<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help understand TAP mode in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/help-understand-tap-mode/m-p/220263#M63556</link>
    <description>So, that was a perfect answer I was looking for @ jvalentine. So there isn't any feature to tie multiple decrypt ports in a decryption profile right. So there isn't any feature release to SPAN on the PA devices itself we need to have a network broker or a physical switch to SPAN right.&lt;BR /&gt;Thx</description>
    <pubDate>Mon, 02 Jul 2018 22:25:39 GMT</pubDate>
    <dc:creator>Sanssj</dc:creator>
    <dc:date>2018-07-02T22:25:39Z</dc:date>
    <item>
      <title>Help understand TAP mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-understand-tap-mode/m-p/159245#M52078</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;sorry for a dumb question but I am new to PaloAlto and I would like to understand the TAP mode on a physical PA firewall. We have Cisco Catalyst 6509 switch running in 1 of the offices as a core. PA firewall is used for users' internet traffic and it is directly connected on that switch. We need to find a way to&amp;nbsp;mirror traffic going through inside interface on that PA firewall. Cisco is not recommending running a permanent SPAN port for monitoring (especially egress port), so I am curious if firewall can provide similar capability. In other words, is it possible to mirror inside interface on an extra firewall port? (1 direction is also fine). Is TAP mode exactly that or this is something different?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2017 18:04:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-understand-tap-mode/m-p/159245#M52078</guid>
      <dc:creator>dlavrichev</dc:creator>
      <dc:date>2017-06-02T18:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: Help understand TAP mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-understand-tap-mode/m-p/159253#M52079</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/65046"&gt;@dlavrichev&lt;/a&gt; We typically use TAP mode interfaces during evaluation with customers (SLR - Security Lifecycle Review), which is part of the Palo Alto sales process. By utilizing tap mode interfaces, the firewall can be connected to a core switch’s span port to identify applications running on the network. This option requires no changes to the existing network design. In this mode the firewall cannot block any traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In situations like yours where the core switch either can't handle SPAN / Mirroring or TAP due to performance or any other issues, we typically recommend VWire, where the firewall is placed inline, and the traffic passes right through it, and the appliance is still able to identify applications and threats. Understand VWire as a bump in the wire.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your case, your firewall is already in a L3 deployment, hence, traffic is already going through it without problems, which offsets the necessity of a TAP deployment.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screen Shot 2017-06-02 at 11.24.59 AM.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9513i20328DDC4648800F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2017-06-02 at 11.24.59 AM.png" alt="Screen Shot 2017-06-02 at 11.24.59 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question to you is about what is the actual need for you to have one of the firewall interfaces in TAP mode since your device is already in a L3 mode?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2017 18:28:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-understand-tap-mode/m-p/159253#M52079</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-02T18:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: Help understand TAP mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-understand-tap-mode/m-p/159640#M52148</link>
      <description>&lt;P&gt;in addition to &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36590"&gt;@acc6d0b3610eec313831f7900fdbd235&lt;/a&gt; 's great explanation: TAP mode is a 'promiscuous' sniffer state, used solely to suck in data and alalyze it in an out-of-band kind of fashion (everything is received, nothing is sent out)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is one type of port that does function sort of like a SPAN port, but this is a specialist config used to forward &lt;EM&gt;decrypted&lt;/EM&gt; traffic out. It's called a 'decrypt mirror' and is typically used for extended DLP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 07:45:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-understand-tap-mode/m-p/159640#M52148</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-06-06T07:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: Help understand TAP mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-understand-tap-mode/m-p/220257#M63554</link>
      <description>so &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt; can we able to span decrypted traffic to multiple decrypt mirror ports on the PA devices without the intervention of a physical switch. Or Is the FR ID 1307 is it still under consideration.&lt;BR /&gt;&lt;BR /&gt;-thx</description>
      <pubDate>Mon, 02 Jul 2018 21:43:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-understand-tap-mode/m-p/220257#M63554</guid>
      <dc:creator>Sanssj</dc:creator>
      <dc:date>2018-07-02T21:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: Help understand TAP mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-understand-tap-mode/m-p/220262#M63555</link>
      <description>&lt;P&gt;You may configure one or more decryption mirror ports&lt;/P&gt;&lt;P&gt;You may configure one or more decryption policies&lt;/P&gt;&lt;P&gt;You may configure one or more decryption profiles&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each decryption policy references _one_ decryption profile&lt;/P&gt;&lt;P&gt;Each decryption profile references _one_ decryption mirror port&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is possible to use multiple decryption mirror ports (at the same time) - but each mirror port will only have the decrypted traffic from its associated decryption profile (and subsequently, decrypt policy).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/81/pan-os/pan-os/decryption/configure-decryption-port-mirroring#id48f6bc3a-c03c-414b-8759-126567761692" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/81/pan-os/pan-os/decryption/configure-decryption-port-mirroring#id48f6bc3a-c03c-414b-8759-126567761692&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As of PAN-OS 8.1, you would need to use an intermediary switch if you need to replicate/duplicate all of the decrypted traffic to multiple Ethernet interfaces.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 21:56:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-understand-tap-mode/m-p/220262#M63555</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2018-07-02T21:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: Help understand TAP mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-understand-tap-mode/m-p/220263#M63556</link>
      <description>So, that was a perfect answer I was looking for @ jvalentine. So there isn't any feature to tie multiple decrypt ports in a decryption profile right. So there isn't any feature release to SPAN on the PA devices itself we need to have a network broker or a physical switch to SPAN right.&lt;BR /&gt;Thx</description>
      <pubDate>Mon, 02 Jul 2018 22:25:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-understand-tap-mode/m-p/220263#M63556</guid>
      <dc:creator>Sanssj</dc:creator>
      <dc:date>2018-07-02T22:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: Help understand TAP mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-understand-tap-mode/m-p/220652#M63639</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91991"&gt;@Sanssj&lt;/a&gt;&amp;nbsp;You are correct on both counts.&amp;nbsp; For those two use-cases/requirements, you would need a network packet broker or a physical switch that supports one-to-many port mirroring capabilities.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of course there's always the possibility that this changes in future PAN-OS releases, but this is the case as of PAN-OS 8.1.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 15:58:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-understand-tap-mode/m-p/220652#M63639</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2018-07-05T15:58:36Z</dc:date>
    </item>
  </channel>
</rss>

