<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PA 500, Hairpin routing and front ending certs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-500-hairpin-routing-and-front-ending-certs/m-p/9531#M6990</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am trying to implement a Exchange 2010 setup and the consultant is asking if the PA can handle HairPin routng and if it can front end the certs for the Exchange systems. I haven't a clue and google results were less than clear,&amp;nbsp; so am turning to the forums and hopeing someone else does. Anyone?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Mar 2012 11:00:48 GMT</pubDate>
    <dc:creator>u7483</dc:creator>
    <dc:date>2012-03-12T11:00:48Z</dc:date>
    <item>
      <title>PA 500, Hairpin routing and front ending certs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-500-hairpin-routing-and-front-ending-certs/m-p/9531#M6990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am trying to implement a Exchange 2010 setup and the consultant is asking if the PA can handle HairPin routng and if it can front end the certs for the Exchange systems. I haven't a clue and google results were less than clear,&amp;nbsp; so am turning to the forums and hopeing someone else does. Anyone?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2012 11:00:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-500-hairpin-routing-and-front-ending-certs/m-p/9531#M6990</guid>
      <dc:creator>u7483</dc:creator>
      <dc:date>2012-03-12T11:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: PA 500, Hairpin routing and front ending certs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-500-hairpin-routing-and-front-ending-certs/m-p/9532#M6991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you can solve that hairpinning with a DNAT rule if you need that (but I would prefer avoiding DNAT if possible).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By front ending certs I assume you mean that the PAN will do the SSL stuff so it is SSL between client and PAN and then just cleartext (or another SSL) between PAN and the Exchange server (so that the PAN can use appid on the traffic to only allow whatever its needed)? And yes PAN can do that (if im not mistaken this was improved in 4.0 or if it was 4.1 to have several certs which you in the decrypt rules choose which to use for which flow).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2012 21:10:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-500-hairpin-routing-and-front-ending-certs/m-p/9532#M6991</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-03-12T21:10:32Z</dc:date>
    </item>
  </channel>
</rss>

