<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DHCP Option 252 WPAD in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39787#M29178</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Within GP, you can push the default route 0.0.0.0/0 to the clients and all traffic will be routed back to the GP gateway.&amp;nbsp; If you want port 80 traffic to hit your WebSense, you could configure Policy Based Forwarding (PBF) on the PA device to send port 80 traffic to WebSense.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Feb 2012 19:50:33 GMT</pubDate>
    <dc:creator>rmonvon</dc:creator>
    <dc:date>2012-02-10T19:50:33Z</dc:date>
    <item>
      <title>DHCP Option 252 WPAD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39780#M29171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seeing since there is no support to push down client proxy settings via GP - does anyone know if we can set up a DHCP scope for SSL VPN clients that has/allows for option 252 WPAD support?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rod&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Feb 2012 09:46:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39780#M29171</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2012-02-08T09:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Option 252 WPAD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39781#M29172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean having the PAN acting as a DHCP-server for your clients?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 08:30:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39781#M29172</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-02-09T08:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Option 252 WPAD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39782#M29173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi - Thanks for responding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes having an option for wpad that's configurable via the dhcp or IP pool option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example we have a laptop that connects via GP or Cisco VPN client. The laptop gets an IP address from the IP pool however the laptop doesn't know the correct proxy address and therfore can't access the interent via our internal network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With CIsco ASA's and PIX's you could specify an address for the proxy that was downloaded to the client. There is no feature with GP that supports this funciton.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rod&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 09:49:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39782#M29173</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2012-02-09T09:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Option 252 WPAD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39783#M29174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont know if the built in dhcpserver of PAN have support for option 252 today. Sounds like you should contact your sales rep with a feature request regarding this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another method to inform the client of which proxy to use is to send this info through an AD-policy if you use AD for your internal network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 09:55:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39783#M29174</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-02-09T09:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Option 252 WPAD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39784#M29175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've contacted our sales rep and requested this feature to be included in future updates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Re AD - there is no way to achieve this without invoking some sort of trigger to run the AD policy on the remote clients. This is something I want to stay clear off.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rod&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 14:16:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39784#M29175</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2012-02-10T14:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Option 252 WPAD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39785#M29176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;GlobalProtect doesn't provide this option at this point. We also don't use DHCP to assign IP addresses or any other network parameters to the GlobalProtect Agents. Just out of curiousity, why do you need to proxy remote access connections to your intranet? If it is for access control, I suppose App-ID and user authentication would give you the tools needed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 18:26:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39785#M29176</guid>
      <dc:creator>mwalter</dc:creator>
      <dc:date>2012-02-10T18:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Option 252 WPAD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39786#M29177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply. I need to assign a proxy to all remote clients so that all Internet traffic (when connected through GP) is routed via in internal Websense server. Split tunnelling isn't an option and all http traffic must pass though the WEbsense box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As we use WEbsense and external radius servers for authentication we haven't needed to use user authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've asked our reseller to pass this onto PA as a feature request,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rod&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 19:43:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39786#M29177</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2012-02-10T19:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Option 252 WPAD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39787#M29178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Within GP, you can push the default route 0.0.0.0/0 to the clients and all traffic will be routed back to the GP gateway.&amp;nbsp; If you want port 80 traffic to hit your WebSense, you could configure Policy Based Forwarding (PBF) on the PA device to send port 80 traffic to WebSense.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 19:50:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39787#M29178</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-02-10T19:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Option 252 WPAD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39788#M29179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Fantastic, thanks for the advice. Will try it out on Monday.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rod&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 20:24:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dhcp-option-252-wpad/m-p/39788#M29179</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2012-02-10T20:24:54Z</dc:date>
    </item>
  </channel>
</rss>

