VPN Client -> Site IPSEC configuration
Hi,Have you a documentation or a procedure describing how to setup a VPN Client to Site connexion in IPSEC (I am using a P200).RegardsBoris
Hi,Have you a documentation or a procedure describing how to setup a VPN Client to Site connexion in IPSEC (I am using a P200).RegardsBoris
Is there information on Security and NAT "add rule" configuration limitations for the PA-4000 series?
I am interested in adding all of the IPs from a range like x.y.z.40/28 to the external interface of the PAN.The verbiage on the GUI makes it sound as if I need to add each IP individually.Can I add a range as listed above by entering it as x.y.z.40/28 and if so, can I then NAT inbound by individual IPs in the range by referencing the individual...
We are trying to log all URLs without having a URL Filtering licenseFor that we created a custom URL category containing*.**.*.*Seemed to work but when we compared the amount of log entries to the proxy logs we discovered that we only see less than half of the proxy URL logs in the PA URL log.Looking around we noticed that the option "Log Contai...
I'm trying to use the CLI to get a list of SSLVPN logins, but keep getting either "sytnax error at end of input" or "syntax error at AND" errors. what i've attempted so far is variation on:show log system subtype equal sslvpn object equal "Test SSL-VPN"I suspect it's something to do with the object name which has a space it in. I've tried single...
Hi All,I have configured the PaloAlto to email me threatn logs for medium , high and critical alerts, but it seems to email me only medium threat alerts, how do i fix this 😞Please find attached my log forwarding profile.My email profile is configured fine, as i can receive system alert emails etc, but only with threat alerts, all i get is medi...
Whil my NAT rules are working fine I get the feeling I am missing something with net rules. I have an external ip which needs three ports forward to separate internal server: port 7000 goes to port 3389 on 192.168.1.1, port 7001 goes to port 389 on 192.168.1.2, port 7002 goes to 3389 on 192.168.1.3.I have these working with individual NAT rule...
Does anyone else have a multi-site network with asymmetric routing? I'm having some issues getting from site to site.Here's what's going on:We have two datacenters -- one for the eastern US, the other for the western US. Each datacenter has a PA-2020. Our satellite offices use PA-500s, ASA 5505s, and ASA 5520s. There is an IPSec tunnel from ...
HiI have a device with floting IPs, can I add a traffic rule based on the MAC address? Thanks
Hello all.I have a fairly easy deployment - a set of PA500s with internal trusted and external trusted zones. On the inside, they are currently connected to a router hsrp pair and on the outside pointing to another brand FW. I have only a handful of networks inside, so I have static routes pointing to the inside/outside configured in the VR area...
I am trying to provide for some 1-to-1 NAT on our PAN, which I thought we be an easy task. However, my configuration insist on using the interface IP address for outbound connections. Here is my setup.Untrusted Network Interface IP: x.x.x.10/29Trusted Network Interface IP: y.y.y.4/16Mail Server Public IP: x.x.x.12/32Mail Server Private IP: y.y...
Hello,Anyone else experienced any issues when upgrading to version 4.1.5?We have done one upgrade to 4.1.5 and the PA-5020 just goes into a reboot cycle.After doing the initial commit the firewall reboots and the cycle repeats.Doing a factory reset from maintenance did not help.But we tried one more thing.Since this PA-5020 does have an redundan...
Hello All,I have encountered an issue where a downloaded client installed on Internet Explorer called Aspera client for downloading video content experienced an error.It states to check the UDP port and firewall based on code 15.Since this is application based (HTTP), where is the most effective place to allow and create the rule for the client ...
All,Digging around in the various docs I've found I can't seem to find an answer to this question so I'll ask here..I'm curious if there is a limit on the number of AD groups per user that the Agent can handle? I'm worried we might run into some limitation cause our group situation is really out of control with no fix in sight..Thanks!-Steve
I'd like to figure out the meaning of a vulnerability alertlet say that I have an alert like:Severity Name ID Directioncritical Adobe Flash Player Bounds Checking Remote Code Execution Vu...
| Subject | Likes |
|---|---|
| 2 Likes | |
| 2 Likes | |
| 1 Like | |
| 1 Like | |
| 1 Like |

