with session offloaded packet will not go through dataplane ?
how will that packet flow ?what does offload processor exacly do ? understanding of itwhy it needs APP-ID completed
how will that packet flow ?what does offload processor exacly do ? understanding of itwhy it needs APP-ID completed
Hi Guys, Any specific Stress Test tools could be used for Palo, looking to generate a hundred thousand flows. Can Kali Linux or any others do this? Cheers,Myky
In our environment, we have eliminated the scourge of people being local administrators on computers, with the exception of administrative accounts assigned to some of the IT personnel. I'm thinking about blocking the DLL, DMG, EXE, MSI, and PE file types for everyone but IT personnel. Are there any caveats or big gotchas related to doing so? ...
All, Does anyone know a way to setup source-based Custom URL Lists containing domains as an alternative to using source-based IP addresses and address groups? I don't think it's possible in any of the current versions of PAN-OS but i am looking at options. For example, if i want to limit inbound SMTP to our edge Exchange server from the Microso...
Hello all, we are running into an issue where we are unable to change static address object groups to dynamic address object groupsWe have an M500 and several PA7050 and the objects are managed under the "shared" device group for all the PA7050's. We have added tags etc. to the address objects and on the panorama they show up with their dynamic...
I'd like to generate a scheduled report of all the GlobalProtect VPN users connected in the last 24 hours. Is this possible to create in Pan OS 7.1?
I want to set email alerts for high severity alerts but want to put some filter for his high serverity also like some keywords.Is it possble to set email alerts only for some keywords in high severity alerts
Hello, I have noticed an IP address which is published by Microsoft and not “mined” by minemeld: 40.112.64.16/28 in Office Identity. I don’t this this IP range in published IPv4 feed (I have imported default configuration published in Live). How do we collect the informations? How can we follow which information has been mined and sent to th...
What is the proper Userid agent version to be used for PAN-OS version 7.1.6?
Some of our networking tools are triggering ZPP actions. Is it possible to whitelist a source so that thresholds in reconnaissance protection are not triggered? Altering the thresholds would make the recon protection basically ineffective.
I have a WSUS server. I have a Site to Site VPN from a PA-3020 at a hosting facility to a Cisco ASA on my corporate network. The PA-3020 is running 7.1.4. When I try to run updates from the servers in the hosting facility, it shows as ms-update in the Traffic Log. The Session End Reason is “tcp-rst-from-server”. I am allowing all traffic on...
I have a firewall with multiple Vsys/VRs. Need to add a static route from one VR to another and I know I can do it via GUI, however I like to use the CLI if possible. So would this command add the static route from one VR pointing to another? set network virtual-router VR-Inside routing-table ip static-route 10.10.10.10/32 nexthop next-vr VR-I...
We're a school and have just started implimenting BYOD for our Students. Along with this is the requirement to Authenticate the users their BYOD devices so we can monitor and filter their web usage. This is easily done with our PA-3050, or so we thought! Our current setup is that our Student BYOD devices are in their own VLAN (known to the PA vi...
Hi, We are testing GProtect 2.3.2 version and its not working fine.Debug GP client shows "WINHTTP CALLBACK_STATUS_FLAG_CERT_CN_INVALID". The certificate is issued with the Common Name clientvpn.xxx.xxx, and this is the address of the portal. If instead of the DNS name of the portal, we put the IP address, the client warns that the CN of the cert...
Hi,İs it possible to protect from ? Regards
| User | Likes Count |
|---|---|
| 5 | |
| 2 | |
| 2 | |
| 1 | |
| 1 |

