<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Needed confirmation on firewall Port spanning or port mirroring in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/needed-confirmation-on-firewall-port-spanning-or-port-mirroring/m-p/327288#M83297</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/105432"&gt;@karthikeyanB&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is not possible, you can't span from the firewall to somewhere else&lt;/P&gt;&lt;P&gt;The only thing that comes close is the decryption port mirror, but that applies only to decrypted ssl/tls&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively you can log export syslog which could feed a NAC user-ip mappings&lt;/P&gt;</description>
    <pubDate>Mon, 11 May 2020 05:42:33 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2020-05-11T05:42:33Z</dc:date>
    <item>
      <title>Needed confirmation on firewall Port spanning or port mirroring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/needed-confirmation-on-firewall-port-spanning-or-port-mirroring/m-p/327160#M83272</link>
      <description>&lt;P&gt;Dear Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per the customer requirement we want to perform Port spanning or port mirroring on the firewall interface so we need confirmation whether it is recommended from Palo Alto and if we perform this will there be any impact on the firewall as firewall is in production at data center or is there any alternate method for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Request your immediate help on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthikeyan Balamurugan&lt;/P&gt;</description>
      <pubDate>Sat, 09 May 2020 10:51:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/needed-confirmation-on-firewall-port-spanning-or-port-mirroring/m-p/327160#M83272</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2020-05-09T10:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: Needed confirmation on firewall Port spanning or port mirroring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/needed-confirmation-on-firewall-port-spanning-or-port-mirroring/m-p/327173#M83274</link>
      <description>&lt;P&gt;Customer requirement is SPAN traffic from Palo Alto on temporary basis to perform POC on NAC.&lt;/P&gt;&lt;P&gt;SPAN the traffic as mentioned below, so that a cable will be connected from Palo Alto to the server to get mirrored traffic from router zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Security Zone – Palo Alto (ae1.120)&lt;/P&gt;&lt;P&gt;Destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Security Zone – NAC POC SPAN (To be created and assign to any free Ethernet physical interface(1000Mbps))&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note : Make sure that production traffic is not disturbed.&lt;/P&gt;</description>
      <pubDate>Sat, 09 May 2020 13:37:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/needed-confirmation-on-firewall-port-spanning-or-port-mirroring/m-p/327173#M83274</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2020-05-09T13:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: Needed confirmation on firewall Port spanning or port mirroring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/needed-confirmation-on-firewall-port-spanning-or-port-mirroring/m-p/327288#M83297</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/105432"&gt;@karthikeyanB&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is not possible, you can't span from the firewall to somewhere else&lt;/P&gt;&lt;P&gt;The only thing that comes close is the decryption port mirror, but that applies only to decrypted ssl/tls&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively you can log export syslog which could feed a NAC user-ip mappings&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 05:42:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/needed-confirmation-on-firewall-port-spanning-or-port-mirroring/m-p/327288#M83297</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-05-11T05:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Needed confirmation on firewall Port spanning or port mirroring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/needed-confirmation-on-firewall-port-spanning-or-port-mirroring/m-p/327291#M83300</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp; that firewall doesnt support port spanning in itself but you can go for one alternative which I always prefer.&lt;/P&gt;&lt;P&gt;Span the port of switch which is connected to firewall interface you want to monitor and then connect the mirrored port to your server . It&amp;nbsp; will more or less serve you the same purpose.&lt;/P&gt;&lt;P&gt;Hope it helps ..Cheers !&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 06:01:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/needed-confirmation-on-firewall-port-spanning-or-port-mirroring/m-p/327291#M83300</guid>
      <dc:creator>KunalChopra</dc:creator>
      <dc:date>2020-05-11T06:01:55Z</dc:date>
    </item>
  </channel>
</rss>

