Change an address to a "shared address"
Is there an easy way to change an address to a shared address for virtuals domains.The only way we found is to clone the address and change every policies where the address is used which is very long !
Is there an easy way to change an address to a shared address for virtuals domains.The only way we found is to clone the address and change every policies where the address is used which is very long !
I have been disabling "server response inspection" by default in all my policies as it is documented in a number of places (including independent group tests) that this improves the overall firewall performance, and I was under the impression that SRI was only useful in certain data-centre environments that do not apply to us.However while testi...
Hi,I could not find a way to block access to sites with invalid (self signed, expired) ssl certifcates. Any Ideas ?PAN OS 4.1.3.rgds Roland
Hi,I'm running the latest firmware from PAN on a PA-500. Not long ago the commit was pretty fast, like 1 minute or so.I haven't done any major changes, but i've noticed the commit has become gradually slower as time passes. Now its really slow!Can someone tell me the reason for this, and a way to fix it?I will get the 5020 box very soon, but i...
Hello all,I recently upgraded to the 4.1 OS from 4.0.1. The firewall settings are fine but for some reason whenever the firewall tries to download any new software like 4.1.1, GlobalProtect, Dynamic Updates it keeps getting the error "Failed due to network failure".I have checked and made sure that the Managment Interface is not being blocked by...
show config candidate can show candidate file, is it possible to create a report for candidate configure output?ThanksSimey
I'm probably overlooking something obvious.. but I can't seem to find a way to generate a login / session report of SSL-VPN users. Can anyone give a brother a hint?
I am having issues with console cable connectivity and scrolling when working in a box. Basically the short of it is, no matter what console program I use, albeit putty; I get about 40 lines shown, and when I go to view more it overwrites the bottom 20 to 30 and only leaves so much up top. Wierd thing on putty is... If you log into the box an...
Hi,We are trying to connect our PAN 2050 OS 4.0.9 to a couple of user-id agent version 4.1.3. The connection is not established and the agent logs reports:Device thread 1 SSL no certificateDevice thread 1 reply ver 5 msg with max ver 5, msg type 6Failed to read message msg header. error -1Device thread 1 SSL shutdownThe PAN "show user userid-age...
We archive old logs off of Panorama for safekeeping, but have a need to re-load some of this data back into a Panorama Appliance for investigation. Has anyone had any experience with doing this, is it even possible to do without going under the hood?
So, interesting thing. We use a PA-500 for our enterprise guest networks. We currently have a couple rules that go like this:1. Allow guest networks to use Skype / Skrype-Probe2. Block guest networks from using Risk 4 and 5 P2P (this catches stuff like Bittorrent, etc.)We just got an email that someone on our guest network is torrenting. L...
Hello,Starting from what appears to be right after pattern update 683-936 was committed - we began receiving a very substantial amount of alerts from multiple internal "victims" for this Trojan. I am still investigating this internally. Has anyone else had a large amount of activity on this signature starting recently? Looking to verify if thi...
Hi everyone, I use PAN-OS 3.1.6, I want to customize url report by filter some website don't show in my customize url report. I try use filter by url and operation is "!=" but it doesn't work. How I do it ?
Hello I try PAN-OS 4.1.3, I use captive portal authentication with Radius/AD. I config user in WiFi zone access to any zone must authentication with captive portal. It work normally. But I try set Proxy server and user in WiFi Zone config Proxy IP into Internet Option. After that the user in WiFi zone can't access to any web becasue of the b...
Hi, I am looking for a way to define a DSCP value as a condition for a rule. I would like to drop traffic that was previously marked before entering the PAN FW. Any ideas?Thanks!
| Subject | Likes |
|---|---|
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like | |
| 1 Like |

