- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-14-2023 07:50 AM
Downstream of our PAN's, we have our Citrix environment. This environment includes some Netscalers that have a nice feature in that they provide in their SYSLOG, two fields named "ClientIP" and "NATIP". This proves quite useful in that while the ClientIP field geolocates to a local Boston IP address, the NATIP address shows they are coming in from, for example, Spain. While we have rules in our PAN that should prevent these non-US connections, the VPN services apparently use a local proxy that thwarts the PAN's location lookup.
I've searched and can't seem to find if the PAN's can present and utilize something equivalent to the Netscaler's NATIP so as to be able to leverage it in a policy rule or not.
Note: I have the TOR rules setup but these connections are not TOR.
Any ideas?
Thanks!
09-19-2023 02:09 PM
I don't know why a Netscaler can see the real NATIP and a PAN cannot.
Still looking for the answer.
Thanks for kicking this around with me!
09-19-2023 02:16 PM
Hello,
I think this is a real scenario that others are facing as well. I reached out to a SE I know really well and he suggested the following:
https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/networking-features/web-proxy
Not sure of the code version or hardware you are running however.
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!