Resolved! PaloAlto firewall is sending system alert
Dear All,PaloAlto firewall is sending system alert saying "PAN-DB url filtering has expired" . But the i am using only "Bright cloud" url filtering license.Please suggest.RegardsSatish
Dear All,PaloAlto firewall is sending system alert saying "PAN-DB url filtering has expired" . But the i am using only "Bright cloud" url filtering license.Please suggest.RegardsSatish
Firewall device has two disk partitions:Partition 1 => 5.0.XPartition 2 => 5.0.Y (current active version)When you install now 6.0.X, it will overwrite 5.0.XSo after reboot Partition 1 will be active. Then you install the next update to 6.1.X, this will overwrite Partition 2.Partition 1 => 6.0.XPartition 2 => 6.1.X (active version aft...
I'm having a heck of a time getting prelogon working for global protect. I have spoke with both Palo Alto support, as well as a vendor that is a Palo Alto partner. Neither were really able to answer my questions.Here is what I have today. Two Palo Alto 3020's. One is on the west coast, and one on the east coast. I have the portal license on...
I have two PA-500's in Active/Active.We do not need to have them in A/A (in hindsight, it was a mistake) because we do not use asynchronous routing or meet the other typical A/A criteria. I think we are paying for that mistake, as you'll read below.When running software 6.0.5 I implemented a site-to-site VPN through which I ran a client-server a...
We have a server that has no body logged into it and all the DNS traffic from that server is showing as a certain user sending the traffic. Is there anyway to exclude this server from User-ID or another way to remove the user from this traffic?
Hi,Is there a way to see Global Protect tunnel statistics in either Panorama or the firewall itself? I'm looking for bytes in, bytes out, packet in, packet out statistics. The statistics are viewable from the client side if you open up the Global Protect agent, but I would like to see them from the Panorama/firewall side if possible.Thank you,...
So, I, like a number of people, converted from Cisco to PAN. We had a consultant in to help with the conversion, and he was assisting with the rule cleanup. However, a) a lot of rules came straight across as it was time-critical, so they are service based, and b) I have trouble wrapping my head around app-based policies. Is there a tool that ...
Is there a way to manually restart daemons and services in the CLI?I have a box with sslvpn configured. The sslvpn suddenly stopped working and the portal page doesn't load. I double checked the config and the traffic logs show the traffic as being allowed and no threat/url logs being matched. I would like to try restarting just the services bef...
Hi there,I generated a CSR with PAN-OS 6.1.3 and submitted it to our Microsoft AD CA with subordinate CA template. After uploading the certificate it shows up under the root CA certificate of our domain. But when commiting the changes I get an "Error: Certificate failed to load: invalid certificate chain" error message. What have I done wrong?Th...
The $misc variable can only be used for Threats?How to register the URL in syslog server?CEF Key Name: requestFull Name: requestURLData Type: stringLength: 1024Meaning: URL or filename for threat logs Palo Alto Networks Value Field: $miscfrom PANOS_6_0_CEF_ConfigurationHow to Forward Custom URL Logs to a Syslog Server
Hi,I have two PAN 500 in HA A/P configuration with PAN OS 6.1.3 and virtual wire configured with link detection failure ANY. I tested link failure detection in way to disconnect one side of Vwire and passive device takes over and became active. After some time approx. less then one minute, non-functional device tries to revert connection, became...
Hello All,I have such situation where considering in which mode to put HA PA configuration. As you can see on drawing, customer consider to put PAN in sandwich of VRRP cluster and vLAG virtual switch. VRRP has one virtual IP and MAC, and all destined packets from host went trough both active links. So far I don't know hashing algorithm of switch...
Has anyone setup Global Protect with LDAP for Child Domain or have a link to a doc on it?Global Protect works perfect for users in the parent domain. Want authenticate users in the child domain.
Hi,We have configured a policy for File blocking in order to ask confirmation before download .doc files.doc file: www.apd.cat/ca/media/2165.docThis is the policyWhen i try to download this .doc file, the browser stuck loading but it shows nothing, the reponse page is not showed and no download is done.I attach the FileBlocking logs where you ca...

