Update 377-1826 breaks youtube-safemode
Just a heads up - it appears that update 377 has broken the detection of youtube-safemode, with everything being detected as youtube-base ; revert to 376-1817 appears to resolve the issue.
Just a heads up - it appears that update 377 has broken the detection of youtube-safemode, with everything being detected as youtube-base ; revert to 376-1817 appears to resolve the issue.
Hello,I have a question about the process "pan_task" of dp-monitor.log, it always shown high cpu usage.Any one can tell me what the mean is ?Thanks.
heyyi tried to troubleshoot some traffic behaviuor, an i created a rull without any security profile and with application overide.when i run those commands to look at the traffic i found this.admin@PA-500> show session all filter destination 147.235.246.154--------------------------------------------------------------------------------ID ...
HiI'm bit confused about dependency ...During commit i have: vsys1: Rule 'XXXXXXXXXXX' application dependency warning: Application 'gmail-base' requires 'imap' be allowed, but 'imap' is denied in Rule 'Scholastycy - deny rest' Application 'gmail-base' requires 'pop3' be allowed, but 'pop3' is denied in Rule 'Scholastycy - deny rest' ...
I am coming from a Checkpoint environment and I am struggling with some of the terminology. I see a number of references in the Getting Started and the Administrator's guides to "Security Policies". To me this implies that I can create a number of policies but it looks like in fact there is only one policy per box and the policy has multiple rul...
Hello,I have problems to identify an AD user whose name contains accented characters:User "SépotF" recognized as "sépotf"Any suggestions?Thanks
HelloI have PA200 without licence for second GP Portal.I did a second gateway because I thought that this should solve my problem.I need to let access to some website to my users but with my IP address. Thease people has accounts on radius server. I did second gateway for them.I have separate IP and SSL certyfiacate for this, separate config (di...
Is it possible in 4.1 to limit the size of icmp replies or strip any payload in order to discourage tunneling via ICMP ?
Hi,I want to install the PA in my ISP net as transparent bridge, I'm looking for a way to configure the machine to get an IP address & then translate it via Radius acounting / diameter protocol to the user info.Do you know how it can be done? How is it installed in other ISP's?Tal
When enabling OCSP and having a self signed certificate for SSL decryption(we push the certificate to all our domain clients)will OCSP check my self signed certificate against the OCSP responder (and fail because it is unknown)?Or will it only check the original destination server certificate (for example that of facebook)?
Hi everybody.I've got a strange problem related to split tunneling in PAN configuration. The situation is:- Portal and Gateway configuration in PAN-2050 with PANOS 4.1.7 (same results with 4.1.6 and 4.1.5).- VPN client Cisco compatible (Windows and Linux, same results)- IP Pool: 192.168.46.0/24- Access routes: 10.0.0.0/8 and 172.16.0.0/12The pro...
I need to confirm what traffic data (specific DNS Request strings inside the packet) is hitting two specific Security rules, so would like to capture just the traffic that is hitting these rules. Is there any way to do this?I have run the Packet Capture (in,out,firewall, and drop), filtered to port 53 (DNS), but have no way of knowing WHICH rule...
When I try to download the latest netconnect install file from the Software Updates web page it downloads without a valid file extension. When I download the file PanVPN-1.3.4 shouldnt it be PanVPN-1.3.4.msi ? I've tried renaming the file...
Hi, i just realised that my two PA (active/passive) have an alert of HA Antivirus Compatibility. I have checked the version in Dynamic Updates and its the same in bot devices. CAn you tell me why this mismatch happens???I attached an screenshot with 2 device and the antivirus version
Facebook is not displaying its page/images properly when SSL Decryption is enabledany ideas why ?*Note: I have a rule allowing ANY destination with ANY application with ANY service, also another rule i tried was with ANY destination with Explicitly allowing all facebook applications on service ANY, and yet it didn't work.My SSL Forward certifica...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

