<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA5020 and Proxy Server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37881#M27726</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/28058"&gt;aguley&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I went through &lt;A _jive_internal="true" data-containerid="2027" data-containertype="14" data-objectid="1128" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-1128"&gt;Enabling support for the&amp;nbsp; X-Forwarded-For HTTP header&lt;/A&gt;. document and didn't see the commit operation mentioned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have enabled it from the configuration mode, lets make sure you commit the configuration:&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;gt; configure&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;# set deviceconfig setting ctd x-forwarded-for yes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;#commit force&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Regards, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Kunal Adak&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Jul 2014 13:54:17 GMT</pubDate>
    <dc:creator>kadak</dc:creator>
    <dc:date>2014-07-23T13:54:17Z</dc:date>
    <item>
      <title>PA5020 and Proxy Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37880#M27725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a PA5020 and am using a proxy server to filter internet traffic.&amp;nbsp; In the traffic monitor all the traffic I see going to the web is from the proxy server.&amp;nbsp; I turned this feature on on the firewall.&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1128"&gt;Enabling support for the  X-Forwarded-For HTTP header&lt;/A&gt;.&amp;nbsp; After enabling this feature I didn't see any difference in the monitor section of the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Is there anyway I can identify the user or IP address instead of just identifying the proxy server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2014 12:18:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37880#M27725</guid>
      <dc:creator>aguley</dc:creator>
      <dc:date>2014-07-23T12:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: PA5020 and Proxy Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37881#M27726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/28058"&gt;aguley&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I went through &lt;A _jive_internal="true" data-containerid="2027" data-containertype="14" data-objectid="1128" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-1128"&gt;Enabling support for the&amp;nbsp; X-Forwarded-For HTTP header&lt;/A&gt;. document and didn't see the commit operation mentioned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have enabled it from the configuration mode, lets make sure you commit the configuration:&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;gt; configure&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;# set deviceconfig setting ctd x-forwarded-for yes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;#commit force&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Regards, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Kunal Adak&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2014 13:54:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37881#M27726</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2014-07-23T13:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: PA5020 and Proxy Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37882#M27727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's the command that I ran and I commited the changes as well.&amp;nbsp; Still just seeing traffic from proxy.&amp;nbsp; Or possibly I am looking in the wrong place.&amp;nbsp; Should I just see it in the monitor section of the firewall or do I need to dig deeper into some logs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2014 14:22:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37882#M27727</guid>
      <dc:creator>aguley</dc:creator>
      <dc:date>2014-07-23T14:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: PA5020 and Proxy Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37883#M27728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A _jive_internal="true" class="jiveTT-hover-user jive-link-profile-small" data-containerid="-1" data-containertype="-1" data-objectid="28058" data-objecttype="3" href="https://live.paloaltonetworks.com/people/aguley"&gt;aguley&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you are looking into URL logs for X-forwarded information - not the traffic logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reference:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/33566"&gt;x-forward source user information is not showing in traffic logs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2014 14:28:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37883#M27728</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2014-07-23T14:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: PA5020 and Proxy Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37884#M27729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am looking at the traffic logs.&amp;nbsp; I am getting an error trying to click on your link saying access is restircted.&amp;nbsp; How do I view the URL logs for X-forwarded information?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am very new to PA so thank you for the very quick responses.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2014 14:31:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37884#M27729</guid>
      <dc:creator>aguley</dc:creator>
      <dc:date>2014-07-23T14:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: PA5020 and Proxy Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37885#M27730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A _jive_internal="true" class="jiveTT-hover-user jive-link-profile-small" data-containerid="-1" data-containertype="-1" data-objectid="28058" data-objecttype="3" href="https://live.paloaltonetworks.com/people/aguley"&gt;aguley&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under Monitor tab, click on URL filtering logs. Under URL filtering logs, you need to have the 'source user' column. If it doesn't have by default, then you can add the column.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-0 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/14651_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or you can enable it :&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/14652_pastedImage_1.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2014 14:41:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37885#M27730</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2014-07-23T14:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: PA5020 and Proxy Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37886#M27731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are not using the PA url filtering.&amp;nbsp; We are filtering with our proxy.&amp;nbsp; Should I still see the traffic in the URL Filtering of the PA.&amp;nbsp; I am not seeing anything currently in it.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2014 15:07:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37886#M27731</guid>
      <dc:creator>aguley</dc:creator>
      <dc:date>2014-07-23T15:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: PA5020 and Proxy Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37887#M27732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/28058"&gt;aguley&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you don't have URL filtering license, I presume you don't have URL filtering profile applied to any of your security policies. If you don't have URL filtering profiles applied to security policies, then you won't see URL filtering logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2014 15:44:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa5020-and-proxy-server/m-p/37887#M27732</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2014-07-23T15:44:09Z</dc:date>
    </item>
  </channel>
</rss>

