is it possible to forward clients with paloalto for websense ?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

is it possible to forward clients with paloalto for websense ?

L6 Presenter

Hi all,

There is a topology like below.Clients using Cisco vpn and they are enforced to use some proxies(enforced from Active Directory)

There is a Local Websense but it cannot be used because of that enforcement.

Can Paloalto firewall decrypt that SSL traffic and make websense available to use ?

is that possible ?

Cisco Any Connect Client--------------(No PAloalto at this time ,bu will be here) -------------------------INTERNET------------------------Cisco ASA

                                                    |

                                                    |

                                             Websense



3 REPLIES 3

Cyber Elite
Cyber Elite

Hi

A Palo Alto Firewall would be able to decrypt the tunnel if it is ssl based and perform URL filtering with our built-in URL filtering, but this cannot be achieved with a 3rd party URL filtering solution.

We do have a feature called "decryption port mirror" which allows you to export decrypted data which you could get analysed by a 3rd party URL filtering solution, but only for logging purposes

How to Configure a Decrypt Mirror Port on PAN-OS 6.0

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Thanks but the thing is we need to forward decrytped data and get back it to PAN to forward.I think this will not be possible as I see.

Hi PAN-OS,

This feature is just like SPAN in Cisco world. But you can say its decrypt-SPAN.

So you get the information, but can not take any action on it. So, its not possible to force websense to take any action on decrypted data.

Let me know if this helps.

Regards,

Hardik Shah

  • 2244 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!