04-26-2011 02:12 PM
Does anyone know if I can configure a web browser to use the PAN device as the proxy? We used to have an ISA as that proxy but after installing the PAN's (two 500's in HA) the ISA waqs moved to a DMZ and only helps with incoming connections to things like webmail and sharepoint.
04-18-2012 03:28 AM
Any roadmap to add this feature? It is good selling point if End user want to replace their Proxy server originally use as URL filtering device.
Check Point FW can act as Web proxy server in R75.40.
04-18-2012 03:34 AM
Hi using proxies with PAN only masquerades information flows assing through the PAN. We've replaced our websence system (proxy) and are routing directy to the internet through the PAN. This allows us to see and more importantly control all data flows.
Rod
04-18-2012 04:09 AM
I agree...
If you still need a forward-proxy (can be handy for cases where you dont want to have public ip's flowing around in your core and by that be able to setup IDS to sound an alarm if such packet submerges anyway) you should use a device dedicated for this work.
Examples (depending on your needs, demands (assurance and stuff) and walletsize etc):
http://www.squid-cache.org/Support/products.html
http://www.tutus.se/products/farist-firewall.html
Most of the forward-proxies can be setup with keep-source meaning that you can still use user/panagent in your PA device (along with url-categories, av, ssl termination etc) if you setup like:
client <-> forward-proxy <-> PA <-> Internet
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!