<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISA (TMG) Problem with PA-500 in vwire mode in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/isa-tmg-problem-with-pa-500-in-vwire-mode/m-p/9269#M6784</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;users who are a member of selected group hit rule one. anyone outwith rule one hits rules two (as you would expect)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we seem to have our user group issue solved kal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now the main problem is getting rid of rule two and why the pa-500 is restricting our edge firewall from communicating with the network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 Jan 2012 12:43:49 GMT</pubDate>
    <dc:creator>d_ballam</dc:creator>
    <dc:date>2012-01-26T12:43:49Z</dc:date>
    <item>
      <title>ISA (TMG) Problem with PA-500 in vwire mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isa-tmg-problem-with-pa-500-in-vwire-mode/m-p/9267#M6782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;background:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have a new installation of a PA-500 (running 4.1.2) which sits behind our edge firewall (TMG 2010) in vwire mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;basic setup. the pa-500 external interface connects directly into the edge firewalls internal interface and the pa-500 internal interface connects directly to our production network. our DNS, AD etc are all on this production network. the PA-500 is only doing content filtering for web / applications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have have the following rules (simplified but basically the important parts)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rule #1 allow internal to external for &amp;lt;selected users&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rule#2 allow internal to external for any users&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rule #3 deny from internal to external for any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as you can see rule one is used for selected members on the domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rule 2 &lt;STRONG&gt;shouldnt&lt;/STRONG&gt; be required as this basically lets anyone who isnt a member of the selected group from rule 1 out to the internet anonymously.&lt;/P&gt;&lt;P&gt;and rule 3 is ther as a deny all (which should be there by default)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as you can see rule 2 should be removed BUT the problem is this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we remove rule#2 our TMG firewall loses connectivity with the production network so loses its secure channel with the domain / domain controls. this causes the firewall to stop authenticating users thus the firewall kills all conenctions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you pleae confirm that rule#2 should never be in the pa-500 setup and confirm that in vwire mode the device should not stop non web/application protocols from communicating.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 09:48:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isa-tmg-problem-with-pa-500-in-vwire-mode/m-p/9267#M6782</guid>
      <dc:creator>d_ballam</dc:creator>
      <dc:date>2012-01-26T09:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISA (TMG) Problem with PA-500 in vwire mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isa-tmg-problem-with-pa-500-in-vwire-mode/m-p/9268#M6783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please confirm if "selected users" are hitting rule #1, or are they hitting rule #2.&amp;nbsp; If there a few users from the&amp;nbsp; "selected users" used in rule #1 and are hitting rule #2, then we would need to look how the User-ID agent has been configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Kal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 11:01:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isa-tmg-problem-with-pa-500-in-vwire-mode/m-p/9268#M6783</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2012-01-26T11:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISA (TMG) Problem with PA-500 in vwire mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isa-tmg-problem-with-pa-500-in-vwire-mode/m-p/9269#M6784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;users who are a member of selected group hit rule one. anyone outwith rule one hits rules two (as you would expect)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we seem to have our user group issue solved kal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now the main problem is getting rid of rule two and why the pa-500 is restricting our edge firewall from communicating with the network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 12:43:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isa-tmg-problem-with-pa-500-in-vwire-mode/m-p/9269#M6784</guid>
      <dc:creator>d_ballam</dc:creator>
      <dc:date>2012-01-26T12:43:49Z</dc:date>
    </item>
  </channel>
</rss>

