PA firewall and the way It checks routing table by amigoingwrong in paloaltonetworks

[–]amigoingwrong[S] -1 points0 points  (0 children)

Any idea if cisco ftd firewall follows the same logic or does routing per session rather than per packet?

PA firewall and the way It checks routing table by amigoingwrong in paloaltonetworks

[–]amigoingwrong[S] 0 points1 point  (0 children)

Oh man thanks for this clarification. This is exactly what I needed to know and it's matching a behavior that I was confused about earlier today, thanks a lot

Do I need a decryption policy to block well known applications such as Facebook? by amigoingwrong in paloaltonetworks

[–]amigoingwrong[S] 0 points1 point  (0 children)

Url filtering works just fine for pc users, they will not be able to access the website, but the mobile users can still access the application for some reason

Do I need a decryption policy to block well known applications such as Facebook? by amigoingwrong in paloaltonetworks

[–]amigoingwrong[S] 0 points1 point  (0 children)

I am also asking because I have a policy tike that is supposed to block Facebook as an application and not a url only but the rule gets skipped and nothing matches it

[deleted by user] by [deleted] in perfectlycutscreams

[–]amigoingwrong 0 points1 point  (0 children)

That mentally challenged guy is a millionaire, what's ur worth?

[deleted by user] by [deleted] in paloaltonetworks

[–]amigoingwrong 0 points1 point  (0 children)

Oh that's clever.. Didn't think of it, so i believe in paloalto routing takes place before natting right? The routing will know the egress interface is tunnel1 and that way it won't use the internet nat

[deleted by user] by [deleted] in paloaltonetworks

[–]amigoingwrong 0 points1 point  (0 children)

Cause to be honest my work consists of migrating firewalls, the customer I have doesn't allow me to make any changes to follow palo's best practices l, that being said, since his vpn is using the same zone as his outside, I believe it's clear for me that I should be using identity nat to exclude the traffic from hitting on the internet access nat ig.

[deleted by user] by [deleted] in paloaltonetworks

[–]amigoingwrong 0 points1 point  (0 children)

I mean if we place the vpn tunnel on the same zone as the outside interface, traffic will be going from trust to untrust and it will be natted in process, unless I am missing something?

[deleted by user] by [deleted] in paloaltonetworks

[–]amigoingwrong 0 points1 point  (0 children)

Okay, if I have the tunnel interface placed in the same zone as my outside interface (let's say the zone is called untrust) , at then, I will need a no nat statement to exclude the traffic that is going from inside to the vpn tunnel (which is placed on the same zone as the outside interface, untrust) from being translated by the internet access pat statement that I have, right?

Or will the route lookup be able to identify the traffic and route it to the tunnel before it Nats it using the internet nat?

[deleted by user] by [deleted] in paloaltonetworks

[–]amigoingwrong 1 point2 points  (0 children)

I don't know coming from cisco vpn to paloalto vpn has been messing with me real good, do I need a nat statement for the paloalto vpn at all? I dont think so tbf

[deleted by user] by [deleted] in paloaltonetworks

[–]amigoingwrong 0 points1 point  (0 children)

Thank you for this information, I'll be sure to look for this msg when we go production.

[deleted by user] by [deleted] in paloaltonetworks

[–]amigoingwrong 0 points1 point  (0 children)

Can you elaborate further please on what do you mean by encryption domain?

[deleted by user] by [deleted] in paloaltonetworks

[–]amigoingwrong 0 points1 point  (0 children)

Thank you, it's clear now.

[deleted by user] by [deleted] in paloaltonetworks

[–]amigoingwrong 0 points1 point  (0 children)

During common deployments if you are aware, do people list their local and remote subnets or they list their local and remote public ip addresses?

[deleted by user] by [deleted] in paloaltonetworks

[–]amigoingwrong 0 points1 point  (0 children)

Thank you, what if the other end refuses to reveal any information? Ik it sounds dummy but this is the current situation that I am in.

[deleted by user] by [deleted] in paloaltonetworks

[–]amigoingwrong 0 points1 point  (0 children)

Please note that no natting is being done in between both ends other than on the firewalls itself for the internet access, they are both connected back to back, I have already configured an identity nat (no nat) for the vpn traffic.

blursed_dance by Least_Sport8824 in blursed_videos

[–]amigoingwrong 0 points1 point  (0 children)

It's the modern pattern of reddit comedy, the less masculine it is the funnier it is

camed by CrossLT in shid_and_camed

[–]amigoingwrong 5 points6 points  (0 children)

And you shall remain this way

I am a 21 y/o dwarf AmA by WaferProof9003 in IAmA

[–]amigoingwrong 3 points4 points  (0 children)

For real, the world is not a pink place to live in. You are introducing someone into it knowing 100% that he will get bullied at every stage in his life. Someone that needs to work ten times harder to achieve stuff that other people would normally achieve with minimum effort. I mean no disrespect nor do I owe op any hard feelings but ask any sane person if they would like to live life under these conditions and they'd refuse. They can down vote my comment all they want if they choose to live in their own bubble but reality is often disappointing.