Decrypt traffice
Is there a reason you wouldn't want to decrypt traffic like: Shopping
Is there a reason you wouldn't want to decrypt traffic like: Shopping
It seems that Global Protect will send user authentication request twice per logon.I setup a lab and the backend authentication server is RADIUS Server, and I find there will be two access request per logon.Is it correct? Is there any parameters I can configuration to make it send one authentication request?Regards, Bobby
Hi All,Can we directly upgrade the OS version from 4.0.7 to 4.1.6. Is there no need to install the base version 4.1.0. My plan is to upload only the software version 4.0.8 up to 4.1.6 then install directly to software 4.1.6.Thanks,Jan
I've been able to configure packet captures with single IP src/dst definitions. Is there a way to set up a capture using "any" as a destination or source?Thanks,Tariq
PANOS : v4.1.6Model : PA-500In the isolated LAB, only management port connected on PA-500 and service route operate well via the management port. I make sure the commit is grey after basic configuration (IP/netmask/gateway/DNS/NTP) set, license retrieved and application/threat prevention updated, and dynamic update scheduled, but the commit is...
I was wondering if anyone has created a custom app-id to identify mobile devices to create policies around. For example block all mobile devices getting to the internet, or apply a QoS policy ect. Thanks,
Hi all!I have a problem using LDAP for user/management authentication/authorization. When I try to log in via my domain I get the following in my log (after logging in again with the admin account):Authorization failed for user *\*via Web from *.*.*.* : Invalid user 06/06 12:41:19User '*\*' authenticated. Profile authProfileAdmins in an authenti...
Hi,I have implemented a Palo Alto without Management interface, only an Inside interface/zone and Outside interface/zone. I configured the service route configuration to use Inside IP address for updates, dns... (all service routes). Also I have configured the network routing (all the networks that has to be accessed from Inside IP address.The p...
Hi,We are having problems with cpu load (sometimes reaching 95%) and i was wondering if active/active configuration would help so both nodes could share the load.Thanks
Hi *,I have problems to sync Captive Portal Settings in a Active/Active HA-Setup.I configure the CP on the active primary host as follows : Enable Captive Portal - checked Server Certificate - cp-cert Authenticaation Profile - company-radius Redirect Host - cp.mydomain.com Client certificate Profile - none Mode - Redirec...
Hello, I'm using PAN OS 3.0.5 and doing> debug device-server dump user-group namefollowed b the tab I'm seing very old group that are not anymore in the Filter group member of the pan-agent. It seams that the PAN have cached the olds user/group relation. There is the way to force a clear of the group <-> user relation on the PAN FW ?
I have configure Active/Passive HA between two PA 5050 Firewalls. One is at high(passive) Priority and another is low(Active). I have also configure Preemtion on Active Firewall, meaning if somehow Active PA fail ,the Passive become active ,but when the active comes up again it should come up as active again i.e , it should take the ownership ag...
I would like to block everything in the file-sharing subcategory of the general-internet category. Currently we are allowing this subcategory.I would like to see what the impact of a policy like this would be, so I setup a policy for this subcategory but set it to allow so I can look at the traffic log for everything that triggers on this rule. ...
I had an issue where mgmt server and device srvr both where high in memory usage and commits where not taking place. I issued the following commandsdebug software restart device-serverdebug software restart management-serverwith no change except that the box was taken out of panorama and from the cli. you were unable to get infoshow session inf...
Hello,We use PAN OS 4.1.1 and GlobalProtect 1.1.0, free version of GlobalProtect.We have configured GlobalProtect in OnDemand mode.When the GlobalProtect software starts it connects to the PA and try's to logon with the stored credentials (Username / password), i does this withoud giving a connect command.We do not want this because ervery time ...
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like |
| User | Likes Count |
|---|---|
| 7 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

