<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can I use PA Policy Based Forwarding to forward user Http and https port traffic to a squid proxy server (tcp port: 8080)? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-pa-policy-based-forwarding-to-forward-user-http-and/m-p/4693#M3459</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So uhm... what CAN a PBF based on appid be used for?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Jan 2013 09:08:24 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-01-30T09:08:24Z</dc:date>
    <item>
      <title>Can I use PA Policy Based Forwarding to forward user Http and https port traffic to a squid proxy server (tcp port: 8080)?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-pa-policy-based-forwarding-to-forward-user-http-and/m-p/4691#M3457</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can I use PA Policy Based Forwarding to forward user Http and https port traffic to a squid proxy server (tcp port: 8080)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 03:15:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-pa-policy-based-forwarding-to-forward-user-http-and/m-p/4691#M3457</guid>
      <dc:creator>SHKP</dc:creator>
      <dc:date>2013-01-30T03:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Can I use PA Policy Based Forwarding to forward user Http and https port traffic to a squid proxy server (tcp port: 8080)?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-pa-policy-based-forwarding-to-forward-user-http-and/m-p/4692#M3458</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, Policy Based Forwarding will work for forwarding traffic passing through the PA based on the PBF rules setup.&amp;nbsp; Would suggest reviewing the following:&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="3220" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Special notes:&lt;/P&gt;&lt;P&gt;PBF Takes place before route look-up (routing table)&lt;/P&gt;&lt;P&gt;PBF does not function for host bound traffic, IPSec Tunnel to the PA, Global Protect Connection, so forth.&amp;nbsp; Any traffic destined to or from a PA interface will not match a PBF rule&lt;/P&gt;&lt;P&gt;When using Applications for PBF rules be aware Application signature match for TCP traffic comes after the 3-way handshake.&amp;nbsp; So PBF rule may not match the initial 3-way handshake&lt;/P&gt;&lt;P&gt;and thus traverse the PA based on route look-up.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the specific question would suggest service (http/https) for matching criteria in rule.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 06:57:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-pa-policy-based-forwarding-to-forward-user-http-and/m-p/4692#M3458</guid>
      <dc:creator>vkelley</dc:creator>
      <dc:date>2013-01-30T06:57:14Z</dc:date>
    </item>
    <item>
      <title>Re: Can I use PA Policy Based Forwarding to forward user Http and https port traffic to a squid proxy server (tcp port: 8080)?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-pa-policy-based-forwarding-to-forward-user-http-and/m-p/4693#M3459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So uhm... what CAN a PBF based on appid be used for?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 09:08:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-pa-policy-based-forwarding-to-forward-user-http-and/m-p/4693#M3459</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-01-30T09:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Can I use PA Policy Based Forwarding to forward user Http and https port traffic to a squid proxy server (tcp port: 8080)?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-pa-policy-based-forwarding-to-forward-user-http-and/m-p/4694#M3460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wait a second... what you describe sounds as if you're trying to transparently have web traffic make it over to your squid proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normally you'd use WCCP for this... is policy based forwarding how you'd do this with Palo Alto?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 14:36:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-pa-policy-based-forwarding-to-forward-user-http-and/m-p/4694#M3460</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-01-30T14:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: Can I use PA Policy Based Forwarding to forward user Http and https port traffic to a squid proxy server (tcp port: 8080)?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-pa-policy-based-forwarding-to-forward-user-http-and/m-p/4695#M3461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Comment of TCP was a word of caution based on application signature match.&amp;nbsp; &lt;/P&gt;&lt;P&gt;TCP:&lt;/P&gt;&lt;P&gt;syn-&amp;gt;&lt;/P&gt;&lt;P&gt;syn-ack &amp;lt;-&lt;/P&gt;&lt;P&gt;ack-&amp;gt;&lt;/P&gt;&lt;P&gt;All standard TCP packets no payload to run signature match on. After the 3-way signature match will come into play&lt;/P&gt;&lt;P&gt;and a l7 processing completed.&amp;nbsp; If rule is based on TCP app-sig will not match until l7 processing done.&amp;nbsp; Note so &lt;/P&gt;&lt;P&gt;far this is TCP.&amp;nbsp; UDP is different matter since initiating packets will have a payload to that can be l7 processed.&amp;nbsp; &lt;/P&gt;&lt;P&gt;Also if company is using any application overrides (skipping l7 processing) these can also match based on initial packet.&lt;/P&gt;&lt;P&gt;TCP: Caution&lt;/P&gt;&lt;P&gt;UDP: Okay &lt;/P&gt;&lt;P&gt;App-Override (l7 skipped): Okay&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most PBF I have seen in cases is more for source based routing and ISP redundancy.&amp;nbsp; Not for load balancing of applications.&lt;/P&gt;&lt;P&gt;Not to say though forcing UDP sessions or TCP (with service setup) would not work.&amp;nbsp; For example in the initial question in this discussion if setup for port 8080.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 14:14:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-pa-policy-based-forwarding-to-forward-user-http-and/m-p/4695#M3461</guid>
      <dc:creator>vkelley</dc:creator>
      <dc:date>2013-01-31T14:14:52Z</dc:date>
    </item>
  </channel>
</rss>

