- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-05-2019 03:06 PM
I can't seem to find a clear answer to this, and there may not be one. I have a VPN tunnel between 2 sites, both on PA-820's. Would "disable server response inspection" on the VPN policy on both sides benefit from this? What are the potential downsides if I did do this?
Just another I.T. Guy
11-05-2019 03:31 PM
Hello there
You should probably NOT perform DSRI between the VPN. (do not checkbox the setting)
Either site could have dirty traffic/malware/etc, so it is best to not disable a security setting like that.
You want the FW to scan for all threat potential traffic.
11-05-2019 03:31 PM
Hello there
You should probably NOT perform DSRI between the VPN. (do not checkbox the setting)
Either site could have dirty traffic/malware/etc, so it is best to not disable a security setting like that.
You want the FW to scan for all threat potential traffic.
11-05-2019 03:43 PM
Thanks Steve,
That's pretty much what my conclusion was also, just wanted some verification.
Just another I.T. Guy
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!