<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Web server and TMG in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/web-server-and-tmg/m-p/4320#M3200</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide a bit more information on your setup? Is your web server published from the inside or from the outsite? Is your web server in your trust zone or is it in a DMZ zone?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Jun 2012 14:28:23 GMT</pubDate>
    <dc:creator>npare</dc:creator>
    <dc:date>2012-06-01T14:28:23Z</dc:date>
    <item>
      <title>Web server and TMG</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-server-and-tmg/m-p/4319#M3199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;our web servers are published using tmg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;at the moment i have a security rule form l3-trust to l4 untrust with any set&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what do i need to do to allow traffic through to the web servers and tmg?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 11:47:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-server-and-tmg/m-p/4319#M3199</guid>
      <dc:creator>notleyhigh</dc:creator>
      <dc:date>2012-06-01T11:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Web server and TMG</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-server-and-tmg/m-p/4320#M3200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide a bit more information on your setup? Is your web server published from the inside or from the outsite? Is your web server in your trust zone or is it in a DMZ zone?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 14:28:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-server-and-tmg/m-p/4320#M3200</guid>
      <dc:creator>npare</dc:creator>
      <dc:date>2012-06-01T14:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: Web server and TMG</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-server-and-tmg/m-p/4321#M3201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If possible (as a test) you can use appid:any and service:any and enable log on session start AND session end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then take a peak in the traffic log to see how the traffic is being identified, lets say "sharepoint" (or whatever).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally change this rule from any into appid:sharepoint (or whatever you found), service:application-default (or manually specify which TCP/UDP ports you wish to allow) and disable "log on session start" (just keep log on session end).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dont forget to enable the IPS while your are at it (in the options).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit: And if you have SSL traffic you should take a look at enabling SSL-termination so the PA device can inspect the encrypted data aswell...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 18:35:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-server-and-tmg/m-p/4321#M3201</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-06-01T18:35:43Z</dc:date>
    </item>
  </channel>
</rss>

