<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA and icap? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48047#M35330</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh yeah and for anyone wondering.&amp;nbsp; PBF doesn't do it.&amp;nbsp; It send routes out an egress, ICAP is different than routing in the DLP world because the DLP can mark up ICAP like it cal SPAM X-FORWARD messages.&amp;nbsp; PBF Doesn't allow this so unless your DLP tool (Websense has a few articles on this) can do that then you're out of luck. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Apr 2013 17:51:50 GMT</pubDate>
    <dc:creator>amansour</dc:creator>
    <dc:date>2013-04-18T17:51:50Z</dc:date>
    <item>
      <title>PA and icap?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48041#M35324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello world,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is there a chance/way of talking icap between my squid and the PA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;Marcus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Feb 2011 08:09:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48041#M35324</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-02-23T08:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: PA and icap?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48042#M35325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, but can you solve whatever you want to do with PBF? Tell us more!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Feb 2011 08:20:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48042#M35325</guid>
      <dc:creator>rapoint_person</dc:creator>
      <dc:date>2011-02-23T08:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: PA and icap?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48043#M35326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yeah I need to setup an ICAP server to SQUID as well,&amp;nbsp; did PBF do this for you? Could you send block pages from PA directly?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 18:13:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48043#M35326</guid>
      <dc:creator>amansour</dc:creator>
      <dc:date>2011-07-19T18:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: PA and icap?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48044#M35327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any updates.&amp;nbsp; We have a number of customers that run 3rd party DLP and want to eliminate their proxy and ICAP, if we can do policy based forwarding or receive messages like ICAP we can send the pages from PA, which would truly make this a proxy replacement.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Aug 2011 14:50:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48044#M35327</guid>
      <dc:creator>amansour</dc:creator>
      <dc:date>2011-08-18T14:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: PA and icap?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48045#M35328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;2 years later and this is still on my wishlist. Working with a solution like RSA DLP is impossible with a Palo Alto. It's a huge problem in helping customers build a comprehensive DLP strategy. The PA built in DLP doesn't do enough and the solution of "just block Dropbox and Gmail Send" isn't really an option for most customers. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 17:38:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48045#M35328</guid>
      <dc:creator>jmahoney</dc:creator>
      <dc:date>2013-04-18T17:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: PA and icap?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48046#M35329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@jmahoney I think this will never make the roadmap.&amp;nbsp; ICAP and WCCP are forwarding for proxies (HTTP/HTTPS/FTP) that's the problem.&amp;nbsp; PAN does all protocols all the time, they can't proxy, there not a proxy, the developers likely cannot make this happen.&amp;nbsp; I think network based DLP better get more protocols to stay relevant on the wire which is why ICAP is no good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I do is instead you should look at a re-generator TAP. Then tools which need to see all the traffic to do their job can have multiple copies (DLP is a great example, RSA Netwitness and other recorders like Niksun too). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then everyone gets a copy and is happy.&amp;nbsp;&amp;nbsp; With respect to blocking (the ICAP forward) the DLP integration would likely have to create a flexible response (Symantec DLP does this) where you could send something to the XML API, like you could with a proxy filter (Websense) or MTA and SPAM filter.&amp;nbsp; Each response is going to be specific to the type of block and in the PAN case I think that's an XML-API call. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway my two cents.&amp;nbsp; Have the DLP bend the response because proxy is dead and they will be too if THEY don't adapt. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 17:48:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48046#M35329</guid>
      <dc:creator>amansour</dc:creator>
      <dc:date>2013-04-18T17:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: PA and icap?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48047#M35330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh yeah and for anyone wondering.&amp;nbsp; PBF doesn't do it.&amp;nbsp; It send routes out an egress, ICAP is different than routing in the DLP world because the DLP can mark up ICAP like it cal SPAM X-FORWARD messages.&amp;nbsp; PBF Doesn't allow this so unless your DLP tool (Websense has a few articles on this) can do that then you're out of luck. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 17:51:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48047#M35330</guid>
      <dc:creator>amansour</dc:creator>
      <dc:date>2013-04-18T17:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: PA and icap?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48048#M35331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;amansour is correct - since we are not a proxy nor do we intend to be one, we will not support ICAP.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 19:01:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48048#M35331</guid>
      <dc:creator>dyang</dc:creator>
      <dc:date>2013-04-18T19:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: PA and icap?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48049#M35332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So how do you explain the SSL/SSH-proxy and DNS-proxy? :smileysilly:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 19:23:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48049#M35332</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-04-18T19:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: PA and icap?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48050#M35333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@mikand, they should have probably labelled it forward instead of proxy.&amp;nbsp; SSL and SSH also misleading but proxy in our DLP case means re-write.&amp;nbsp; It terminates the session and re-establishes it which can work for protocols like http, https, ftp but not all applications. Those proxy features forward traffic they don't re-write it.&amp;nbsp; I think It's also why the GlobalProtect portal is only somewhere you can download the agent and not put links or content that is re-written to the internal segments like other SSL-VPNs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also Nice Pantopia score &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 19:52:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48050#M35333</guid>
      <dc:creator>amansour</dc:creator>
      <dc:date>2013-04-18T19:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: PA and icap?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48051#M35334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dyang, my recommendation is that Palo Alto work with top DLP vendors to figure out some sort of DLP solution, doesn't have to be ICAP. The Palo Alto strategy is not realistic for most customers and I've seen PA lose a number of engagements to customers who want a real DLP strategy. The fact that Palo Alto doesn't integrate with anyone out of the box is an issue. I haven't run into a customer yet that wants to create custom connectors with the API. If you put anything in Gartner, which I don't, at least Checkpoint has a more robust DLP strategy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's just my 2 cents. We work with a ton of customers and a lot of PA customers and this (and global protect) are my only two complaints against the platform.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 23:42:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48051#M35334</guid>
      <dc:creator>jmahoney</dc:creator>
      <dc:date>2013-04-18T23:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: PA and icap?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48052#M35335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Agreed - we have reached out to vendors such as Symantec to see if there's something that we can do to at least provide a viable solution for our customers.&amp;nbsp; We have not made any progress to-date, but you'll certainly hear about it once there is something to report!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 23:54:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48052#M35335</guid>
      <dc:creator>dyang</dc:creator>
      <dc:date>2013-04-18T23:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: PA and icap?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48053#M35336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Regarding those scores, thanks &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding those proxies another example is wildfire.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even if PA hardware design most likely cannot be used with a ICAP and then continue (that is client click on a link, PA downloads the file, sends it to ICAP, gets the response and if negative (that is nothing bad was found) it will forward the file to the client) at least not with +10Gbit/s speeds (because the mgmtplane would need to be part of this) it perhaps should be possible to make it a one way the same way as with wildfire (this way, as with wildfire, the files can be buffered by the mgmtplane and it in some extend doesnt matter if the file was scanned now or a few seconds later (due to high load)).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is client downloads file but instead of sending it to wildfire the PA device will send it as ICAP to a ICAP server. The response will then later be attached to the log. This wont bring you DLP (as in prevention) but at least DLD (as in detection) - the question here might be if this is enough (at least it would be enough for those who accept DLD)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps something for PA to consider for upcoming hardware releases?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Same goes (if we speak about DLP) with that 7 bytes limit (your signature must look for 7 bytes or more)...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Apr 2013 01:39:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48053#M35336</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-04-19T01:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: PA and icap?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48054#M35337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey All I have the Symantec DLP 11.6 deployed with PAN in a few places.&amp;nbsp; For the integration Symantec uses PCAP (SPAN or Mirror Ports to do network detection and the response is to markup the messages (ICAP and X-Forward for Web and Email) What we recommend is creating a FlexReponse (Symantec Specific) which makes an XML call can take a quick action on the user (so far this isn't fast enough to stop because we don't have a way to instantly send the user a block page or at least haven't found it).&amp;nbsp; @jmahoney I think we should put a thread together like the SIEM one with a point person assigned for each DLP platform. Just like ArcSight and RSA and others put their SIEM integration and docs on the forum there should be an integration for each documented here.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Symantec Email Prevent there is no integration required, for Web Prevent this ICAP integration will likely need to be supplemented with a better FlexResponse. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for the others, without ICAP we'd need a way to call the XML quickly to do something, (Block URL is the most common). But without doing a commit. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway happy to work on this with you guys on it we are a CPSP and ASC and Go to Partner with Symantec DLP at least.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Apr 2013 13:33:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/48054#M35337</guid>
      <dc:creator>amansour</dc:creator>
      <dc:date>2013-04-19T13:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: PA and icap?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/307728#M79911</link>
      <description>&lt;P&gt;I'm curious whether anyone is using the PANOS L3 security broker service -&amp;gt; Proxy supporting ICAP -&amp;gt; Symantec Network Prevent server.&amp;nbsp; I've heard this design works with PANOS, F5 &amp;gt; v14 and Symantec DLP NWP 15.5.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2020 18:58:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/307728#M79911</guid>
      <dc:creator>coldstone2</dc:creator>
      <dc:date>2020-01-23T18:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: PA and icap?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/431529#M95093</link>
      <description>&lt;P&gt;We just implemented that design with their new version of Security Broker called Network Packet Broker in version 10.1.X.&amp;nbsp; We used the NPB to build a transparent bridge that sends all traffic (decrypted and clear text) through the bridge into our DLP and back out into our Palo.&amp;nbsp; Works really nice!&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 19:58:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-and-icap/m-p/431529#M95093</guid>
      <dc:creator>BobbyHiers</dc:creator>
      <dc:date>2021-09-03T19:58:18Z</dc:date>
    </item>
  </channel>
</rss>

