<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto firewall vs Web Proxy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/259705#M73620</link>
    <description>&lt;P&gt;Most of the documents compare pan to a proxy, yes it does proxy, ssl forward etc but it does not cache or rewrite like a proxy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so PAN is a next gen firewall, a proxy is a proxy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for me the proxy has been replace by the PAN for outgoing traffic for the reasons mentioned by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107910"&gt;@jeremy.larsen&lt;/a&gt;&amp;nbsp;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not as much requiremenr for cache as mega gig pipes now replace our old isdn etc...&lt;/P&gt;&lt;P&gt;you cannot check your bus timetabel these days without https and this cannot be cached in proxy world,&amp;nbsp;&lt;/P&gt;&lt;P&gt;plus the additional complication and demands of todays content seems to be ever forcing us closer to a proxy rule of......&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if url=*.* then go direct (vial PAN)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;having said that, our incoming web requests do not touch the PAN, &amp;nbsp;it traverses a non NGFW and is then reverse proxied to our internal web servers.&amp;nbsp;we are in control of code and content and with ssl terminated on the proxy we can cache to reduce overheads on our web servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so.... if you need to proxy, dont use a PAN, it is not a proxy. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 May 2019 06:02:13 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2019-05-03T06:02:13Z</dc:date>
    <item>
      <title>Palo Alto firewall vs Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/259634#M73605</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to understand what references mean when mentioning Palo Alto firewall as a web proxy or any reference to it that way.&lt;/P&gt;&lt;P&gt;I mean, from what I gather, the PA does not cache web requests like a web proxy product would, or rewrite URLs, or have other traditional web proxy type features.&amp;nbsp; Unless I am wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could it be that the term Web Proxy is often misused in certain descriptions or reference when discussing PA devices?&lt;/P&gt;&lt;P&gt;I was looking at this comparison paper, but seems to highlight what Web Proxies don't do in regards to App-ID, which I understand.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/resources/techbriefs/palo-alto-networks-vs-proxy-based-products" target="_blank"&gt;https://www.paloaltonetworks.com/resources/techbriefs/palo-alto-networks-vs-proxy-based-products&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;OMatlock&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 15:13:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/259634#M73605</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2019-05-02T15:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto firewall vs Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/259641#M73606</link>
      <description>&lt;P&gt;What specific features are you looking for?&amp;nbsp; PAN is a "transparent" web proxy.&amp;nbsp; There is no need to point to a proxy in your environment.&amp;nbsp; Personally, I prefer this method as it is much easier to implement without a bunch of special use case exceptions where a traditional proxy doesn't work/isn't supported/causes problems/etc.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 15:25:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/259641#M73606</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-05-02T15:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto firewall vs Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/259676#M73613</link>
      <description>&lt;P&gt;Thank you for responding!&lt;/P&gt;&lt;P&gt;I am not really looking for anything in particular, just trying to understand when I read and see reference to using PA device as a web proxy.&amp;nbsp; When I think of a web proxy device, I think of web caching or web proxy device capturing the request and resending on user's behalf, and or other features that are specific to web proxy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In other words, I've believed there is a clear separate distiction between these two types of products.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you say the PA is a transparent proxy, that is just meant to say that web traffic flows through it as an intermediatary device (as a firewall for app-id scanning, etc, using NAT)?&amp;nbsp; Therefore, when web proxy is used to in reference to PA device, I should understand within that context only (specifically)?&amp;nbsp; Am I correct in this thinking?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just trying to confirm as I get these kinds of questions when evaluating what are necessary in environments...&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 20:25:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/259676#M73613</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2019-05-02T20:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto firewall vs Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/259678#M73614</link>
      <description>&lt;P&gt;I guess that's kind of hard to answer because I don't know what features you are looking for.&amp;nbsp; I couldn't tell you on the top of my head whether or not PA caches requests (I would assume so).&amp;nbsp; Is there a specific feature or use case you are looking for.&amp;nbsp; Perhaps I am just misunderstanding your question.&amp;nbsp; Whether you explicitly forward traffic to a proxy on a predefined port or if it just runs transparently inline shouldn't make that big of a difference.&amp;nbsp; I guess this boils down to your derfinition of "on your behalf".&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 20:43:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/259678#M73614</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-05-02T20:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto firewall vs Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/259705#M73620</link>
      <description>&lt;P&gt;Most of the documents compare pan to a proxy, yes it does proxy, ssl forward etc but it does not cache or rewrite like a proxy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so PAN is a next gen firewall, a proxy is a proxy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for me the proxy has been replace by the PAN for outgoing traffic for the reasons mentioned by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107910"&gt;@jeremy.larsen&lt;/a&gt;&amp;nbsp;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not as much requiremenr for cache as mega gig pipes now replace our old isdn etc...&lt;/P&gt;&lt;P&gt;you cannot check your bus timetabel these days without https and this cannot be cached in proxy world,&amp;nbsp;&lt;/P&gt;&lt;P&gt;plus the additional complication and demands of todays content seems to be ever forcing us closer to a proxy rule of......&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if url=*.* then go direct (vial PAN)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;having said that, our incoming web requests do not touch the PAN, &amp;nbsp;it traverses a non NGFW and is then reverse proxied to our internal web servers.&amp;nbsp;we are in control of code and content and with ssl terminated on the proxy we can cache to reduce overheads on our web servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so.... if you need to proxy, dont use a PAN, it is not a proxy. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2019 06:02:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/259705#M73620</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-05-03T06:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto firewall vs Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/259778#M73635</link>
      <description>&lt;P&gt;Ah!&amp;nbsp; Incoming connections is your use case (I was only describing a client internet bound use case).&amp;nbsp; Yes, in that case, PAN might be inline but then you should be using comething like F5/Netscaler/etc for reverse proxy traffic flow and load balancing.&amp;nbsp; I don't usually refer to those services as a "web proxy".&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 19:01:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/259778#M73635</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-05-09T19:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto firewall vs Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/260448#M73825</link>
      <description>&lt;P&gt;Thank you guys for the feedback.&lt;/P&gt;&lt;P&gt;It's mainly my inexperience with both and learning that is driving these questions.&lt;/P&gt;&lt;P&gt;Very helpful.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 18:43:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/260448#M73825</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2019-05-09T18:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto firewall vs Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/541748#M111022</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&amp;nbsp;solution "PAN is not a proxy" seems technically incorrect considering PAN-OS has very specific settings to configure itself as a proxy.&amp;nbsp; He did not answer the question, rather he just offered an opinion to use a different product. Recommend this "solution" comment for removal.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 19:49:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/541748#M111022</guid>
      <dc:creator>Jonathan_Runyan</dc:creator>
      <dc:date>2023-05-10T19:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto firewall vs Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/541983#M111050</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/288816"&gt;@Jonathan_Runyan&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The reply reflects the PAN-OS versions and the features that were available at the time of writing (early 2019).&lt;/P&gt;
&lt;P&gt;It wasn't until PAN-OS 11.0 that web proxy capabilities were introduced.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For anyone interested to use the web proxy capabilities I recommend checking out the following: &lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-networking-admin/dns/configure-a-web-proxy" target="_blank" rel="noopener"&gt;Configure a web proxy&lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2023 10:38:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-vs-web-proxy/m-p/541983#M111050</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-05-12T10:38:49Z</dc:date>
    </item>
  </channel>
</rss>

