Management Profile and Security rules
Hi There,I got a question, on non-mgmt interface firewall, I configured a management profile to access SSH and HTTPS do I need to allow the security policy explictly to access firewall ?
Hi There,I got a question, on non-mgmt interface firewall, I configured a management profile to access SSH and HTTPS do I need to allow the security policy explictly to access firewall ?
Hi all! I have this problem: when i check new software updates, clicking "check now" button, this error appears: "Failed to check upgrade info due to generic communication error. Please check network connectivity and try again." Doing a traceroute we see that after the 17th hops the trace stops, all the ping are unsuccesful17 * paloaltonetit-5....
I have an interesting problem. There is a requirement for moblie devices (Throughout the Us and Canda) to access an SFTP Server from the Internet and upload files to it. No other devices are allowed access, from the Internet, to the SFTP server. The mobile devices will not have stat IPs but dynamic ones. The will of course not be part of our Win...
Just wondering if the more vsys you add, how much more CPU utilization or resource utilization will be used? Does the more you add degrade the system at all? I'm looking at a 5060 or a 5560 with at least 7.0 OS. Is there any documentation that states this?
After hearing the news that the Webex extension in Chrome has a serious vulnerability is it possible to block this at the Palo Alto? http://arstechnica.com/security/2017/01/ciscos-webex-chrome-plugin-opens-20-million-users-to-drive-by-attacks/?comments=1 Either through an App policy or even better a threat signature? Thanks
Hi,We have a Splunk Server that sends to your id-agent (on a windows server) the information of guest users.Now on PA We can se [email protected] in the logs, is possbile for us create a rule for all users from acme, without define each user? So a group policy without LDAP group.We want to set in the field "source user", something like *@acme.com.It...
Hey guys, I have such a weird problem. A user has to connect to a samba server. He does it on his mac with cyberduck, Port 999 and ssh. in the monitor, the application is "incomplete", the action is "allow", and session end reason is "aged-out". Currently, the concerning firewall policy to this public server is any app and any service. However, ...
We've added a netflow server profile to 4 sub-interfaces on ae1 that connects ISP. The netflow is then reported to Solarwinds where we have poll and collect netflow from these sub-interfaces. But we are also seeing notifications i Solarwinds that all the other sub-interfaces on ae1 (and an additional link-aggregation ae2) sends unmonitored netfl...
I have two global protect portals one for staff and one for contractors. I regularly have to test both and the only way I have found to do it so far it to change the portal name on the client. Is there anyway to add both portals and toggle between the two like you can to on the cisco vpn client?
IP address (IP: 4.35.21.146) is pushing out a Google update (url:GoogleSoftwareUpdate-1.2.7.43.dmg) but Palo Alto show it as Virus (Virus/OSX.WGeneris.Icwwz)
Any one out there using firemon or algosec to optimize your firewall? I am interested in your opinions whether you like it or not and which one is better or if there are other options
I"ve been seeing on untrust interface count of Packet Routed to Differenet zone increasing.I've been facing issue with browsing for few minutes. When i browse websites it shows "connecting" n browsing will be slow.After 2 minutes browsin will be fine. I'm not able to trace the issue.When i see count on interface of untrust " packet routed to di...
Is it possible to make Global Protect check someone's connection quality and if the quality is better to another portal, then switch to that one seamlessly? Say we have users connected to a portal in Los Angeles and the connection becomes less than acceptable, is it possible to make the GP client automatically connect to our NY portal if it has...
Can high availability be controlled per virtual system?In other words, is it possible to have an active/passive HA pair with 2 virtual systems, where one virtual system has unit 1 active - unit 2 passive and the other virtual system unit 1 passive - unit 2 active ? Albert
I didnt see an issue on the GitHub for this or anything in the discussions.
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

