GlobalProtect access policies
If I want different GlobalProtect VPN users to have access to different resources, do I need to create separate Gateways and have the GP license?
If I want different GlobalProtect VPN users to have access to different resources, do I need to create separate Gateways and have the GP license?
Question, when we were using the User Identification Agent Version 3.1.2 we could filter out accounts by editing the “ignore_user_list.txt” in the pan agents folder (typically c:\Program Files\Palo Alto Networks\PanAgent). Now we have upgraded to the User-ID Agent Version 4.1.1-7, is there a way to filter out accounts in a txt file and in filte...
When attempting a download of a PAN OS software image, I get the error "Another download is in progress. Please try again later" in the download dialog. How can I find out what download is in progress and potentially stop that so I can get the software image downloaded?
repoHiRecently I was on Next Generation SECURITY Conference 2012 in Poland. I got sample report from CheckPoint 3D security. You can get it from http://downloads.checkpoint.com/dc/download.htm?ID=13521Is it possible to get similar report from PAN (without PANORAMA)? Im interested in content from 1 -15 page of this report.I need to get the same i...
Wondering if the PA2020 can do this. Or do I need to purchase a link balancer from Peplink or another vendor.
Dear Support:I want to know how long will the Standby PA become active ?According to the HA best practice , Running @ PA2020 & 4.1.8the HA statue is normal , all things are matchand the link monitor had setup , interface monitor set to shutdownI ping 8.8.8.8 -t at the internal networkI unplugin one of data interface , and the standby PA bec...
I see there is a way to export policies, is there a similar way to export my objects/addresses? I'm trying to do a little cleanup on my PA4020's and I'd like to send object lists to the people who requested their creation, to see if they are still valid. By the way, it would be VERY helpful if I could add a comment to an object, so I know who ...
Hi All,Trying to configure a pair of PA-200's as an active-passive cluster using "HA lite". Right now both devices are showing active, so it seems the nodes do not see each other as cluster members. I have defined one HA link on both firewalls, ethernet1/2...they are connected together via a cross-over cable and both interfaces are showing UP....
We have a Panorama box, and I thought I would try to push apps and content version 192 out to our PA-2050s that are in an HA pair. We are running PAN OS 3.1.2 on the Panorama server and the PA-2050s. I downloaded the apps package, and began deploying it to the PA-2050s when I got this message:Image uploaded.Installation initiated.content update ...
Hi.I have two 2020's in a HA configuration.On software 4.1.7, when I modified configurations etc, the synchronisation worked just fine - every change was automatically synched to the passive node on commit.Now that I've upgraded to 4.1.8, more than half the time I commit a config change, it does *not* synch to the passive pair, and I have to rem...
This is probably a question more for Palo Alto networks, but I'm not sure where to submit this question, or request a new app-id. I was wondering if an application profile for Veeam Backup and Recovery will ever be created? I am not seeing anything in the applipedia and wondered if there was a plan for this. I might just have to create my own...
I would like to know a way to protect the manager interface because I´m undergoing brute force attack trying to access the “admin” account and I cannot use the permit address IP because I´m over a dynamic IP connection to manager the equipment. Is there a way to block an address after 3 login fail tentative or something like this?Regard
Hi there,I have a random issue occur whereby one or two of my users seem to loose access to their internet privileges. I check on PA and it shows the traffic but no source user, which is what the rule for their internet access is based on. If we reboot their pc then it is fine again, but I just wondered what could be causing this to all of a sud...
We have a number of IPs assigned by our ISP. I have been told that I can set incoming NAT rules for the IP addresses even if they are not "assigned" to the public facing interface. Is that accurate?Thanks,Bob
I have been searching for an application or applications that cover Symantec NetBackup communications. I have not been able to find anything. Anyone running NetBackup (versions 6.x or 7.x) traffic over a PAN firewall? What applications does the PAN identify (or not)?
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like |
| User | Likes Count |
|---|---|
| 7 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

