<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using AWS Bundle 2 as an Ironport replacement in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/using-aws-bundle-2-as-an-ironport-replacement/m-p/148969#M49702</link>
    <description>&lt;P&gt;I have a Bundle 2 in trail at the moment as a POC. At first glance, the interface is overwhelming, so navigating it is cumbersome at first.&amp;nbsp; What I am trying to accomplish is a viable replacement for Ironport WSA.&amp;nbsp; I have a Bluecoat POC in place and it can replace the Ironport, as well as TMG for Citrix, two of our criteria.&amp;nbsp; My goal is to proof out if the PA-VM can also do this.&amp;nbsp;&amp;nbsp; Another requirement is DLP with Symantec.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what I need to know in order for this to be viable is&lt;/P&gt;&lt;P&gt;User authentication via AD&lt;/P&gt;&lt;P&gt;User group authorization,&amp;nbsp; ability to categorize users for specific access to URL lists, ex: a list for specific sites and nothing else, along with full internet access for other users, all coming from the same IP.&amp;nbsp; This is the Citrix portion of the POC. With Ironport it is all or nothing based on first on. If a first on user has only access to one list, all users afterwards have the same access. I need for each user on the same box to have their AD access, one user in limited group, and another user with full access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Mar 2017 16:53:08 GMT</pubDate>
    <dc:creator>ACD-II</dc:creator>
    <dc:date>2017-03-22T16:53:08Z</dc:date>
    <item>
      <title>Using AWS Bundle 2 as an Ironport replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-aws-bundle-2-as-an-ironport-replacement/m-p/148969#M49702</link>
      <description>&lt;P&gt;I have a Bundle 2 in trail at the moment as a POC. At first glance, the interface is overwhelming, so navigating it is cumbersome at first.&amp;nbsp; What I am trying to accomplish is a viable replacement for Ironport WSA.&amp;nbsp; I have a Bluecoat POC in place and it can replace the Ironport, as well as TMG for Citrix, two of our criteria.&amp;nbsp; My goal is to proof out if the PA-VM can also do this.&amp;nbsp;&amp;nbsp; Another requirement is DLP with Symantec.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what I need to know in order for this to be viable is&lt;/P&gt;&lt;P&gt;User authentication via AD&lt;/P&gt;&lt;P&gt;User group authorization,&amp;nbsp; ability to categorize users for specific access to URL lists, ex: a list for specific sites and nothing else, along with full internet access for other users, all coming from the same IP.&amp;nbsp; This is the Citrix portion of the POC. With Ironport it is all or nothing based on first on. If a first on user has only access to one list, all users afterwards have the same access. I need for each user on the same box to have their AD access, one user in limited group, and another user with full access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 16:53:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-aws-bundle-2-as-an-ironport-replacement/m-p/148969#M49702</guid>
      <dc:creator>ACD-II</dc:creator>
      <dc:date>2017-03-22T16:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: Using AWS Bundle 2 as an Ironport replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-aws-bundle-2-as-an-ironport-replacement/m-p/148976#M49703</link>
      <description>&lt;P&gt;Looks like there is a limit, and it wiped out the rest.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DLP support as mentioned above&lt;/P&gt;&lt;P&gt;I also need authentication exemptions, there is one IP that has strict access to only certian sites, but no users in AD to authenticate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WCCP?&amp;nbsp; Can I forward traffic to it using WCCP from another firewall or router?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any documentation in regards to setting this up provided it is supported would be appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 16:53:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-aws-bundle-2-as-an-ironport-replacement/m-p/148976#M49703</guid>
      <dc:creator>ACD-II</dc:creator>
      <dc:date>2017-03-22T16:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: Using AWS Bundle 2 as an Ironport replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-aws-bundle-2-as-an-ironport-replacement/m-p/149180#M49748</link>
      <description>&lt;P&gt;First keep in mind that PA is a FW, not a proxy. And unlike some other FWs you can't set it up to work as a proxy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However it can replace all the security features of a proxy (URL filtering, AV), it offers more features (IPS), it can be connected to AD (and many other LDAP and/or authentication servers..), it can work in Layer 3 and inline modes....&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 14:47:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-aws-bundle-2-as-an-ironport-replacement/m-p/149180#M49748</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-03-23T14:47:32Z</dc:date>
    </item>
  </channel>
</rss>

