PAN Agent version with PANOS 4.0.9
Hello,Does anyone know which version of PAN Agent is compatible with PAN OS 4.0.9 ?(3.1.2 or 4.1.x ?)Many thanks.Gildas.
Hello,Does anyone know which version of PAN Agent is compatible with PAN OS 4.0.9 ?(3.1.2 or 4.1.x ?)Many thanks.Gildas.
Hello,We are migrating to a Palo-Alto 4020 cluster from our PIX firewall cluster. I have a question regarding Cisco WAAS and WCCP v2 traffic. The front end router redirects to a Cisco WAE via WCCP services 61 and 62. Both WCCP and the WAE mark the original packet using the TCP options field and also change the packet sequence numbers.My question...
Hello.I have a specific question about certain situation. There is a customer with 2 ISPs, let's call them ISP1 and ISP2. Customer has a single PA device to which both ISPs are connected. Each ISP provides a block of public IP addresses which are routed to the PA device. With PBF we'll make a rule, which sets ISP1 as primary ISP and ISP2 as seco...
Whats the maximum number of UserID agents that can be configured to talk to the firewall ?ie. Will the firewall complain if we have 200+ userID agents configured to talk to it?I know each agent can monitor a maximum of 100 domain controllers.. but how many agents can the firewall monitor?
HiI have 4 interfaces;eth1/1 = sub1 -> 10.10.1.1/24eth1/2 = sub2 -> 10.10.2/1/24eth1/3 = mpls -> 10.10.3/1/24eth1/8 = wan -> x.y.z.wdefault router on all interfacesbut now I need to route all 0.0.0.0/0 traffic from sub1 over the MPLS (10.10.3.10) and 0.0.0.0/0 on sub2 over the wan (x.y.z.w)sub2 still needs access to sub1 and sub2 to ...
Hi,After cloning a rule i had this answer if i try to commit"vsys -> vsys1 constraints failed : Maximum number of virtual systems reached"Does someone knows what it means and what i can do?ThanksFrederic
I am seeing several atempts by the same IP address utilizing t.120 to connect via port 3389 to the various Windows Servers that I have with external IP addresses (and, yes, some are actual Terminal Servers). I would love to be able to configure a threshold of denying this type of activity via the application with an activity threshold similar t...
I have a PA-500 Firewall. I am trying to test some policies, however, when I add and remove users from groups, the Palo Alto isn't picking this up fast enough. Does anyone know the command line to clear out a session from the Palo Alto so it will re-check which group a user is in?Thanks!
Am I going mad, or can anyone else not actually use certificates imported in Panorama and then distributed to end devices?Once I have pushed these to PA's I cannot seem to apply them to 'functions' via the GUI or the CLI.Using the same certificate uploaded directly to the PA, everything is fine.I'm on PAN-OS 4.1.4.Rgds
I think I may have found a bug with PANOS 4.1.1 on PA-5050s where the WebUI will not display new signatures until the user has logged out and logged back in again.I left a browser (Firefox 10) logged in for several days, using it just enough that the session did not time out. During this long session, a content update was installed. However, w...
Trying to set up SSL decryption these are the steps ive done:* Configured SSL decryption rules* Installed certificated on FW* Installed cert on client computer with gpo, (yes it removed my warnings about saftey)But it won't warn the user with the response page even though iv'e enabled it under Device > Response Pages > SSL decryption opt-o...
HI guys I am trying to create a custom App-ID to identify Youtube in the context of facebook, I would like to use this for a possible App QoS.Dependency is youtube from facebook but defining youtube app in the context http-host-header is too complex, so I was thinking of using youtube app as dependency and look for triggers as facebook referrer....
Hi,I'm experiencing a problem for importing configuration file from a cluster Fortinet 310B. After conversion, i try to load the file, and i recieve a message "File pan_conversion_l3.xml is malformed". I have tried to compare with the first configuration file fform the PA4020, I saw ther's no certificat on the top, but I'm not shure, if it's the...
HiWe're about to install the web filter licence for the PA. Our current system is a proxy configuraiton via websense. Now that we're going to use the PA for web filtering is the best practise to create a security rule allowing all internal PCs direct access to the Internet using the common web based ports or is there some other way of making the...
I have been testing the security profile for vulnerability protection. I set the action for all critical threats to block. What should I expect to see on the user computer screen if a site does contain a critical threat recognized by Palo Alto? Should the user see a block page?
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 |

