<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: App portal for mobile devices in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/236828#M67863</link>
    <description>&lt;P&gt;Hi Jani&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sounds to me like Palo Alto's Clientless VPN feature (introduced in PANOS-8.0.4) is what you need:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/globalprotect-features/clientless-vpn" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/globalprotect-features/clientless-vpn&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are a few caveats:&lt;/P&gt;&lt;P&gt;1. This is a licensed feature - you need GlobalProtect License for your PAN Firewall. You can request a trial license on the support portal if one was never issued in the past for this Firewall.&lt;/P&gt;&lt;P&gt;2. It's support of web technologies, see this link for what is supported:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-clientless-vpn/supported-technologies" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-clientless-vpn/supported-technologies&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The user browses to Global Protect Portal and the links the user sees are behind the GlobalProtect Portal on the firewall so it is secure when leaving your network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
    <pubDate>Wed, 24 Oct 2018 11:53:26 GMT</pubDate>
    <dc:creator>ShaiW</dc:creator>
    <dc:date>2018-10-24T11:53:26Z</dc:date>
    <item>
      <title>App portal for mobile devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/236809#M67856</link>
      <description>&lt;P&gt;Hi !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was wandering if there is a way to set up some sort of webproxy, so the connections to services behind firewall would be secure (https). We have some services that runs via http an would like to publish them to internet but we would like to make it more secure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One solution would be (if Palo Alto has it) to have a mobile application with a portal (a proxy), where you have some icons of those serivces, let say web services, a webpage for example. When user opens it, the secure connection is established to it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is that one of the vendors for a web service we have, only allows HTTP connection and&amp;nbsp;discourages the opening it to the internet. Thats why we are looking to still use this web service but make it more secure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you and best regards,&lt;/P&gt;&lt;P&gt;Jani&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 09:13:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/236809#M67856</guid>
      <dc:creator>janicerne</dc:creator>
      <dc:date>2018-10-24T09:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: App portal for mobile devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/236826#M67861</link>
      <description>&lt;P&gt;hi Jani&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The PA firewall does not support proxy services, but you can set up GlobalProtect VPN, this allows you to build vpn&amp;nbsp;tunnels into your application servers&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 11:44:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/236826#M67861</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-10-24T11:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: App portal for mobile devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/236827#M67862</link>
      <description>&lt;P&gt;Thank you for your response,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there any way (except for Globa Protect) to secure http connections ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Jani&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 11:46:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/236827#M67862</guid>
      <dc:creator>janicerne</dc:creator>
      <dc:date>2018-10-24T11:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: App portal for mobile devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/236828#M67863</link>
      <description>&lt;P&gt;Hi Jani&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sounds to me like Palo Alto's Clientless VPN feature (introduced in PANOS-8.0.4) is what you need:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/globalprotect-features/clientless-vpn" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/globalprotect-features/clientless-vpn&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are a few caveats:&lt;/P&gt;&lt;P&gt;1. This is a licensed feature - you need GlobalProtect License for your PAN Firewall. You can request a trial license on the support portal if one was never issued in the past for this Firewall.&lt;/P&gt;&lt;P&gt;2. It's support of web technologies, see this link for what is supported:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-clientless-vpn/supported-technologies" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-clientless-vpn/supported-technologies&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The user browses to Global Protect Portal and the links the user sees are behind the GlobalProtect Portal on the firewall so it is secure when leaving your network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 11:53:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/236828#M67863</guid>
      <dc:creator>ShaiW</dc:creator>
      <dc:date>2018-10-24T11:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: App portal for mobile devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/236899#M67879</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36075"&gt;@ShaiW&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That option works to encrypt traffic to the PA; the actual session to the HTTP service however still isn't going to be encrypted.&amp;nbsp;If you wish to secure HTTP, you'll have to setup the service for HTTPS connections.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 18:39:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/236899#M67879</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-10-24T18:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: App portal for mobile devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/236990#M67906</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36075"&gt;@ShaiW&lt;/a&gt;Clientless VPN seems realy good solution for what i was looking for. Thank you for leting me know about the feature !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;As i understand wan connection will be encripted, because of the VPN, that is basically what we need. Or am i missing somethig ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your replies&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 09:29:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/236990#M67906</guid>
      <dc:creator>janicerne</dc:creator>
      <dc:date>2018-10-25T09:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: App portal for mobile devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/237033#M67916</link>
      <description>So to be clear here, the only connection that is encrypted is going to be from the device to your firewall. The actual connection to the http server is still completely in the clear. If that works in your situation then you have a secure way of providing access back to your environment. Make no mistake though, that site is no more secure then it is currently.</description>
      <pubDate>Thu, 25 Oct 2018 12:55:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/237033#M67916</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-10-25T12:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: App portal for mobile devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/238735#M68376</link>
      <description>&lt;P&gt;Thanks for help, i set up the portal and looks promising. I set up a zone for clientless traffic which has only few rules to acces servers to specific port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This should be more secure way to access the servers from outside, but just to the entry point of firewall. Inside traffic is still secure as it was before, not less not more.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you guys !&lt;/P&gt;</description>
      <pubDate>Tue, 06 Nov 2018 11:35:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-portal-for-mobile-devices/m-p/238735#M68376</guid>
      <dc:creator>janicerne</dc:creator>
      <dc:date>2018-11-06T11:35:57Z</dc:date>
    </item>
  </channel>
</rss>

