<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OCSP service route? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40373#M29629</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still waiting for an official Palo Alto reply, but I think I found my answer in the admin guide&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN style="color: #000000; font-size: 12px; font-family: 'Microsoft Sans Serif';"&gt;Service Route &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 12px;"&gt;Configuration &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 12px;"&gt;(Continued)&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="color: #000000; font-size: 12px; font-family: 'Microsoft Sans Serif';"&gt;For example, if you want to route Kerberos authentication requests on an interface other than the MGT port, you need to configure the Destination and Source Address in the right section of the Service Route Configuration window since Kerberos is not listed in the default Service column.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For all services that are not selectable on the left side, you have to configure a route on the right. So i guess this will be the same for OCSP...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ex.&lt;/P&gt;&lt;P&gt;Destination: IP of your internal kerberos server&lt;/P&gt;&lt;P&gt;Source Address: IP of your internal interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But this setup has some limitations:&lt;/P&gt;&lt;P&gt;Since you can not choose a service or application, this route is for all traffic! And it will overrule all settings set on the left.&lt;/P&gt;&lt;P&gt;Ex.&lt;/P&gt;&lt;P&gt;Service: DNS&lt;/P&gt;&lt;P&gt;Source Address: MGT&lt;/P&gt;&lt;P&gt;+ primary DNS is set to same IP as you kerberos server&lt;/P&gt;&lt;P&gt;=&amp;gt; DNS traffic wil NOT use the MGT interface, but hit on the right side route rules and use you internal interface as source...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Jun 2013 14:51:22 GMT</pubDate>
    <dc:creator>mr.linus</dc:creator>
    <dc:date>2013-06-04T14:51:22Z</dc:date>
    <item>
      <title>OCSP service route?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40369#M29625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Question: What service route does the PA take for his OCSP requests?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since we can not choose anything under the service routes, I suppose it will use the management as default...&lt;/P&gt;&lt;P&gt;Is there any way to change this to some other interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Linus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2013 11:47:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40369#M29625</guid>
      <dc:creator>mr.linus</dc:creator>
      <dc:date>2013-05-29T11:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP service route?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40370#M29626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Linus,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CRL-status service route may be worth a try if you have not done so already?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2013 12:31:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40370#M29626</guid>
      <dc:creator>DavePalo</dc:creator>
      <dc:date>2013-05-29T12:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP service route?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40371#M29627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have asked Palo Alto directly to confirm this, since I was not able to really pin point the ocsp traffic in my packet captures.&lt;/P&gt;&lt;P&gt;I am still waiting for a definitive answer on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the mean time, I have another related question/observation: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way of checking if OCSP stapling was used? Is there a way of testing if a certain website is using this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Linus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 May 2013 09:24:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40371#M29627</guid>
      <dc:creator>mr.linus</dc:creator>
      <dc:date>2013-05-31T09:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP service route?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40372#M29628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To answer part of my own question.&lt;/P&gt;&lt;P&gt;Apparently you can use openssl to test this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"openssl s_client -connect login.live.com:443 -tls1&amp;nbsp; -tlsextdebug&amp;nbsp; -status"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Linus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 May 2013 09:49:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40372#M29628</guid>
      <dc:creator>mr.linus</dc:creator>
      <dc:date>2013-05-31T09:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP service route?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40373#M29629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still waiting for an official Palo Alto reply, but I think I found my answer in the admin guide&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN style="color: #000000; font-size: 12px; font-family: 'Microsoft Sans Serif';"&gt;Service Route &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 12px;"&gt;Configuration &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif'; font-size: 12px;"&gt;(Continued)&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="color: #000000; font-size: 12px; font-family: 'Microsoft Sans Serif';"&gt;For example, if you want to route Kerberos authentication requests on an interface other than the MGT port, you need to configure the Destination and Source Address in the right section of the Service Route Configuration window since Kerberos is not listed in the default Service column.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For all services that are not selectable on the left side, you have to configure a route on the right. So i guess this will be the same for OCSP...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ex.&lt;/P&gt;&lt;P&gt;Destination: IP of your internal kerberos server&lt;/P&gt;&lt;P&gt;Source Address: IP of your internal interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But this setup has some limitations:&lt;/P&gt;&lt;P&gt;Since you can not choose a service or application, this route is for all traffic! And it will overrule all settings set on the left.&lt;/P&gt;&lt;P&gt;Ex.&lt;/P&gt;&lt;P&gt;Service: DNS&lt;/P&gt;&lt;P&gt;Source Address: MGT&lt;/P&gt;&lt;P&gt;+ primary DNS is set to same IP as you kerberos server&lt;/P&gt;&lt;P&gt;=&amp;gt; DNS traffic wil NOT use the MGT interface, but hit on the right side route rules and use you internal interface as source...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2013 14:51:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40373#M29629</guid>
      <dc:creator>mr.linus</dc:creator>
      <dc:date>2013-06-04T14:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP service route?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40374#M29630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Dyoung,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems you were right after all:&lt;/P&gt;&lt;P&gt;Official reply from PA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;The service route in question is the CRL one. That will apply for both.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since we are having some issues with OCSP I am not able to confirm this from our lab setup, but I guess it is correct.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jun 2013 07:21:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40374#M29630</guid>
      <dc:creator>mr.linus</dc:creator>
      <dc:date>2013-06-06T07:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP service route?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40375#M29631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Testing the PAN OCSP responder with &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;"openssl s_client -connect ocsp.company.com:443 -tls1&amp;nbsp; -tlsextdebug&amp;nbsp; -status"&amp;nbsp; (PA-200 5.0.4)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;root@backup:~# openssl s_client -connect ocsp.company.com:443 -tls1&amp;nbsp; -tlsextdebug&amp;nbsp; -status&lt;/P&gt;&lt;P&gt;CONNECTED(00000003)&lt;/P&gt;&lt;P&gt;OCSP response: &lt;STRONG&gt;no response sent&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was expecting to see something like &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OCSP response:&lt;/P&gt;&lt;P&gt;======================================&lt;/P&gt;&lt;P&gt;OCSP Response Data:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; OCSP Response Status: successful (0x0)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Response Type: Basic OCSP Response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Version: 1 (0x0)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jun 2013 16:32:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40375#M29631</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2013-06-07T16:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP service route?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40376#M29632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;dear gafrol,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the openssl command given is to test ocsp stapling. apparently PA does not support OCSP stapling. Find here their official anszer to this question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Regarding you oscp stapling question, per the PM: We do not support ocsp stapling which just takes an oscp response and folds it into the tls handshake.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that is why you got that result...&lt;/P&gt;&lt;P&gt;linus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 12:11:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40376#M29632</guid>
      <dc:creator>mr.linus</dc:creator>
      <dc:date>2013-06-18T12:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP service route?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40377#M29633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh OK thanks, good to know !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 16:54:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ocsp-service-route/m-p/40377#M29633</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2013-06-18T16:54:14Z</dc:date>
    </item>
  </channel>
</rss>

