Resolved! 6.0.5 h3 explanation
Hi allcould someone give an example about 6.0.5 h3 asymmetric bypass.When to enable that ?how that asymmetric trafic works with 6.0.5 but not with 6.0.5-h3 ? That is the thing I'm confused about.
Hi allcould someone give an example about 6.0.5 h3 asymmetric bypass.When to enable that ?how that asymmetric trafic works with 6.0.5 but not with 6.0.5-h3 ? That is the thing I'm confused about.
heydoes anyone have a document that describes "step by step" the commit procedure of the panorama?just had a quick talk with support and apparently the commits from panorama are calculating directly to the running configuration
I have a problem where the user id Agent is reporting the wrong user to an IP. For example, user a is 10.1.1.5 and has id test1Sometimes user b with an id of test 2 shows up with 10.1.1.5 which is not accurate, if I do a show user Ip mapping it shows test 1 is mapped to 10.1.1.5 and test 2 is mapped to a 10.2.2.5.These are example IP's.What is h...
We are seeing a large amount of url logs being categorized as 'not-resolved' at a rate of about 5500 per hour. After reviewing logs to compare it appears it started a few days previous. What is strange is a site will be categorized as 'not-resolved' but a second or two later it is properly categorized. For example: www.napaautopro.com category =...
Seriously? | NSS LabsCould someone elaborate on the section which says:All PAN-OS devices require a configuration change to detect even the most basic TCP stream segmentation evasions. The “Mismatched overlapping TCP segment” protection in the Zone Protection profile is not enabled by default, which allows attackers to bypass the device complete...
Hi.Can anyone provide insight into the threat signature for MS10-049? What it triggers on, etc.? I have seen this triggered by Goggle domain IP sources that produce certificate errors.Thanks,Monica
Hello,I was wondering if anyone could explain the following scenario to me as I seem to have found a bug with NAT policies.On our PA-2050 v5.0.8 I have configure three zones: inside, dmz and outside, and a host in the DMZ. I created two NAT policies, one is static for the spam appliance (MX) and another is a catch-all for other servers in the DM...
Halloi am setting up a new PA 3050 FW. I dont want to use the management port to connect to internet and download updates. So I am following the admin guide to "Set up an External Data Port" for updates. Now as per that:1. I set up a port, say e1/4 on PA 3050, as an internal port in "L3-Trust" Zone and give it a static IP address 192.168.35.100....
Hi,Is there any way to print the PA policies??? i would like to print the window with all policies NAT/security.... Its possible to do it or i would have to use "Print Screen" many times :''( thanks
Hello, Today, when i try to connect PA-500 user interface, after login, PA-500 WEB server shown (as usually) "Creating administrative session. Plase Wait..." for a while, and nothing happen. Chrome Browser shown "Page is not responding".I tried to login with other browsers, from other PCs - not result.I can access the CLI, i restarted web-server...
Hi ,Why do we see url filtering logs although there is no any url profile ?logs related to denied app. like ultrasurf and hot-spot shield
Hi,There is any way in PaloAlto to know the rules which are being overlapped in anothers????? thanks
For those of you with global Palo deployments, here's a paper to get you started on what you should know about employee privacy issues. This issue can be complex in countries outside of the U.S."Next Generation Firewalls and Employee Privacy in the Global Enterprise”http://www.sans.org/reading-room/whitepapers/legal/generation-firewalls-employe...
Has anyone discovered any issues with H3? I have an odd issue and am not sure if it has to do with the layer 4 changes in the hotfix to address the evasion issues.I have upgraded 3 client sites. No issues at 2 of the sites. On the third side, I have an issue. This client has a public web site in a DMZ. The ACL allows it to be directly accessed b...
Hi,GP 2.1.0 is now released with the extended SSO support: With Single Sign-On (SSO), the GlobalProtect agent wraps the user’s Windows login credentials to automatically authenticate and connect to the GlobalProtect portal and gateway. SSO has been enhanced in this release to so that when a third-party credential provider is being used to wrap t...
| Subject | Likes |
|---|---|
| 8 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like |
| User | Likes Count |
|---|---|
| 8 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |

