We recently place firewall in-lline and now when needing to use http file transfer it takes over 5 min. Before PA's in transparent mode it was a 20sec process. Is there any thing I can check to see why this is now happening? Or something I need to modify? Over scp works fine but we are not looking to use SCP as primary file transfer method.
If you users browse internet then users are client side and internet servers are server side.
DSRI means disable server response inspection.
It means that if you enable this then traffic from unknown internet servers towards you is not checked.
As good as not having Palo in between at all because you have no security.
Here's a learning article on DSRI that you might find usefull.
As the article explains, typically DSRI is used in environments where internal servers are trusted and protected by the firewall. In these cases, content inspection can be configured for only client to server (internet users to internal servers) traffic using the DSRI option.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!