Resolved! Deny internet access by OS
hi there,is there a possibility to create a rule to deny internet acces by specific os?i want to disconnect a large set windows xp clients from the internet, but allow access fo win7 clients.thank yousascha
hi there,is there a possibility to create a rule to deny internet acces by specific os?i want to disconnect a large set windows xp clients from the internet, but allow access fo win7 clients.thank yousascha
We are in the process of replacing an internet facing Check Point (NokiaIP560) deployment with Palo Alto (PA-2050) running PAN-OS 5.0.9.The current checkpoint deployment has two equal cost default routes to the upstream providers routes. These two next hop IP addresses are the multi-group VRRP IP addresses to achieve outbound load sharing. Bel...
I'm trying to delete an SSL certificate from a Palo Alto cluster I'm setting up via Panorama. It tells me the cert cannot be deleted due to this reason:because of references from:template -> {firewall cluster name} -> config -> devices -> localhost.localdomain -> vsys -> vsys1 -> captive-portal -> server-certificateI rem...
This was a qos configuration example and is no longer accessible, I get: unauthorized "Access to this place or content is restricted. If you think this is a mistake, please contact your administrator or the person who directed you here." Can someone help me gain access to this?
Hello,I am currently on Palo Alto v 6.0.0-b23 and facing an issue with the format of syslog message.if we pass the same malicious file through Palo Alto device, syslog message forwarded by Palo Alto v5.0.6 and v6.0 beta are different. Palo Alto 5.0.6 forwards threat name and ID while Palo Alto 6 beta forward threat ID twice. Log on Palo Alto 6.0...
So I see over on Issue in the syslog message format in Palo Alto 6 beta 1 that PANOS 6.0 is in beta... how do we as customers request to be in PA's beta program? I was totally unaware that PANOS 6.0 was being worked on.
Hello,my customer is worried about Cryptolocker infections in the network - CryptoLocker Ransomware Infections | US-CERT. Do you happen to have any best practices or general tips on how to use PAN tools to detect and prevent Cryptolocker from infecting hosts? Cheers, Tuomo
Hello, We are on PAN-OS 5.0.8 and use PA-5050, PA-5060, PA-200 (test boxes) and PA-3020's. We use the User-ID Agent running on VM servers. I have a couple questions, 1) When the PAN "loads" the group membership from our LDAP instance... we get the users that are part of the AD Groups we have "Group-Mapped"... Which is good and as expect...
I am having trouble finding how I would run a pdf summary report for a specific time period. If you click the summary report and then the date it generates for that day.Am I able to do this for the previous month?Thanks
I want to make a search string with regular expression in Monitor tab --> TrafficLike that ( addr.src in (192.168.*?) ).If I have any miss syntax, please help me.Any document for Regular expression for searching in pan, please show me
Hello Is there way that application-override for icmp base application as ping , traceroute ??I would like to bypass from L7-Engine.Thanks
Hi,We're using GlobalProtect client on many workstations. GP Agent is configured in SSO mode. This work flawlessly on Windows XP, 7, and some Windows 8 Pro PCs and tablets.I just got a brand new Microsoft Surface Pro running Windows 8 Pro 64 bits. For some reason, SSO won't work with this tablet. It looks like credentials are not sent to the GP ...
I'm having a problem with Canon printers communicating with an external IP (Canon site). They are trying to communicate to a particular IP on port 443 (simple, right?) but they aren't contacting the destination. I checked my Palo monitor and didn't see anything wrong but I thought I'd create fresh rules just for these printers. So, I've setup...
Hi all,Having a paloalto with multiple VR and subnet overlapping ( having multiple interfaces / Sub witth same subnet).EX: Int1 - IP: 10.1.1.1/24 - VR1 Int2 - IP: 10.1.1.1/24 - VR2 .....It works but does anybody knoes how: For management services, specify one VR or another. You can choose per IP but not per VR / Interface ? F...
Dear All,Please help me on this issue. The IT Security Audit team has scanned the PaloAlto Firewall PA-2050 and they found this vulnerability:*********************************************************************************************************62565 (1) - TLS CRIME VulnerabilitySynopsis:The remote service has a configuration that may make it ...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

