HTTP response code logging

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

HTTP response code logging

L1 Bithead

So PAN doesn't log HTTP response code, at least I do not seem to find one under URL Filtering logs, and if it doesn't, then how Palo could claim that it is the replacement of proxy?

 

 

3 REPLIES 3

Community Team Member

Hi @rKarki ,

 

Palo Alto NGFW and proxies are similar in that they are both designed to protect the network ... that is where the similarities end.

A proxy and a NGFW are 2 different things.  Don't use a NGFW as a proxy 😉

 

I think the following pages explain the differences and why not to use your NGFW as a proxy.

 

What is a proxy server 

palo-alto-networks-vs-proxy-based-products 

 

Did you check this previous discussion on the same topic ? :

Palo-Alto-firewall-vs-Web-Proxy 

 

Cheers,

-Kiwi.

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Hello Kiwi,

I am pretty sure I did read the comparison docs once before and I should have acknowledged from the start that "PAN is NGFW and a proxy is a proxy". At that time I just thought that I could easily replace proxy with PAN, but after knowing some of it's fact, I figured I was wrong. Every company's requirements are different so do we. Anyway, PAN is a great FW and I am not looking this discussion to go towards NGFW vs Proxy particularly. 

Thanks!

Do anyone in this community care about the the http response code on the PAN URL logs? If you do and getting it today, then can you please let me know how you did it. 

 

I found this workaround and have implemented also but the log is a bit mess. This is about creating vulnerability custom signatures and for sure, it fires up event/logs based on a traffic match. The problem that I am having with this is to create a report based on response and that is for URL (http/s) only. This is even harder from a remote log collector eg. Splunk. 

https://live.paloaltonetworks.com/t5/Community-Skillets/HTTP-Response-Codes/ta-p/314255

 

thanks!

  • 4402 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!