<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting Up MS DirectAccess in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-ms-directaccess/m-p/157025#M51546</link>
    <description>&lt;P&gt;DA does have a public IP. The PA is currently setup as a vwire, so NAT is handled by our Cisco ASA. I have all of the ports enabled correctly on the ASA).&amp;nbsp; As far as the PA, I created application overrides for all of the ports. One thing I noticed and I know this is the default since version 7 ( I believe); the policy for "Inbound Traffic" has application-Default as a service type. Should I change this to any and see if that solves the issue (instead of trying to figure out application overrides)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You mention premit all traffic from the source IP. Is that as in creating a new policy with that source IP and set any as service and allow? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry, still a newbie to PAN.&amp;nbsp; Thanks.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 May 2017 13:42:38 GMT</pubDate>
    <dc:creator>jharlow</dc:creator>
    <dc:date>2017-05-17T13:42:38Z</dc:date>
    <item>
      <title>Setting Up MS DirectAccess</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-ms-directaccess/m-p/156461#M51365</link>
      <description>&lt;P&gt;Trying to configure DireectAccess (Windows Server) to work but I believe it is failing due to the Palo Alto. I created a custom application and application override for the ports needed but still failing. Per a Microsoft Document, "the firewall has to be configured to pass the traffic through transparently. you cannot NAT the traffic".&amp;nbsp; How do I do this?&amp;nbsp; Anyone else experience using DA (more so with DA is behind the PA firewall)?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 18:14:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-up-ms-directaccess/m-p/156461#M51365</guid>
      <dc:creator>jharlow</dc:creator>
      <dc:date>2017-05-12T18:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Up MS DirectAccess</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-ms-directaccess/m-p/156975#M51530</link>
      <description>&lt;P&gt;I have not set up DirectAccess but few ideas.&lt;/P&gt;&lt;P&gt;Do you have dedicated public IP for DA?&lt;/P&gt;&lt;P&gt;If yes then can you set up bi-directional NAT with Service Any.&lt;/P&gt;&lt;P&gt;Permit all traffic from specific source IP you attempt to connect from to this DA IP.&lt;/P&gt;&lt;P&gt;Review logs. What applications do you see in use?&lt;/P&gt;&lt;P&gt;Disable app-overrides temporarily to see how Palo identifies this traffic.&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2017 22:10:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-up-ms-directaccess/m-p/156975#M51530</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-16T22:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Up MS DirectAccess</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-ms-directaccess/m-p/157025#M51546</link>
      <description>&lt;P&gt;DA does have a public IP. The PA is currently setup as a vwire, so NAT is handled by our Cisco ASA. I have all of the ports enabled correctly on the ASA).&amp;nbsp; As far as the PA, I created application overrides for all of the ports. One thing I noticed and I know this is the default since version 7 ( I believe); the policy for "Inbound Traffic" has application-Default as a service type. Should I change this to any and see if that solves the issue (instead of trying to figure out application overrides)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You mention premit all traffic from the source IP. Is that as in creating a new policy with that source IP and set any as service and allow? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry, still a newbie to PAN.&amp;nbsp; Thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 13:42:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-up-ms-directaccess/m-p/157025#M51546</guid>
      <dc:creator>jharlow</dc:creator>
      <dc:date>2017-05-17T13:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Up MS DirectAccess</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-ms-directaccess/m-p/157027#M51547</link>
      <description>&lt;P&gt;Yes if you know public ip of client who tries to communicate then create policy where source zone is wan, source ip is client ip, application is any and service is any.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And share logs what you see Monitor &amp;gt; Traffic.&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 14:32:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-up-ms-directaccess/m-p/157027#M51547</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-17T14:32:50Z</dc:date>
    </item>
  </channel>
</rss>

