Hi all, Installing a palo on network with VCSExpressway (cisco ToIP) module. After reading other discussion (https://live.paloaltonetworks.com/message/7757#7757, https://live.paloaltonetworks.com/message/12132#12132, , for a "full" compatibility between palo and VCS, we have to create app override for disabling the app L7 PA's analyse (for NAT reason). The Cisco argue is our VCS know perfectly H323 and SIP, more than your fw which is just a FW ... Does anybody have feedback about this archietecture ? what is for you the best practice, disbaling L7 on palo or disabling NAT on VCS ? If you have create App overide please can you explain which rule you have create. Thx for your help V.
... View more