Resolved! Can Layer 3 interface belongs to multiple vsys?
As title, can 1 single Layer 3 interface belongs to multiple vsys?
As title, can 1 single Layer 3 interface belongs to multiple vsys?
I just deployed a PAN-VM and everything is working except I don't have any traffic logs for some reason but I do have ACC, System and Conguration logs. The only thing I can think that may cause issues is the fact that the box is not licensed yet as I'm just testing it out. Is this why? An unregistered PA-200 logs traffic data though so I find th...
Our 3020 PA got updated with new AV definition this morning. Since then it is marking all Flash as Virus/Win32.generic and dropping it for all users. But we are not getting any complains from end users. We tried some sites with flash content and had no problem playing flash video. It appears the firewall is not really denying it, but logs it as...
Model# of the device: PA-5020 Serial# of the device: 0011C103358 Current PANOS version: 5.0.4 Customer requires information that whether CVE-2015-0310 will have an impact on the PANOS version or not and if yes then is there any patch available?An exploit for CVE-2015-0310 exists in the wild, which is being used in attacks against older version...
Today I switched on the "strict" Spyware anti-spyware policy on my outbound Domain Controller DNS policy - I'm seeing a lot (I mean a lot) of requests blocked for things like advertising networks.Here are 3 DNS queries that were blocked, and they're indicative as I've picked them at random:d.audienceiq.comd.p-td.comp.adsymptotic.comThose flag as...
What is the maximum number of certificates you can install on a box?
HelloI need your help.I look out flow_sfpwq_taildrop counters increase high when I monitor PA.So I wonder what this counter mean.And I also wonder whether this counter influence real traffic or not.Thanks.
Hey folks,I've run into a following issue. We have a Juniper MAG box communicating with a web server and a rule in place allowing this communication (source Juniper, destination any production IP, on any port). I can also see in the traffic log that the communication is accepted. However when I did a packet capture on the FW I saw the following:...
What's the recommendation on the best way to configure a Palo Alto to log URLs visited during regular browsing?We have various categories set to block which are of course logged but I've never quite got my head around the logic of setting something to "alert" when actually I don't want to see it in the URL logs, but I do want it logged - if that...
Has anyone encountered any throughput issues with 6.1.1? I have NOT had any issues until Friday.Installed a PAN200 in vwire mode for a client eval / AVR. Their throughput to the internet was 44mbps before PAN. Through the PAN, it as cut down to 8mbps. Removed PAN and it went back up to 44mbps. With other PAN200s on 6.1.1, I am getting 50+ on the...
We have a new PA-3020 running on version 6 and I'm using our old Windows User-ID agent running on version 5 that are currently operational in our environment. I've configured PA-3020 to connect with the User-ID agent but I'm having an authentication issuePAN-3020> show user user-id-agent state allAgent: ad-agent(vsys: vsys1) Host: 10.2.2.2 (1...
Just a question about Global Protect Gateway License. Currently we're planning to deploy PA-5050 for our Data Center Infrastructure. Is Global Protect Gateway License is a requirement? For what I've understand, this is only a requirement if you're going to use remote access or SSL VPN but since this is only for our internal security and no remot...
I know you can export a report as an XML manually but when you create an Email Scheduled report I don't see any options.Are emailed reports only in PDF or is there an option somewhere to select this?Thanks!
Has anyone seen this issue? We have had this issue for months with no relief and am at my wits end. Forgive me if my frustration comes through......what happens is this:A remote user will login to VPN web page and click the link to download the GP client then..... *poof*! All traffic in every direction stops. ALL the PAN layer 3 interfaces stop ...
Hello,is it necessary to use Numbered Tunnel-IP confuguration when running OSPF over a VPN line?Roman
| Subject | Likes |
|---|---|
| 2 Likes | |
| 2 Likes | |
| 1 Like | |
| 1 Like | |
| 1 Like |
| User | Likes Count |
|---|---|
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 |

