<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: is it possible to forward clients with paloalto for websense ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-forward-clients-with-paloalto-for-websense/m-p/6000#M4365</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi PAN-OS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This feature is just like SPAN in Cisco world. But you can say its decrypt-SPAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you get the information, but can not take any action on it. So, its not possible to force websense to take any action on decrypted data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 Sep 2014 17:29:30 GMT</pubDate>
    <dc:creator>hshah</dc:creator>
    <dc:date>2014-09-25T17:29:30Z</dc:date>
    <item>
      <title>is it possible to forward clients with paloalto for websense ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-forward-clients-with-paloalto-for-websense/m-p/5997#M4362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a topology like below.Clients using Cisco vpn and they are enforced to use some proxies(enforced from Active Directory)&lt;/P&gt;&lt;P&gt;There is a Local Websense but it cannot be used because of that enforcement.&lt;/P&gt;&lt;P&gt;Can Paloalto firewall decrypt that SSL traffic and make websense available to use ?&lt;/P&gt;&lt;P&gt;is that possible ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Calibri','sans-serif'; color: black;"&gt;Cisco Any Connect Client--------------(No PAloalto at this time ,bu will be here) -------------------------&lt;EM style="font-family: 'Calibri','sans-serif';"&gt;INTERNET------------------------Cisco ASA&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Websense&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 07:54:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-forward-clients-with-paloalto-for-websense/m-p/5997#M4362</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-09-25T07:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: is it possible to forward clients with paloalto for websense ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-forward-clients-with-paloalto-for-websense/m-p/5998#M4363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A Palo Alto Firewall would be able to decrypt the tunnel if it is ssl based and perform URL filtering with our built-in URL filtering, but this cannot be achieved with a 3rd party URL filtering solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We do have a feature called "decryption port mirror" which allows you to export decrypted data which you could get analysed by a 3rd party URL filtering solution, but only for logging purposes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6212"&gt;How to Configure a Decrypt Mirror Port on PAN-OS 6.0&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 08:28:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-forward-clients-with-paloalto-for-websense/m-p/5998#M4363</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2014-09-25T08:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: is it possible to forward clients with paloalto for websense ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-forward-clients-with-paloalto-for-websense/m-p/5999#M4364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks but the thing is we need to forward decrytped data and get back it to PAN to forward.I think this will not be possible as I see.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 13:27:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-forward-clients-with-paloalto-for-websense/m-p/5999#M4364</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-09-25T13:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: is it possible to forward clients with paloalto for websense ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-forward-clients-with-paloalto-for-websense/m-p/6000#M4365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi PAN-OS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This feature is just like SPAN in Cisco world. But you can say its decrypt-SPAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you get the information, but can not take any action on it. So, its not possible to force websense to take any action on decrypted data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 17:29:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-forward-clients-with-paloalto-for-websense/m-p/6000#M4365</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-25T17:29:30Z</dc:date>
    </item>
  </channel>
</rss>

