This website uses cookies essential to its operation, for analytics, and for personalized content. By continuing to browse this site, you acknowledge the use of cookies. For details on cookie usage on our site, read our Privacy Policy
Many thanks for your reply, Tom. Your question prompted me into looking at our NAT settings and it looks like we are all set. Removing the proxy would only mean that whoever can administer the PA, can see what our users our browsing but this is not of concern for us.
... View more
Hi all, We currently have a setup using a Forcepoint Content Gateway for proxy server with an external facing Palo Alto 850. The main we reason with use the Forcepoint appliance is for: 1. "Anonymous browsing" (no leakage of internal IP spaces) 2. DLP 3. URL Filtering Ideally, I would like to remove this appliance to simplify our setup and I understand that our PAs can easily handle 2. and 3. However, is there way to configure the PA for 1? Or do I still need some an inline proxy for this? Thanks for your time and advice! Gregory
... View more
Hello there, I am in the process of configuring our reconnaissance protection profile and need some advice on best practices for interval and tresholds (events). I have been searching through the docs and can't find recommended settings for the below interval and threshold. - TCP Port Scan - Host Sweep - UDP Port Scan I currently set 2 seconds for interval and 10 events for treshold. Wondering what is the best practice here. Device: PA 850 OS: 8.0.18 Thanks!
... View more