GRE- plans to support on PAN
Hi,Are you going to support GRE on PaloAlto in the near future?Thanks,Pawel
Hi,Are you going to support GRE on PaloAlto in the near future?Thanks,Pawel
Hello All,I'm curious about spending public IP pool given by my ISP, if I decide to put PAN-s in front edge perimeter. I have seen that in A/A scenario I need 4 IP's (physical and virtual) for Floating IP scenario, or 3 for ARP load sharing (2 physical and one virtual-shared IP). Am I right or some other way could be used in active/active scena...
Hi,I'm trying to aggregate logs across all dps in the system – right now only 2x NPC.Using the procedure here: https://live.paloaltonetworks.com/docs/DOC-3876, the firewall says "packet-diag.log is aggregated” but where is it? Does that aggregated log encompass all slots? When they try to tail or less dp-log pan_packet_diag.log to view the outpu...
Hello world,I must change a cluster PA2050 by PA5020 (with the same configuration) and this PA are Managed by Panorama. ( all policies objects are created on Panorama but not policies)Somebody know how to make this change? which steps?thanks for your helpRegards
Hi All.I want to know really means that logs of dp-log and mp-log as below. I think that logs would be very useful for troubleshoot when problem occur. please give me that logs info in detail.admin@UQUEST_PANOS40_PA2050> less dp-log brdagent.log dp-monitor.log dp-monitor.log.1 dp-monitor.log.2 dp-monitor.log.3 dp-mon...
We use 802.1X on our network for user authentication and assigning VLANs dynamically. Our edge switches (Brocade) and Aruba Controller are configured to use Aruba ClearPass to authenticate each user. ClearPass uses LDAP (freeIPA) to look up users. ClearPass is currently configured to pass user to IP mappings to the PA via the API. My problem is ...
I have a private subordinate CA signed using sha256. This is my forward decryption certificate. The trust anchor is also sha256.With forward decryption enabled on my PanOS5.0.15 device, the certificates generated by the firewall are signed using sha1, even when the websites real certificate is signed using sha256.The current changes made by Go...
I'm setting up two 7050's in an active/active configuration. What is the best method to handle this with Panorama? Right now I only have one of them in there and it seems like only one of the nodes is getting my config changes even though I have config sync turned on.
I have URL filtering configured that blocks pornography, but if I search in Google for pornography and then click on images, pornographic images are accessible. I know that I can block these in Chrome browser, but how do I block them as a policy via the firewall?
Running Global Protect version 2.1.0-50 on a Macbook Pro with OS X and Yosemite. Connecting to a PA-500 running PANOS 4.1.8.When I finish using my Mac for the day, I put it in Sleep mode so that it starts up again instantly. But if the VPN through Global Protect is active at the time and I forget to Disconnect, it gets locked up and there's no w...
Hi,on URL-filtering how can I allow a single URL (i.e. docs.google.com) and block all the others ? Thanks.
Hi, im checking my logs about AppID behaviour. i realised that in traffic https (withouth SSLdecypt policy configured) the PA is detecting facebook-base in SSL connection but with youtube for example is not detecting the app and it shows SSL. Why in a SSL session the PA detects Facebook and not youtube???? without SSLdecryot policy....thanks
Hello,We have a PA-3020 running 6.0.3. Basically we have iSCSI replication set up between two sites. When I pull up the traffic in the Monitor tab I see the picture below. Even though iSCSI traffic is defined in the Applications section I tried creating another app to identify it but still see the "unknown-tcp" traffic show up. Is there some...
I am curious what the general take of the recent Netflix announcement is with regard to our ability to control the traffic. Announcement here . I have an opinion as to whether it is necessary, but that is another subject altogether.It is clear there is only so much application ID that can occur if the data is encrypted, but can it be combined w...
Hi everybody,does everyone have this situation on your PA-FW on the ports 137, 139 and 445 with country's: CN, US, MY, IN ...We have a lot of outgoing traffic with this situation and find out, that the PaloAlto "User-ID Agent" is the causer.A lot of the external (outside) addresses are in case of "WebBot" - very curiosity.
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

