- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Hi,I am trying to configure a rule on the PA2050 to allow SKYPE out of the network, and I am seeing a bit of a security hole in the app rule.I have set it up using the document:https://live.paloaltonetworks.com/docs/DOC-1505/controllingskype.pdfI have:From Zone: Trustto Zone: UntrustAddress: <My Workstation>Application: SKYPE, SKYP...
We've just purchased a PA-3020 in order to replace an old ASA 5510. But PAN OS does not support clientless VPN(WEB-VPN).Will PAN OS release clientless VPN near feuture?
Name: Network Time Protocol Daemon crypto-NAK Authentication Bypass VulnerabilityUnique Threat ID: 39734criticalCVE-2015-7871 FIRST RELEASE612 (2016-09-14 UTC)LAST UPDATE612 (2016-09-14 UTC) Anyone else seeing lots of "Threat Alerts" for this signature? Just started seeing these Threat Alerts come in from multiple PA-500's for our orginization ...
Folks. Does anyone know if it's possible to integrate dual-factor authentication (SecureID or similar) into Global protect authentication? Our business is requiring more and more rigid access control for VPN access (among other things), and I need to look into getting some form of 2FA integrated into our VPN sign on in the short to medium term. ...
Which report, and what configuration should I use to get every user/source IP of a user using a specific application? I currently tried "Device Traffic Summary" sorting by "bytes" top 5 grouping by user, but I can only have top 50. So only the "Top 50 users consuming the most bandwidth." If I try ACC and target the application I can get top 50...
We created a new rule for tableau application. There is an existing app-id for Tableau which specifies ports 80/443 but when we tried to test we got a deny. Service worked when we added SSL app-id. Question is if Tableau shows ports 80/443 as standard ports then why would we need to add SSL for it to work.
From ETOpen.yml blockIPs: author: Gregory Roehl (paloaltonetworks.com) development_status: STABLE node_type: miner description: > Raw IPs for the firewall block lists. These come from Spam nets identified by Spamhaus (www.spamhaus.org), Top Attackers listed by DShield (www.dshield.org), Abuse.ch. config: source_name: ET.block_ips attributes...
We are attempting to configure pim sparse mode via the PA-7050 which is going to be used as a control point for various virtual routers on our juniper mx core. From what I can tell the pim is configured correctly, and the proper rp has been selected. multicast routes appear correct, however the traffic is still being dropped. This is the co...
from minemeld-engine log jjust after the update 2016-09-09T06:48:49 (20984)launcher.main INFO: mm-run.py arguments: Namespace(config='/opt/minemeld/local/config', multiprocessing=0, verbose=False)Traceback (most recent call last): File "/opt/minemeld/engine/current/bin/mm-run", line 11, in <module> sys.exit(main()) File "/opt/minemeld/e...
Hi when I upload the netmaps config file, nothing show up under Nat i am not sure what is missing, The second issue i am having, the interfaces i have on the sidwinder have alias IPs attached to each interface (they are secondary IPs), the conversion tool only convert the first IP address of the interface and not the other ones. I appreciate any...
After we provison new ISP link and connect directly to firewall is there way we can do throughput testing from Interface to check we are getting correct speed quoted by ISP , IF I connect ISP link directly to laptop assign IP and do speedtest it works fine.So next point is firewall , so was thinking if there is way we can do this.
Im looking for those with reallife experience from running site-to-site VPN with PA devices both pro (good) and con (bad) stuff that might float up to the surface. How is the reliability, how is the performance, how is the troubleshooting (if any) etc? For example looking at this test http://blog.webernetz.net/2016/07/26/palo-alto-vpn-speedtests...
Hi all, Has anyone tried installing MineMeld on Hyper-V, I know we support Azure but didn't know if it works on Hyper-V? Thanks, Tim
Would it be possible to add a miner for the Red Hat Subscription Manager (RHSM)?They do advice to use domains name as filter rather than IP addresess [1] (mainly because they use Akamai's CDN), but we prefer to have that kind of traffic under control. There is a public CIDR list [2], but as you need an account in the RedHat portal, they provide ...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 |

