<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to setup pan to inspect/monitor wireless traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46139#M33904</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Screenshot:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. setup vwire on ethernet0/5 and ethernet0/6 with (both) trusted interface&lt;/P&gt;&lt;P&gt;2. no policies where applied to either interface&lt;/P&gt;&lt;P&gt;3. from the lan I could not browse to controller nor see broadcast SSIDs &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 08 Nov 2011 23:11:15 GMT</pubDate>
    <dc:creator>psimilien_1</dc:creator>
    <dc:date>2011-11-08T23:11:15Z</dc:date>
    <item>
      <title>How to setup pan to inspect/monitor wireless traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46131#M33896</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am currently running a PA-500 in IPS mode and is setup as a VWire behind my ASA. I have an environment that consist of a Cisco wireless controller and APs. How do I monitor my wireless traffic or better yet how do i setup policies for this? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way I had a conversation with support this morning and it went no where.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Nov 2011 13:21:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46131#M33896</guid>
      <dc:creator>psimilien_1</dc:creator>
      <dc:date>2011-11-08T13:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup pan to inspect/monitor wireless traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46132#M33897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My question has not been answered yet &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Nov 2011 22:43:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46132#M33897</guid>
      <dc:creator>psimilien_1</dc:creator>
      <dc:date>2011-11-08T22:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup pan to inspect/monitor wireless traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46133#M33898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;P,&lt;/P&gt;&lt;P&gt;I think part of what you are asking is really a professional services design question as opposed to a configuration issue.&lt;/P&gt;&lt;P style="text-align: left;"&gt;As far as monitoring your wireless traffic, unless the traffic crosses the wire and passes through either a switch or the PA-500 it won't see the traffic - so any wireless to wireless traffic will not be seen unless you are able to span that traffic out to the PA-500.&lt;/P&gt;&lt;P style="text-align: left;"&gt;Hope that is of some help&lt;/P&gt;&lt;P style="text-align: left;"&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Nov 2011 22:55:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46133#M33898</guid>
      <dc:creator>jcostello</dc:creator>
      <dc:date>2011-11-08T22:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup pan to inspect/monitor wireless traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46134#M33899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your question is rather broad. Could you give us some more specifics about your implementation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you going to allow all traffic bidirectionally? If not what applications will you allow and in which direction?&lt;/P&gt;&lt;P&gt;Do you need to identify users and map them to IP addresses?&lt;/P&gt;&lt;P&gt;I assume you will be implementing security profiles to block viruses, malware, spyware and attempts to exploit vulnerabilities. Please confirm if you plan to do this?&lt;/P&gt;&lt;P&gt;Do you plan to implement file blocking?&lt;/P&gt;&lt;P&gt;Will you implement data filtering?&lt;/P&gt;&lt;P&gt;Are you going to implement URL filtering? (requires a license)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Nov 2011 22:56:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46134#M33899</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-11-08T22:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup pan to inspect/monitor wireless traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46135#M33900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What I would like to do is create a vwire for the traffic from the controller to the core switch. My problem is that, in doing so traffic is block without any policie setting. How can I set this up? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Nov 2011 23:00:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46135#M33900</guid>
      <dc:creator>psimilien_1</dc:creator>
      <dc:date>2011-11-08T23:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup pan to inspect/monitor wireless traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46136#M33901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The anwser to your questions are yes and yes. I would like to setup a vwire or layer 3 interface (if needed) to map ip to users..ect... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Nov 2011 23:02:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46136#M33901</guid>
      <dc:creator>psimilien_1</dc:creator>
      <dc:date>2011-11-08T23:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup pan to inspect/monitor wireless traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46137#M33902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please post a screengrab of your security policies?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once I see that I can give you some specific guidance on most of the questions that you have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Nov 2011 23:06:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46137#M33902</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-11-08T23:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup pan to inspect/monitor wireless traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46138#M33903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;P-&lt;/P&gt;&lt;P&gt;Here is a link to an older configuration document on how to set up a Virtual Wire evaluation&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/docs/DOC-1165"&gt;https://live.paloaltonetworks.com/docs/DOC-1165&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The core concepts have not changed.&lt;/P&gt;&lt;P&gt;You will need a set of policies to pass traffic between the interfaces - the simplest are&lt;/P&gt;&lt;P&gt;1. Zone 1 to Zone 2 allow any address to any application and services&lt;/P&gt;&lt;P&gt;2. Zone 2 to Zone 1 allow any address to any application and services&lt;/P&gt;&lt;P&gt;You can add complexity with more rules as you go.&lt;/P&gt;&lt;P&gt;Hope that helps&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Nov 2011 23:10:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46138#M33903</guid>
      <dc:creator>jcostello</dc:creator>
      <dc:date>2011-11-08T23:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup pan to inspect/monitor wireless traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46139#M33904</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Screenshot:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. setup vwire on ethernet0/5 and ethernet0/6 with (both) trusted interface&lt;/P&gt;&lt;P&gt;2. no policies where applied to either interface&lt;/P&gt;&lt;P&gt;3. from the lan I could not browse to controller nor see broadcast SSIDs &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Nov 2011 23:11:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46139#M33904</guid>
      <dc:creator>psimilien_1</dc:creator>
      <dc:date>2011-11-08T23:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup pan to inspect/monitor wireless traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46140#M33905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;P -&lt;/P&gt;&lt;P&gt;You will still need to configure a trust to trust rule. Traffic passing between interfaces on a Palo Alto Firewall still needs to have zone relative rules to allow the traffic to pass.&lt;/P&gt;&lt;P&gt;Since you do not have a security policy from trust to trust, no traffic is passing.&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Nov 2011 23:23:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46140#M33905</guid>
      <dc:creator>jcostello</dc:creator>
      <dc:date>2011-11-08T23:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup pan to inspect/monitor wireless traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46141#M33906</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will let you know the outcome of this soon, thank you. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Nov 2011 15:57:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-setup-pan-to-inspect-monitor-wireless-traffic/m-p/46141#M33906</guid>
      <dc:creator>psimilien_1</dc:creator>
      <dc:date>2011-11-09T15:57:10Z</dc:date>
    </item>
  </channel>
</rss>

