<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TRAPS and Reverse Proxy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traps-and-reverse-proxy/m-p/101062#M44374</link>
    <description>&lt;P&gt;Hello Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have recently installed a ESM core and console server. I have added a URL re-write rule to allow my traffic to be proxied through this server. The issus is that the web based traffic is rewriting no problem. Its the communication on port 2125 that is being hindered through the reverse proxy. So I tried to specify a different port on the server installation like 443 so all comunications head through port 443 however the installer just yelled at me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is anyone else attempting to have TRAPS traffic go through a reverse proxy?&lt;/P&gt;&lt;P&gt;The reason I am trying to do URL re-write is because I am limited in the amount of external IP addresses I have left.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this a feasible method? How are we supposed to deploy the agent externally if I don't have any external IP's left?&lt;/P&gt;</description>
    <pubDate>Tue, 02 Aug 2016 13:58:27 GMT</pubDate>
    <dc:creator>Eddie_Brown</dc:creator>
    <dc:date>2016-08-02T13:58:27Z</dc:date>
    <item>
      <title>TRAPS and Reverse Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traps-and-reverse-proxy/m-p/101062#M44374</link>
      <description>&lt;P&gt;Hello Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have recently installed a ESM core and console server. I have added a URL re-write rule to allow my traffic to be proxied through this server. The issus is that the web based traffic is rewriting no problem. Its the communication on port 2125 that is being hindered through the reverse proxy. So I tried to specify a different port on the server installation like 443 so all comunications head through port 443 however the installer just yelled at me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is anyone else attempting to have TRAPS traffic go through a reverse proxy?&lt;/P&gt;&lt;P&gt;The reason I am trying to do URL re-write is because I am limited in the amount of external IP addresses I have left.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this a feasible method? How are we supposed to deploy the agent externally if I don't have any external IP's left?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2016 13:58:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traps-and-reverse-proxy/m-p/101062#M44374</guid>
      <dc:creator>Eddie_Brown</dc:creator>
      <dc:date>2016-08-02T13:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: TRAPS and Reverse Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traps-and-reverse-proxy/m-p/101066#M44376</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45496"&gt;@Eddie_Brown&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;How are we supposed to deploy the agent externally if I don't have any external IP's left?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've got three relatively unused class Bs. &amp;nbsp;I'll sell you come class Cs... 1k a piece. &amp;nbsp;lol&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry I've really got nothing consturctive.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2016 14:30:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traps-and-reverse-proxy/m-p/101066#M44376</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-08-02T14:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: TRAPS and Reverse Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traps-and-reverse-proxy/m-p/101085#M44379</link>
      <description>&lt;P&gt;Hi Eddie,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you not use destination NAT to allow your clients to check in/upload externally? Or preferably you could use an always-on VPN back to your internal network that your clients establish? I'm not sure on the requirement to have the server accessible from outside the network? &amp;nbsp;(maybe I don't have enough traps knowledge) I understand that the traps&amp;nbsp;clients would still function and be protected if they are not connected to the server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2016 16:20:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traps-and-reverse-proxy/m-p/101085#M44379</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-08-02T16:20:24Z</dc:date>
    </item>
  </channel>
</rss>

