<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Web Browsing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing/m-p/36450#M26796</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;The PA doesnt do web proxy so it will not understand when a client connects to the ip address of the PA box and sends "CONNECT &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.example.com/"&gt;http://www.example.com/&lt;/A&gt;&lt;SPAN&gt; HTTP/1.0".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you want to keep the proxy setting in your clients (well browser settings) and in order to avoid having public ip addresses in your internal network you would need to use a dedicated forward proxy for this. A good (and cheap) solution is to use squid. There are also squid appliances if you want to pay some money: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.squid-cache.org/Support/products.html"&gt;http://www.squid-cache.org/Support/products.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise you need to disable the proxysetting in your client-browsers and make sure to point defgw towards your PA box (for the client the defgw is most likely already some router, then you need to add a routing entry in this router to point towards PA as defgw).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit: A tip when using a forward webproxy inline with a PA is to setup the webproxy to use "keep client ip". Then the PA will get the client ip's (as srcip on the packets forwarded to the PA) and you can use the ACC in the PA device to dig on what each client have done (otherwise the PA would just see the ip of the webproxy).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Mar 2012 08:50:42 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-03-29T08:50:42Z</dc:date>
    <item>
      <title>Web Browsing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing/m-p/36449#M26795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're about to install the web filter licence for the PA. Our current system is a proxy configuraiton via websense. Now that we're going to use the PA for web filtering is the best practise to create a security rule allowing all internal PCs direct access to the Internet using the common web based ports or is there some other way of making the PA the proxy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rod&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2012 08:27:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-browsing/m-p/36449#M26795</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2012-03-29T08:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Web Browsing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing/m-p/36450#M26796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;The PA doesnt do web proxy so it will not understand when a client connects to the ip address of the PA box and sends "CONNECT &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.example.com/"&gt;http://www.example.com/&lt;/A&gt;&lt;SPAN&gt; HTTP/1.0".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you want to keep the proxy setting in your clients (well browser settings) and in order to avoid having public ip addresses in your internal network you would need to use a dedicated forward proxy for this. A good (and cheap) solution is to use squid. There are also squid appliances if you want to pay some money: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.squid-cache.org/Support/products.html"&gt;http://www.squid-cache.org/Support/products.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise you need to disable the proxysetting in your client-browsers and make sure to point defgw towards your PA box (for the client the defgw is most likely already some router, then you need to add a routing entry in this router to point towards PA as defgw).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit: A tip when using a forward webproxy inline with a PA is to setup the webproxy to use "keep client ip". Then the PA will get the client ip's (as srcip on the packets forwarded to the PA) and you can use the ACC in the PA device to dig on what each client have done (otherwise the PA would just see the ip of the webproxy).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2012 08:50:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-browsing/m-p/36450#M26796</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-03-29T08:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: Web Browsing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing/m-p/36451#M26797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks for taking the time to respond.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rod&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2012 13:51:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-browsing/m-p/36451#M26797</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2012-03-29T13:51:31Z</dc:date>
    </item>
  </channel>
</rss>

