bit9 integration
Is it still possible to integrate bit9 with the PA? If so has anyone tried it and is it effective? Other comments pro or con would be appreciated
Is it still possible to integrate bit9 with the PA? If so has anyone tried it and is it effective? Other comments pro or con would be appreciated
Hello all,I am testing out SSL decryption on a few categories. For now I am using a system generated certificate and it works in decrypting the categories I have selected. The problem is that once it is decrypted, it doesn't use the proper security policy. We have AD integration and URL filtering set up between certain groups. My user ID has...
hi,am facing a weird issue my app+threat update did not update since 489-2600, nothing changed connectivity exist i tried manually to download from the gui it worked perfectly, even yesterday update is been missed for some reason.although the logs show it contaced the updates.paloaltonetworks.com with no issue but still not downloaded.any hint o...
Hi!I've got a question about BotNet reports available on Palo Alto firewalls. Maybe someone has an experience on how accurate they are, what logic they are using and how to better tune them to display more precise information?At this point I have all default settings configured. But I have noticed that some of the web sites categorized by Palo A...
Hello support community,I'm using a PAN 3020 A/P cluster on the perimeter running 6.0.9. At all of my remote sites I have a cisco ASA that uses IPSEC tunnels to connect back to the main network. The IPSEC tunnel configuration (IKE phase 1, IKE phase 2, and peer IDs) are consistent across my remote sites (best to my knowledge). Out of my 8 IPS...
Is a KB article out there that explains what each type of config export is and what is included? Looking through our Palo Altos I can see these 6 different config exports...Named Configuration SnapshotCandidate ConfigurationConfiguration VersionDevice State(Panorama)Scheduled Config Export(Panorama)Panorama and Devices Config Bundle
Does the Web GUI use flash or another plugin? I'm able to use it without it enable, but I receive a warning.
I feel silly asking this - wouldn't you want a deny on any decoder where a virus is detected rather than allowing the traffic and just throwing an alert?
Hey there,my colleagues are not able to connect via the HSPA USB Stick "Vodafone Mobile Connect" with our GlobalProtect gateways.I do not see any error-message on the Firewall, only a successful log in but the client disconnect after ~1 second. Also I do not see a useful hint in the log files of the GP-Client.I tried it with a LTE/4G mobile Wifi...
Hi,We have a cluster active/Pasive. We have created a certificate signed by external authority with this config:After creating the certificate we have done a commit and the config failed synchronizing to the passive firewall.¿The certificates pass through HA to the passive firewall or i would have to export this create certificate to the passive...
Hello,I currently have my palo alto setup to use two VSYS ( VSYS1 AND VSYS2) each with its own virtual router.I would like them to use the same interface for outgoing internet traffic which I though I could accomplish with "shared gateways"My problem is:The interface I select to use for the shared gateway configuration does not appear when tryin...
Hi Friends,panos hshah hsharma HULK Steven Puluka panagent Please suggest for the same. i am already check below document and i think, i dont have permission to root access for PAN.https://live.paloaltonetworks.com/docs/DOC-3772https://live.paloaltonetworks.com/message/31894#31894RegardsSatish
There's a ton of fantastic best practices guides on this site in addition to the admin guides. I was wondering if a best practices security configuration benchmark or checklist exists for PA firewalls. Something I can hand an IT auditor, similar to this:http://goo.gl/JgmTTc
Hi, could someone explain if PanOS is able to consider the filed "TCP Window Scale Option (WSopt)" ( http://www.ietf.org/rfc/rfc1323.txt?number=1323). when tcp asymmetric-path is disabled (drop)?I mean that in my experience the firewall drop the packet as "oow - out of window" even if it not should be dropped if we consider "calculated windows ...
Hi,Pls help how to disble CVE ID: CVE-2006-0225 on paloalto firewall.
| Subject | Likes |
|---|---|
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |

