External Web Proxy

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

External Web Proxy

L3 Networker

Hi.

Have someone working with next hop fwd proxy ? 

I need post firewall solution for additional files types blocks (like Trellix)

 

3 REPLIES 3

Cyber Elite
Cyber Elite

Hello,

Would you mind elaborating on your question?

Regards,

L3 Networker

i am forwarding (BPF) to SkyHigh Web Gateway (on-prem),

SkyHigh Web Gateway has a wonderful solution for identifying (and block) dozens of file-mimes (unlike the short list of Palo Alto file types).

https://success.skyhighsecurity.com/Skyhigh_Secure_Web_Gateway_(On-Prem)/Secure_Web_Gateway_Product_...

 

My plan is to to use Palo Alto (as default gateway) content inspection (TP and WF and all the protection modules), and then forward to SkyHigh (2nd hop)

SkyHigh Proxy is listening on port 9090, and gets the traffic.

Both PA and SkyHigh (and clients) using same SSL certificate.

The issue is that the SkyHigh doesn't like the new SSL re-encryption from Palo Alto (1st hop).

Seems like the SSL content inspection doesn't work when traffic comes not directly from clients (SSL is being handled by Palo Alto as MITM)

 

Ideas?

 

L1 Bithead

To configure an external web proxy on Palo Alto Networks, choose explicit or transparent mode. Explicit requires client setup, while transparent intercepts traffic. 

  • 392 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!