Resolved! will an unlicensed Palo Alto pass traffic?
We have a fully configured cold spare racked - unlicensed, no subscriptions. If pressed into service wil it at lease pass traffic until an RMA arrive for instance?
We have a fully configured cold spare racked - unlicensed, no subscriptions. If pressed into service wil it at lease pass traffic until an RMA arrive for instance?
HI all,it.s that any way I could disable the global protect portal pages exposure in public? Could I just manually install the global protect client to the pc and get the ssl VPN feature works?
Has anyone come across this vulnerability? We have several PC's with 7-zip installed for extracted .tar files in windows. Even after we delete 7-zip, we still see these vulnerabilities being flagged by the pan. Has anyone seen this behavior before? Possibly a rootkit or other malware on the pc's?Thanks
hey i am trying to analyse if the PA is under load regarding to the PA specs,the customer is having sometimes disconnects on the network, i can see that the CPU have peaks sometimes but mainly is OKnetcom@PA-IL-ACTIVE(active)> show running resource-monitor hourResource monitoring sampling data (per hour):CPU load (%) during last 24 hours:core...
Hello,first I try to give you some information. Our headquarter is located in Germany. All of our subsidiaries are connected to Germany via relatively slow VPN lines. Overall we have round about 20 DCs in different countires. Until now we have only 3 Palo Alto firewalls (Germany, USA, Canada) but in the future we plan to buy more.Our setup until...
Hi,Can someone give a competitive explanation for that ? Portal for once, GW for every year.But why both ?Vendor updates make sense for GW subs., what extra portal makes ?Regards.
Hi Friends,I wanted your help in solving this persiting issue.I have a PA4020 in HA mode which is configured in Active-Passive mode. From last few days i am getting the below errorSYSTEM ALERT : high : HA Group 1: Anti-Virus version does not matchSYSTEM ALERT : high : HA Group 1: URL Database version does not matchthe extracts of the logs is att...
I have a free 6in4 tunnel from Hurricane Electric. The tunnel profile inucludes IPv6 Tunnel Endpoints, Routed IPv6 Prefixes and Anycasted IPv6 Caching Nameserver. I used these information to configure a Juniper SSG firewall and it works. I was told by Technical Support Engineer that PA does support 6in4 and it is termed as NAT64. However it need...
Hello, have a PAN-5050 running 4.1.13, where I am trying to debug flow on. Followed the steps necessary to turn on flow debugging but I am not seeing anything log to either of the dataplane pan_packet logs files. I've confirmed the settings are in place on both data planes but nothing is logged. Anyone know of any issues with flow debugging on...
Hi,In my office environment, we have an internal certificate that we have been using prior to installing PAN device. Lately after installing PAN, our office staff are always getting certificate warnings whenever they visit a SSL enabled website. I read in the PAN documents that a self-signed certificate generated by PAN firewall will eliminate t...
Hi All,I see in Release Note application update in Dynamic Updates or email like this :There is a maximum PAN-OS version in Conficker.Why some threat have limitation in PAN-OS ?Please advice.Thanks.Regards,MG
Hi.I saw PAN-OS 5.0 Administorator Guide.P37 bellow------Revert to last saved config Restores the last saved candidate configuration from flash memory. The currentcandidate configuration is overwritten. An error occurs if the candidateconfiguration has not been saved.------I recognized it as config being saved at a hard disk.Actually is config s...
Is it possible to ignore tcp control flags in the Palo Alto?I have a client where several nodes talk back to a server through the PAN. The nodes will send a FIN packet so the PAN will drop the session.. however, the vendor requires the session to stay up. In the ASA world, there is an option to -ignore control flags-.
Is anyone else having issues with PA not recognizing gotoassist very well ?Citrix documentation expects you to open tons of DNS addresses and/or IP ranges, but I'm a bit wary of opening ALL traffic on ports 80 and 443 to these (most IP ranges are on Amazon btw) since we're heavily relying on application identification.
Hi,We are working on custom response pages for all our devices but wanted to know if it was possible to deliver then using HTTP instead of HTTPS as the default ones currelty come via HTTPS and users have to accept the invalid certificate. We have valid certificates on the devices for management but are using transparent interception not re-direc...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 |

