setting up services to be accessible through the internet
I am wanting to have one of my internal machines be a webserver and be allowed to talk out through the internet.Not sure how to go about doing this.
I am wanting to have one of my internal machines be a webserver and be allowed to talk out through the internet.Not sure how to go about doing this.
Hi,Sorry I know this is an old thread but figured I'd ask here as my issue is the same... I am interested in finding the specific route in the route table that will be used for a specific destination network lookup. So I do "test routing fib-lookup ip 2.2.2.2 virtual-router default" command but the output only shows the interface that will be u...
Hello community,we have running a PA-500 with a captive portal configuration. This config was build up last year on a PAN-OS 3.1.7. We haved used Debian Linux with openssl to generate a key-pair and a CSR. To correctly import the certificate I had to convert the certificates in Base64 format and copy&paste the intermediate certificate on the...
Hello Everyone!Is there any way to treat trafic from an specific Computer in AD ?I need to block internet traffic and allow only internet corporate email (gmail) to some computers (doesnt matter the user logged in there)I can fix thos MACs to the DHCP so they will receive always the same IP and I can treat those traffic... But I would like to kn...
I've seen this a few times and have finally decided to ask.Running Panorama 4.1.6, managing several devices. I switched context to a 2050 running 4.0.12 and created a new zone to be used for a second SSL VPN. The results of the commit show that I didn't "Enable User Identification". Returning to "Edit Zone", I select the check box and hit "OK". ...
Hello, Anyone handling DNS Resolution Failures - user types bad url or site not available? Would appreciate hearing your ideas...ThanksArt
I thought a Config Lock is supposed to disable the "OK" button when making configuration changes. Could someone please confirm that's the case?
Can someone please explain what the CLI "target" command actually does? It says that its for a "management session target". What does that actually mean?
I am trying to create a static destination NAT to enable RDP access on port 3389 for one of my internal servers, but no matter what I try, it just doesn't seem to work. I've read through several KB articles as well as https://live.paloaltonetworks.com/docs/DOC-1517 and I've set everything up as it seems it should be, yet no NAT session is ever ...
Greetings Evereyone,I need some ideas / suggestions / thoughts on:For reference, I just attached a hand drawn network diagram.Just to provide a brief description, I have a network scenario that presently uses HSRP to maintain Active/Passive configuration on the border Cisco FWSMs firewalls. I will be replacing these FWSMs with Palo Altos in HA....
We are planning to set up HA in Active Active mode. The boxes sit in separate locations with Layer 2 network between them. Currently our guest Network site on our second PA-2020 with our LAN on the first. Wer had to put the guest Network on second box as we had an issue where we was filling the arp table. When you run Active Active how does a...
Hi,in what situations should we use user-id agent as Ldap Proxy ? And when we select this function, how agent behaves?
Hi,I've deployed two standalone firewalls...i.e., non-HA. And have been using the interface comment field to document the switch port that interface is connected to. I'm now building an active/passive cluster and noticed that when I sync the configs, the passive firewall gets its interface comments overwritten with the comments from the active...
I am new to the PaloAlto world, and admittedly somewhat overwhelmed at the moment. I am working with the reporting features and not getting even close to the results I expect. Particularly when I run a "User Activity Report", I get a 5 page PDF and all pages read "No Data Available" see attached reportEmpty Report. I figure I am not logging some...
The HA documentation states that one should start with a 'clean slate' when implementing HA. I currently have one PA-500 in production on 4.1.4 and another PA-500 as a cold spare. The production PA-500 has 2 unused traffic ports that can be used for HA. I would like to know what the least disruptive process is to change from cold spare to active...
| User | Likes Count |
|---|---|
| 6 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

