<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best practise For TAP Mode in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/best-practise-for-tap-mode/m-p/190302#M57480</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73785"&gt;@hamza_ineos&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. you will want to set a policy from tap to tap, allow&lt;/P&gt;
&lt;P&gt;This will ensure you allow all the packets to be received and APP-ID and scanning to take place on all the received sessions (if you select drop you will only see discarded packets with no further context)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. decryption will only work for inbound connections since you are not able to insert te firewall into the stream (for inbound connections you can import the server certificate and will know the private key)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. make sure you have all the security profiles enabled (best is to create all new profiles that mimic strict enforcement), and set all the desirable URL categories to 'alert' (as allow does not log). If you have a WildFire License fdon't forget to enable WildFire profiles in the AntiVirus profile&lt;/P&gt;</description>
    <pubDate>Wed, 06 Dec 2017 10:38:00 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-12-06T10:38:00Z</dc:date>
    <item>
      <title>Best practise For TAP Mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practise-for-tap-mode/m-p/190057#M57430</link>
      <description>&lt;P&gt;Hello Brothers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Plz i want make a POC with one of our clients, but i need to know what's th best practise for putting the PaloAlto in TAP mode !!&lt;/P&gt;&lt;P&gt;i mean:&lt;/P&gt;&lt;P&gt;1-what's the rule policy that i must create ?? must enable all security profile ?&lt;/P&gt;&lt;P&gt;2-must make dycryption rule ?&lt;/P&gt;&lt;P&gt;3-Wich elements i must focus on for the best practise and give the best report to the client ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Plz help&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;NB:(technicaly i can deploy PA on TAP mode with no problem)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Thanks&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 11:06:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practise-for-tap-mode/m-p/190057#M57430</guid>
      <dc:creator>hamza_ineos</dc:creator>
      <dc:date>2017-12-05T11:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: Best practise For TAP Mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practise-for-tap-mode/m-p/190302#M57480</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73785"&gt;@hamza_ineos&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. you will want to set a policy from tap to tap, allow&lt;/P&gt;
&lt;P&gt;This will ensure you allow all the packets to be received and APP-ID and scanning to take place on all the received sessions (if you select drop you will only see discarded packets with no further context)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. decryption will only work for inbound connections since you are not able to insert te firewall into the stream (for inbound connections you can import the server certificate and will know the private key)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. make sure you have all the security profiles enabled (best is to create all new profiles that mimic strict enforcement), and set all the desirable URL categories to 'alert' (as allow does not log). If you have a WildFire License fdon't forget to enable WildFire profiles in the AntiVirus profile&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 10:38:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practise-for-tap-mode/m-p/190302#M57480</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-12-06T10:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Best practise For TAP Mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practise-for-tap-mode/m-p/190309#M57481</link>
      <description>&lt;P&gt;thanks for very much brother&lt;/P&gt;&lt;P&gt;ok also i need to know plz, after this POC, what's the very important things that i must looking at and talking about it with client in report side for exemple ??&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 11:12:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practise-for-tap-mode/m-p/190309#M57481</guid>
      <dc:creator>hamza_ineos</dc:creator>
      <dc:date>2017-12-06T11:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: Best practise For TAP Mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practise-for-tap-mode/m-p/190313#M57482</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73785"&gt;@hamza_ineos&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;do you know how to run the Security Lifecycle Review?&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://riskreport.paloaltonetworks.com/SLR" target="_blank" rel="nofollow noopener noreferrer"&gt;https://riskreport.paloaltonetworks.com/SLR&lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This will outline the most notable information found in your logs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may want to reach out to your local sales team for assistance how to 'bring' this information to your customer most efficiently&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 11:55:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practise-for-tap-mode/m-p/190313#M57482</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-12-06T11:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: Best practise For TAP Mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practise-for-tap-mode/m-p/190314#M57483</link>
      <description>&lt;P&gt;ok thanks very much brother &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 11:36:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practise-for-tap-mode/m-p/190314#M57483</guid>
      <dc:creator>hamza_ineos</dc:creator>
      <dc:date>2017-12-06T11:36:40Z</dc:date>
    </item>
  </channel>
</rss>

