- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-28-2011 03:22 AM
Hi,
Is it possible to set up the Palo Alto to publish internal applications on the SSL vpn protal ? Just like the Juniper SSL devices lets you do ?
Regards,
Sunil
04-28-2011 07:01 AM
No, this is not available. I wish it was as it would be a great addition to the product line.
04-28-2011 07:49 AM
Thanks,
Yes , most customers ask for this ability when they look at the SSL VPN component of the product.
Does anyone know if this feature will be available in the product anytime soon ?
Regards,
Sunil
04-28-2011 08:07 AM
Hi Sunil,
I guess part of the reason to do this was to give a sense of application control. The Palo Alto Networks solution will give full security once you gain access to the SSL VPN and/or GlobalProtect. This is done by user, application, HIP - which is not available on most remote access solutions.
Shortcuts/bookmarks can be pushed to client stations through GPO or done manually by the user.
I think the game has shifted a little and the use cases can be reviewed. A full portal may still make sense in some areas - but worth reviewing the actual requirements.
Thanks
James
04-28-2011 09:29 AM
Hi James,
Thanks for the detailed response. It makes sense from a security perspective becuase of palo's ability to secure and control applications . Most customers who ask for the published services on the SSL portal would like to use clientless SSL that lets you reverse proxy to the published applications on the web browser. This is also useful when you connect using a mobile device like an Iphone or even a device which is not yours , a friends machine or a device on another company network where you cant really install an SSL client, I guess clientless vpns just runs a Java applet on your browser.
The other aspect that comes to mind is the convenience of having the published applications to be clicked , as we go to multiple access devices (some which cant be controlled using GPO) , like mobile devices , tablets and other operating systems it just seems more convenient to have a web interface where all access channels are published. We can still run all the Palo Next generation firewall features of application control , IPS etc across these sessions also.
Just thinking out loud.
Regards,
Sunil
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!