much. i kinda had the same idea but was'nt sure.&amp;nbsp; I will get to test this config tomorrow so hopefully it goes well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jun 2010 21:12:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allowing-a-subnet-complete-internet-access-but-logging-their/m-p/23163#M16889</guid>
      <dc:creator>casdc1pa</dc:creator>
      <dc:date>2010-06-18T21:12:26Z</dc:date>
    </item>
  </channel>
</rss>

