Logging DNS, NTP, etc
I am curious if others are logging DNS, NTP, OCSP, and other lower level protocols being used by their clients. It seems kind of like a waste of electrons to do so.Thanks,Bob
I am curious if others are logging DNS, NTP, OCSP, and other lower level protocols being used by their clients. It seems kind of like a waste of electrons to do so.Thanks,Bob
After turning on the SSL-Decryption, firefox tells me every moring after restart this error "sec_error_reused_issuer_and_serial", after deleleting the whole history and a restart of firefox it works, but that workaround every morning couldn't be the solution.Anybody some suggestions??thx
Hi All,I configure an email profile for alert and report by email from my PAN ( latest OS 5.0.8 )I have a problem with Email Scheduler belowsometime, I only send test email (test manually) once and after that I can not send email any more.I really don't know where I miss configuration, please help if any one have experience
If I want to set an application like linkedin so that user can view it but not do any thing like send emails, endorse people etc make it read only how do I do that?
We use SSL decrypt in our enviroment with a PA-500. In Internet Explorer this works well and the users doesn't get any messages. But with firefox the story is different, for each page they open they need to add an exeption. This is quite frustrating so I really want to fix this. The question is, how can I fix this?
I am working on a PA-200 firewall and get an error within the traffic log. It reports in the application column that it is 'incomplete'. I can't find anything on this error. It appears it would be in the rule settings but not sure.I am using version 4.1.6Any assistance would be appreciated.
Hi I need help blocking gaggle from our network. This is an App where users enter anonymous comments or pics and users in the area can view them. I was able to do Yik Yak since there was an Application in Palo Alto.
HelloWe can read in email "Palo Alto Networks Content Updated" that version 435 give us:New Vulnerability Signatures (4)SeverityIDAttack NameCVE IDVendor IDDefault ActionMinimum PAN-OS Versionlow36421Phishing Webpage Detectionalert4.0.0critical36442Malicious Flash file Detectionalert4.0.0critical36443Apache Structs ClassLoader Manipulation Secur...
I have a PA-500 running PANOS v4.1.10. Is it possible to configure a single destination NAT rule that translates the address for any given /24 subnet on to the equivalent address in the destination /24 address; e.g. Original Packet Dest: 192.168.50.X -> Translated Packet Dest 172.16.29.X
Hi,I am not able to access the management website. The website does not load. When I try to restart the management plane from ssh with a command "debug software restart management-server" I get this error: 2014-05-08 12:08:11.503 +0200 Error: pan_read_full(comm_utils.c:104): srvr: fatal recv error. sock=3 err=Connection reset by peer (131)admin@...
Hi all,We are working on moving some of our servers to AWS and they require 2 VPN redundant tunnels to be configured with our network. Amazon suggested to terminate the VPN on Internet edge router because the VPN redundancy requires BGP. Between the Internet edge router and the Palo Alto firewall, it is unprotected (but it will be on our physica...
How can I tell the PAN device to use a different port for my SMTP Server when I set up an Email Destination Profile? I need to use port 2525.Thanks,Jeff
I'm trying to setup GlobalProtect to terminate in its own VSYS (for administrative purposes), i.e the Portal and Gateway should reside in its own VSYS and not in my external vsys.But I would like to be able to use the same physical interface as the external vsys, is that even possible?I have tried to create a loopback interface with its own exte...
Hello, I have a big network with thousands of systems, I have 3 domains , I want to know and log all access from outside off my network to any inside server that the url is different to *.mydomain.com.If i use url filtering and in block I put * and in permit *.mydomain.com all the outside access to my network are log including all to *.mydom...
I would like to know what is the impact, if any, when configuring a security policy with allow action and associate with a url filtering profile if we use application as any or application set to web-browsing.I understand the url filtering is only applicable to web-browser traffic by default, but i want to understand what is the best thing to do...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

