Service settings in a NAT
I ran across this setting this morning- when setting up a NAT rule, you can specify a service or service group. Cool, but is there a reason to do that when a policy is necessary to open a service port?
I ran across this setting this morning- when setting up a NAT rule, you can specify a service or service group. Cool, but is there a reason to do that when a policy is necessary to open a service port?
Hi There, I have installed Minemeld on my Ubuntu Server 14.04.. And the service is up and running.. Wheneve I use the default Username and Password to logon to the console, it gives me an error "Error Checking credentials - gateway timed out".. I have also checked the file opt/minemeld/log/minemeld-web.log for errors ? but could not find ...
My HA is not in sync because I am getting above error message. Are there like basic troublehsooting steps/docs which I can do?
Hello, I am new to this forum so please bear with me. I would like to use debug log feature on my PA VM. I am able to turn the logging on with the following commands:debug dataplane packet-diag set logdebug dataplane packet-diag set log feature flow basic But I am unable to localize the pan_packet_diag.log file to view the logs. dp0-log does not...
Hi, we have GlobalProtect configured using a LDAP group for authentication in the VPN "cn=groupvpnusers,ou=_generic_groups,dc=it,dc=xxxx,dc=local" When we commit this new config using vpn group in Auth profile, the GP authenticacion is working fine but 2-3 hours later it starts to fail and we get this error in all users in this group "failed aut...
I am going through some cleanup of our PAN firewalls. We have 8 sites with active/standby pairs of PAN's. The sites are connected with IPSEC VPN's. The code varies from 6.0.3 to 7.0.4 versions. What's your feeling on the most stable 7.X code as of now? Requirements: 1. I want to get to the newer/later code for encryption enhancements (Suite B ...
Hey there, I was curious if anyone successfully used another VPN client on their IOS or Andriod device that works. I was told that with X-Auth/IP-Sec the Cisco Anyconnect client worked but it appears that the new 4.0 client does not (am I wrong?). If anyone has had any success with another client I would love some input or feedback.Thanks,Matt
Hi, we see a lot of files with extension docm attacking the mailserver via smtp and identified as malicious by wildfire. is there a way to simply block those files via File Blocking profile like we are doing for pe and other file types. The point is that there is no possibility to choose such file type in File Blocking profile. Any other idea? ...
Hi,I need to create a rule to make run Skype enterprise. I don't find an app for skype enterprise so i tried to create a rule with only skype and ms-lync-online but it's deny with the destination port 5061...I don't understand. does someone has an idea about this subject ?Thks,
Hello Folks, I have recently installed a ESM core and console server. I have added a URL re-write rule to allow my traffic to be proxied through this server. The issus is that the web based traffic is rewriting no problem. Its the communication on port 2125 that is being hindered through the reverse proxy. So I tried to specify a different port ...
The following custom application can be created on the Palo Alto Firewall to identify Pokemon-go traffic <application version="7.1.0"> <entry name="pokemon-go"> <default> <port> <member>tcp/443</member> </port> </default> <signature> <entry name="pok...
We are setting up a new printing zone on the PA and have created a rule that allow the following applications , postscript-pdl, hp-jetdirect, lpd, snmp. It allows one page to print to the printer and then it stops. After much testing we added a second rule below the first fule bu the applications are set to any. It allows everything to print no...
One of out departments recently purchased access to an online training site that uses youtube to play some of the videos within the courses. We block all streaming-media on our network as a general rule on our PA 3020. I would like to allow access to the vidoes within the training courses without oppening up the rest of youtube to these users. I...
A few weeks ago I noticed that in our firewall suddenly all the Source User fields are showing blank. This is very strange since it happened without any changes being made to the firewall or the Domain Controller. We populate user IDs using LDAP. All the settings are correct and the LDAP servers (our primary and backup domain controllers) are bo...
Right now we use a standard vwire with 2 physical interfaces. We're about to make some hardware changes that means that the vwire input and output will be from/to the same physical switch. If I have to use 2 interfaces then on that switch I'll just be using two untagged ports from/to the appropriate VLANs on the switch. But do I have to use 2 ph...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

