<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting up Policy to allow all access to a squid proxy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-policy-to-allow-all-access-to-a-squid-proxy/m-p/156993#M51535</link>
    <description>&lt;P&gt;To answer your question "&lt;SPAN&gt;so for example msn-file-transfer allows 1025-65535 ... so now all these ports are allowed to the proxy !!!"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;No it is not the case.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Some applications use wide range of ports so SYN/SYN-ACK/ACK must be permitted through. When real communication starts then Palo can identify if it is really msn-file-transfer or not. If not then session is dropped.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 17 May 2017 03:25:45 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2017-05-17T03:25:45Z</dc:date>
    <item>
      <title>Setting up Policy to allow all access to a squid proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-policy-to-allow-all-access-to-a-squid-proxy/m-p/156592#M51417</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still a beginer with the PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a universal rule that allows from&amp;nbsp;&lt;/P&gt;&lt;P&gt;any zone&amp;nbsp;&lt;/P&gt;&lt;P&gt;my internal ip address&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;to&amp;nbsp;&lt;/P&gt;&lt;P&gt;ip address group that has by proxy addresses in it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For applicaiton I have&amp;nbsp;&lt;/P&gt;&lt;P&gt;http-proxy - this covers a lot of ports&lt;/P&gt;&lt;P&gt;default urls&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from my test &amp;nbsp;box I try&amp;nbsp;&lt;/P&gt;&lt;P&gt;wget -O /dev/null &lt;A href="http://www.smh.com.au" target="_blank"&gt;http://www.smh.com.au&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this works !!!&lt;/P&gt;&lt;P&gt;wget -O /dev/null &lt;A href="http://www.google.com" target="_blank"&gt;http://www.google.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fails, when i look in the traffic logs I see that the PA have identified that the application is google-base.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so I add in google-basic, infact I include a application filter of general-internet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try that it fails.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I then set service to any not application default and now it works&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But doesn't this now mean I can connect to my squid box on any port ????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How am I supposed to configure this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2017 04:54:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-up-policy-to-allow-all-access-to-a-squid-proxy/m-p/156592#M51417</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-05-15T04:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Policy to allow all access to a squid proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-policy-to-allow-all-access-to-a-squid-proxy/m-p/156593#M51418</link>
      <description>&lt;P&gt;Actually even worse than this ....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the standard ports of the other applicaitons are allowed to the proxy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so for example msn-file-transfer allows 1025-65535 ... so now all these ports are allowed to the proxy !!!&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2017 05:17:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-up-policy-to-allow-all-access-to-a-squid-proxy/m-p/156593#M51418</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-05-15T05:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Policy to allow all access to a squid proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-policy-to-allow-all-access-to-a-squid-proxy/m-p/156828#M51487</link>
      <description>&lt;P&gt;For the record, its just me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had to set the service ports as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All working well now&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2017 06:59:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-up-policy-to-allow-all-access-to-a-squid-proxy/m-p/156828#M51487</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-05-16T06:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Policy to allow all access to a squid proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-policy-to-allow-all-access-to-a-squid-proxy/m-p/156993#M51535</link>
      <description>&lt;P&gt;To answer your question "&lt;SPAN&gt;so for example msn-file-transfer allows 1025-65535 ... so now all these ports are allowed to the proxy !!!"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;No it is not the case.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Some applications use wide range of ports so SYN/SYN-ACK/ACK must be permitted through. When real communication starts then Palo can identify if it is really msn-file-transfer or not. If not then session is dropped.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 03:25:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-up-policy-to-allow-all-access-to-a-squid-proxy/m-p/156993#M51535</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-17T03:25:45Z</dc:date>
    </item>
  </channel>
</rss>

