Palo Alto PA-3220 replace Bluecoat Proxy

cancel
Showing results for 
Search instead for 
Did you mean: 

Palo Alto PA-3220 replace Bluecoat Proxy

L0 Member

Hi Guys,

 

Does anyone tried to use PA-3220 model as proxy server? Currently the internet traffic of my company is using bluecoat proxy with pac file (config in windows proxy setting), and the proxy also inline with sourcefire for doing SSL interception, IPS/IDS. I'm investigating can this model replace the bluecoat proxy. 

Can I define the PAC to point to PA-3220 and forward the traffic to next hop?

1 ACCEPTED SOLUTION

Accepted Solutions

Hi @deecheung ,

Unfortunately no, PAN FW cannot be used as explicit proxy. This topic has been discussed couple of times throughout the years, and if I remember correctly someone mentioned that Palo Alto doesn't event consider adding such functionality.

 

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

@deecheung,

The PA-3220 itself can do SSL inspection and IPS/IDS functionality without any need to have it defined on the host as a proxy. I'd recommend really looking at the capabilities and environment as a whole and seeing if you actually still need this setup. 

L0 Member

@BPry Thanks for the reply. Yes, I indeed need to use PAC as per global design since we have couple of proxy and the pac defined on the host is use for routing different website to different proxy. So my question is can this model run as explicit proxy?

Hi @deecheung ,

Unfortunately no, PAN FW cannot be used as explicit proxy. This topic has been discussed couple of times throughout the years, and if I remember correctly someone mentioned that Palo Alto doesn't event consider adding such functionality.

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!