vWire Fails in BGP
Hi,We have a deployment of Palo Alto in vWire mode. But after it was setup, bgp is no longer functioning. I already created an allow all policy but it didn't work as well. Any advise that can help me to make this work?Thanks,Rex
Hi,We have a deployment of Palo Alto in vWire mode. But after it was setup, bgp is no longer functioning. I already created an allow all policy but it didn't work as well. Any advise that can help me to make this work?Thanks,Rex
Hi,symantec announce a worm named java.tomdep,Ref link :http://www.symantec.com/security_response/writeup.jsp?docid=2013-111815-1359-99Can Paloalto with Threat Prevention can stop this threat ? Regards
I was looking at some logs and noticed data displayed in the screenshot below. There are several things highly questionable about the data displayed here:- The Start Time is in 2031, and the receive time is 2013.- Bytes Received is about 2 exabytes (we have a large SAN, but not that large)- Application is listed as web-browsing on UDP port 53Is...
I would like to have further discussion on this it seems that we now have a very broad policy at the top of our blocking list which contradicts the first rule of firewalls.
We have a lab PA2050 that I have tweaked to exactly where I want it to be. We are now trying to add it to a lab Panorama and I would like to populate Panorama with all of the policies and objects from the lab 2050. I exported the running config to an xml and imported it to the Panorama instance and just changed the server information (IP, gatewa...
Im getting tons of failed to get CRL errors in my logs all of the sudden. Im not sure what I did (if anything) to cause this.Ive tried to fix it,I tried to enable "Server CRL"I did a nslookup on crl.verisign.com and I cant see any connections outbound being denied.I cannot fix this.Any sugestions on how to fix this?What is this even for? I was ...
Hi Gents, here is my PA design as active active.to be clear, the server farm is connected to the Core switches, and the Clients are connected to both Agg switches.the PA Configuration is in VWire mode.the question here is, when I create a security policy to allow access clients to access the servers for specific applications on the servers. shou...
When creating security policies would it be better to create a separate policy for inbound and outbound traffic, trusted and untrusted, per user group or one policy to manage both ways to minimize number of policies
Hello to All, I noticed some strange behavior regarding GRE protocol, and try to explain what exactly is strange:Customer has unfortunate GRE VPN tunnel and in one policy "Public_ulaz_GRE" they stated to pass only GRE and NVGRE protocol respectively. (following picture) But, when you filter traffic by mentioned policy, you can see that beside l...
All,I am a PA beginner so bare with me. I am trying to restrict access to only a few servers to several of our GlobalProtect VPN users. I could set these users into groups but how would I restrict access for each group? We have a PA-500 with 5.0.6 OS version. Let me know if any other info is needed.Any help would be appreciated!Thanks,Troy
HelloI'm using CP since over 6 months. It's working quite good.I moved my servers from internet (untrust zone) to my DMZ zone. I realized that traffic between WiFi network and servers in DMZ (using public adreses) is allowed without CP.In WiFi zone I have two networks: WiFi and WiFi_konferencja - traffic between them also should be blocked.I cre...
Hello,i am confused a little bit when i found out that 10.0.0.0-10.255.255.255 is listed in Top 5 Destination country. What actually refers 10.0.0.0-10.255.255.255 in this instance?Regards,
Dear,I was wondering if it was possible to schedule a dynamic update (download&install) from Panorama.I know I can configure dynamic updates from the panorama (templates/device/dynamic updates). But I don't want my devices to download the dynamic updates since they have no internet access; I want the Panorama to download them and push them t...
Anyone know the command to show the actual distribution of current logs on a log collector? Basically, i need the output of "show system logdb-quota" at a collector level. I know how to view my defined % allocations and how view the overall disk space usage. I just need a current view of my current usage by log type, so i can re-allocate more to...
Hi Gents,I have installed Palo Alto 5050 between the users and my Server Farm.the Issue here is that I created a policy that allows access to the file server based on specific applications or ports, but now I want to prevent usersfrom saving mp3, and video files on my server. so I created a files profile that blocks these file types, and assigne...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

