System and Configuration logs are missing
I'm not sure what happened, but the System and Configuration logs are not showing up under Monitor>Logs. Do I need to (re)enable it somewhere?
I'm not sure what happened, but the System and Configuration logs are not showing up under Monitor>Logs. Do I need to (re)enable it somewhere?
I've been getting a lot of traffic from 'unfriendly' countries trying to gain access to a service we provide via one of our NAT'ed public ip address. I know for a fact they have no business connecting to that service. Is there a setting on the Palo Alto to hide my Public ip addresses? In that same vain, can I also hide what ports/protocols I hav...
Hello guysWe have a few VPN tunnels between our PA-2050 (in HA cluster) and some WatchGuard firewalls (different models). We migrated these tunnels to the PA-2050 a few weeks ago and they ran stable. Now suddenly two of 10 tunnels are down and we don't get them back up. Here's what we tried so far:- Rebooting the WatchGuard firewalls- Suspending...
Had a question about internal routing.We have eth port assigned to a trust network which is a 192.168 network. We also have a Avaya VoIP PBX that is vLan'd on this network and the routing is managed on an internal core switch to access this network. In our single virtual router I have a route for the 192.168.0.00/16 with next hop to the Gatewa...
I have configure a 2050 in a vwire configuration can I still utilize layer3 on the device. From what I have been reading if I configure PAN device for vwire then the device cannot due any layer3 funcationality.
Last i heard it was going to be released end of June...
The other day we discovered that our SMTP server was unable to send email to the silvacom.com domain.The problem was traced to our PAN rule which allows only SMTP traffic to eminate from our email server, on the application-default port. All attempts to deliver email to this domain, however, were being seen by the PAN as FTP traffic on TCP port ...
Hi,my questions deals with the application detection. As far as I know the heuristic engine is the last possibility after application signature and decoders weren't successful.But does anybody know how much traffic (bytes or packets) will/can run through a PAN before the heuristic engine gives and the application is set to "unknown"?Many thanks,...
Hello,So I have tested SSL decryption today, and I made it work. But for some reason some of the webpages that are being decrypted are extremely slow. Facebook and even support.paloaltonetworks.com are two of them.I exported a CA certificate from our AD and imported it into the PA as described in a document I found on the knowledgebase.Look at t...
Hi,I have a few questions about how the user-id works that I have been unable to solve.We are currently rolling out a lot of virtual systems to our customers in a MSSP environment and as you can imagine coming across some strange server setups. This has resulted in some strange behaviour with user-id setups.I am trying to work out how user-id b...
In browsing through the default actions for vulnerabilities, spyware and AV I see that the a lot of the actions for HIGH and CRITICAL severity events is just Alert. I expected a lot more blocking, dropping, and resetting. (half of High and >10% of Critical Vulnerabilities and the vast majority of High and Critical anti-spyware are Alert on...
HiI have a simple L3 setup.E1/1 connected to a router (default gateway to the internet). IP 192.168.119.2, untagged Zone VLAN1E1/2.2 connected to a switch (VLAN 2 tagged). IP 10.2.2.1 (default gateway for the 10.2.2.0/24 network), Zone VLAN2I have a default allow all rule, no nat (VLAN2 to VLAN1)A ping from 10.2.2.51 to 8.8.8.8 doesn't work, so ...
HiI have a host which I can access without password with ssh by public key.This works fine, but as soon as the traffic goes over a PAN (500), I get asked for the password.Is the PA500 doing anything special here that I'm not aware of?Thanks
Is there a way to disable SSL renegotiation at firewall level ?Disabling it server side ( Microsoft Security Advisory: Vulnerability in TLS/SSL could allow spoofing ) breaks activeSync. I'd like to test a different scenario to get rid of the many false positives we get for the SSL Renegotiation Denial of Service Vulnerability.
Hello All,Maybe it's there, in a doc, but I cannot find it...Suppose I have tiered architecture.And suppose developer breaks his code and want's to connect to other security zone or to the outside world buth should not, and I want his application to know it immidiatelly by getting tcp reset.Right now I catch myself debugging for several hours ro...
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like |
| User | Likes Count |
|---|---|
| 7 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

