<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: does PA supports xForward ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/does-pa-supports-xforward/m-p/624#M483</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi James,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You mentioned the App-ID will work, do you mean we can see which application (e.g. facebook) was using but the source IP is still the proxy server in traffic log? &lt;BR /&gt;How about the user-based QOS, it doesn't work with x-Forwared-for neither, right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In PAN-OS 4.0.x/4.1.x, is the same limitation exist?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Linus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Dec 2011 02:24:34 GMT</pubDate>
    <dc:creator>linuss</dc:creator>
    <dc:date>2011-12-19T02:24:34Z</dc:date>
    <item>
      <title>does PA supports xForward ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-pa-supports-xforward/m-p/619#M478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;am wondering if PA can supports xforward as i need to install PA behind a bluecoat were the users request reaches 1st bluecoat then PA, so is there a way for pa to detect the ip addresses or usernames.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2010 09:40:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-pa-supports-xforward/m-p/619#M478</guid>
      <dc:creator>LCMember4717</dc:creator>
      <dc:date>2010-12-22T09:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: does PA supports xForward ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-pa-supports-xforward/m-p/620#M479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you enable x-forward-for on the proxy, then the PA-Appliance will see the original source.&amp;nbsp; However, this will only be seen in the URL logs and cannot currently be tied to User-ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2010 10:15:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-pa-supports-xforward/m-p/620#M479</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2010-12-22T10:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: does PA supports xForward ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-pa-supports-xforward/m-p/621#M480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what about app-id would it work ? assuming my proxy doing url filter and pa application ana data filter ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2010 10:19:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-pa-supports-xforward/m-p/621#M480</guid>
      <dc:creator>LCMember4717</dc:creator>
      <dc:date>2010-12-22T10:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: does PA supports xForward ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-pa-supports-xforward/m-p/622#M481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, App-ID will work - but you will not see users or the X-Forward-For information in the traffic logs - only the URL logs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2010 10:23:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-pa-supports-xforward/m-p/622#M481</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2010-12-22T10:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: does PA supports xForward ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-pa-supports-xforward/m-p/623#M482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Be aware if you do x-forward-via header you will "publish" your &lt;/P&gt;&lt;P&gt;internal IP-addresses on the internet as the header will not be removed by Palo Alto.&lt;/P&gt;&lt;P&gt;That is as far as I know a new feature in 4.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a much better way to do this!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let Blue Coat do "send-client-ip" and you will see the original source from the client.&lt;/P&gt;&lt;P&gt;You can enable this function in management console (my guess is proxy and general) or in the VPM and forward layer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recommend to use two dedicated L3 interfaces on the Palo Alto for this and put these in its own routing table, just to make 100% sure you do not get any asymmetric routing. So hope you have one "spare" public IP you can use for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you have this also in the local policy of the Blue Coat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http.client.persistence(preserve)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You probably do not need an routing table in Blue Coat either except the default gateway.&lt;/P&gt;&lt;P&gt;Be aware that Blue Coat will do return-to-sender by default, meaning that it will reply to internal macaddress where the packet came from.&lt;/P&gt;&lt;P&gt;So there should be no need for a routing table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards Staffan, Radpoint Sweden.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 09:30:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-pa-supports-xforward/m-p/623#M482</guid>
      <dc:creator>solsen</dc:creator>
      <dc:date>2010-12-23T09:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: does PA supports xForward ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-pa-supports-xforward/m-p/624#M483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi James,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You mentioned the App-ID will work, do you mean we can see which application (e.g. facebook) was using but the source IP is still the proxy server in traffic log? &lt;BR /&gt;How about the user-based QOS, it doesn't work with x-Forwared-for neither, right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In PAN-OS 4.0.x/4.1.x, is the same limitation exist?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Linus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Dec 2011 02:24:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-pa-supports-xforward/m-p/624#M483</guid>
      <dc:creator>linuss</dc:creator>
      <dc:date>2011-12-19T02:24:34Z</dc:date>
    </item>
  </channel>
</rss>

