need to forward log to Panorama and do not save logs on Pan
For some reasons, I need to manage all logs using Panorama and the logs can not save on Pan. How can I do to config ? Or the request againsts Pan policy.
For some reasons, I need to manage all logs using Panorama and the logs can not save on Pan. How can I do to config ? Or the request againsts Pan policy.
Hi,I need capture some traffic for a specific subnet ( or vlan tag) .With "debug dataplane packet-diag set filter match" I can only put a single ip's but not subnet. Neither a vlan-tag can be added in a filter.Is there any way to do this ?Tx.
Hi all,We would like to deploy 2 PAs on two different sites in an Active/active design. The two sites are 10ms far away from each other.So the first question is : Is 10ms (RTT) acceptable from a PanOS perspective to enable the HA feature ?The IP plan is not the same on each site. Is it an issue to setup HA active/active in this case ? I've read...
Need to find the field identifiers in the syslogs, some of them are pretty obvious while others are not.
Wondering how the Palo Alto detects HTTP tunneling and how would a security policy be configured to detect/prevent this situation.
I just started using PAN 2050 in production and confiuring ssl vpn. Issue is that after client computer connect to vpn, client computer loses all internet access. What makes ssl vpn to work so that client computer doesn't lose internet access locally and still access resources remotely (office reourses behind the PAN)?Thanks
HiI have a rule with some custom ports in the service tab, but how do I add ping then? - does not work if I dont have "application-default" in the service tab.Thanks
HiI configure PDF Summary report for AD group.The way i did , i create the Custom AD group report and attached this custome report to PDF Summary report.But the generated pdf summary report doesnt have any data it shows all the the custom report with any data.If run manually the custom group report i will get the data.Please let me know what wi...
A few of my rules allow for certain individuals (by way of User-ID) access to download EXE and access most any application. This of course works fine for PCs that are joined to the domain which makes up 99% of our PCs. However, for that 1% that are not on the domain, what's the best way for an individual to optionally supply the proper AD cred...
If a download service uses SSL and PAN has an App and file blocking capability, but under SSL Decryption, it is an exception (ala drobpox), are options are pretty limited, correct?
Hello,I'm trying to setup a ipsec vpn with a fortigate which has dynamic ip as gateway.I have a security policy which allows all packets from the dynamic ip (fqdn) but if i type the command 'show log traffic src in x.x.x.x' i can see that i have an incoming request which Palo Alto denies.The weird thing is that this allow rule contains all other...
Remote Desktop Protocol (RDP) is a multi-channel protocol that allows a user to connect to a networked computer. Clients exist for most versions of Windows (including handheld versions), Linux/Unix, Mac OS X and other modern operating systems. The server listens by default on TCP port 3389. Microsoft refers to the official RDP server software as...
Hi, I've PA-500 with 4.1.1 and I've configured Captive Portal with AD Authentication. Pan-agenty seems to work fine and I can select the AD groups when I configure Securtiy Policy. I've created an authentication profile only for Captive Portal with Kerberos authentication and my Domain controller as Server profile but I cannot see the groups in ...
OK, I have read many discussions about this, but never found the answer. We were provided a /28 range of IP addresses from our ISP. We currently plug the ISP connection straight into port 3 on the PA. I would now like to add a Juniper SRX behind the PA, with a public IP so our VPN routers in the field can connect. Seems straight forward.In t...
Very basic configuration, an any any rule and a PAT rule for nat... trust and untrust zones and a default route and an internal summary route... what is happening is that from a traffic log perspective its being ALLOWED, from a NAT perspective I can see the session built with two flows for each direction successfully and they go ACTIVE. However,...
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like |
| User | Likes Count |
|---|---|
| 7 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

